zhangzhangco/dsh-llm-codex ↗★ 0

dsh-llm-codex

接入本地Codex CLI并支持OpenAI接口降级 适合需要结合本地Codex命令行与云端API进行模型调用的用户。

套件
dsh-llm-codex
相容性
待驗證
Harness 依賴範圍
^0.1.5-rc.2
Cordis 依賴範圍
^4.0.2
版本
0.2.0
授權
MIT
最近更新
2026年9月22日

同名套件的其他儲存庫

安裝

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:zhangzhangco/dsh-llm-codex

Configuration

Mounted from ~/.dsh/profiles/web/cordis.patch.yml:

- insert:
    - id: llm-codex
      name: dsh-llm-codex
      config:
        provider: codex-local
        # Codex's own sandbox (not the harness permission mode). See
        # "Sandbox and file writes" below before choosing a value.
        sandbox: read-only
        ephemeral: true
        transport: auto
        reasoningEffort: ''
        fallback:
          baseURL: ''
          apiKeyEnv: CODEX_FALLBACK_API_KEY
FieldDefaultMeaning
providercodex-localRoute name shown to the model picker
commanddiscoveredCodex CLI to run; empty discovers it ($CODEX_COMMAND, PATH, known installs)
args[]Extra argv passed to codex exec before the prompt
modelemptyPin one model; empty uses the catalog, then $CODEX_HOME/config.toml
reasoningEffortemptyDefault effort; a session selection wins
sandboxread-onlyread-only, workspace-write, or danger-full-access
cwdemptyCodex working root; empty uses the session workspace
ephemeraltrueRun without persisting Codex threads under $CODEX_HOME
timeoutMs600000Wall-clock budget for one codex exec
codexHomeempty$CODEX_HOME for the child; empty inherits the environment
modelsCachePath$CODEX_HOME/models_cache.jsonCatalog cache
models[]Extra ids to advertise when the cache is missing
defaultContextWindow272000Capacity fallback for unknown ids
transportautoauto (CLI, then fallback), cli only, or api only
fallback.baseURLemptyOpenAI-compatible base URL; empty disables the fallback
fallback.apiKeyEnvCODEX_FALLBACK_API_KEYVariable holding the fallback key
fallback.modelemptyModel id for the fallback; empty reuses the request id
fallback.headers{}Extra request headers
fallback.timeoutMs300000Fallback request budget

Sandbox and file writes

sandbox selects Codex's own sandbox for the CLI route. It is a different boundary from this harness's permission mode, which keeps gating DSH's own tools independently; changing one does not change the other.

ValueEffect on Codex's tools
read-onlyReads and answers; every file write is refused
workspace-writeWrites inside the session workspace; other targets stay refused
danger-full-accessNo Codex sandbox at all

The two sandboxed modes need macOS Seatbelt, applied through sandbox-exec. A host that already runs inside a sandbox cannot apply a nested profile — the call fails with sandbox_apply: Operation not permitted — and then every sandboxed mode refuses writes, no matter which roots are allowed: