返回目录
其他 待识别

dsh-sandbox-argument-normalizer

Hanihahaha/dsh-sandbox-argument-normalizer

该仓库暂未提供项目说明。

Stars
0
Forks
0
Issues
0
更新
3 天前

PROJECT TOPICS

项目标签

PROJECT README

README

dsh-sandbox-argument-normalizer

中文

A DeepSeek Harness host plugin that removes invalid sandbox_permissions and justification arguments before native tool dispatch.

Install

# Run from the repository root.
dsh plugin --profile web add ".\dsh-sandbox-argument-normalizer"

Restart dsh web after installation.

Problem Solved

Some models or OpenAI-compatible gateways include every advertised optional argument in ordinary pwsh, write, or edit calls. When the injected sandbox_permissions equals the session's current mode, or is narrower, DSH correctly rejects the call before it runs with an error such as:

sandbox escalation to "workspace-write" is not strictly wider than this call's current "workspace-write" mode

The same failure occurs in a danger-full-access session when the model still sends either advertised escalation mode. This is not a real sandbox denial; the session already has sufficient access, but the invalid escalation fields prevent the intended tool call from executing.

It only removes a request when it is not strictly wider than the calling session's effective sandbox mode. Valid escalation requests remain unchanged and continue through DSH's normal approval flow.

Examples:

  • workspace-write session + sandbox_permissions: workspace-write: removed.
  • danger-full-access session + either advertised mode: removed.
  • read-only session + sandbox_permissions: workspace-write: preserved for the regular approval flow.

The plugin hooks the tools/execute waterfall. It does not auto-approve requests and does not alter session permission state.

CLASSIFICATION EVIDENCE

分类依据

项目类型待识别
功能分类其他
规则置信度

系统优先读取 GitHub Topics,再与站内分类词典和词根规则比对。当前命中: 无有效分类标签。