api-relay-audit
toby-bridges
Local security audit for AI API relays and LLM proxies: detects prompt injection, model substitution, tool-call rewriting, SSE anomalies, error leakage, and Web3 wallet risks.
PROJECT TOPICS
INSTALL REFERENCE
dsh plugin --profile web add github:liyuqian/dsh-flutter-sandbox
该命令指向仓库当前默认分支;尚无绑定当前 commit 的完整验证结果。
PROJECT README
A DeepSeek Harness (dsh) plugin that lets Flutter and Dart run inside dsh's workspace-write sandbox.
Out of the box, dsh only lets sandboxed commands write the session workspace and /tmp. Flutter also writes outside the project on every run, so even flutter --version fails:
update_engine_version.sh: line 71: .../flutter/bin/cache/engine.stamp.tmp: Read-only file system
This plugin replaces dsh's stock sandbox provider with one that also grants write access to these directories (only those that exist):
| Directory | Why |
|---|---|
Flutter SDK ($FLUTTER_ROOT, or found from flutter on PATH) |
The tool updates bin/cache on every run |
$PUB_CACHE or ~/.pub-cache |
Package downloads |
~/.dart-tool, ~/.dartServer |
Telemetry state and analysis-server cache |
~/.flutter, $XDG_CONFIG_HOME/flutter (~/.config/flutter) |
Flutter settings |
$GRADLE_USER_HOME or ~/.gradle, ~/.android |
Android builds |
Everything else stays protected, and read-only and danger-full-access modes are unchanged. The model is told about the extra directories in its context.
dsh plugin --profile tui add github:liyuqian/dsh-flutter-sandbox
Use --profile web (or any other profile name) for other profiles. Remove it with dsh plugin --profile tui remove dsh-flutter-sandbox.
The defaults need no configuration. To turn off the Flutter directories or add your own, override the plugin row in your profile's cordis.patch.yml (~/.dsh/profiles/<profile>/cordis.patch.yml):
- id: sandbox-flutter
config:
flutter: true # grant the Flutter/Dart/Gradle/Android directories above
extraWritableRoots: # additional absolute directories
- /home/me/.cocoapods
The stock provider's options (runnerCommand, runnerFailureSignatures, probeTimeoutMs) are accepted too.
The plugin's bundle patch disables dsh-base's sandbox row (@deepseek-ai/dsh-sandbox-local) and inserts sandbox-flutter, a subclass of that provider. For each workspace-write call it lets the stock provider build the runner command, then inserts one grant per existing directory before the -- that precedes your command:
--bind <dir> <dir>--rw <dir>(allow file-write* (subpath "<dir>"))flutter pub get in a package of a pub workspace writes to the workspace root; start the dsh session at that root.npm test
The tests cover root discovery and each runner's grant insertion without a dsh installation.
MIT
CLASSIFICATION EVIDENCE
系统优先读取 GitHub Topics,再与站内分类词典和词根规则比对。当前命中: sandbox。