zhangzujian/dsh-same-mode-sandbox-noop

DSH compatibility plugin for redundant same-mode sandbox escalation requests

A removable compatibility plugin for DSH 0.1.0-rc.6. That release rejects a tool call when sandbox_permissions names a mode already covered by the call's effective sandbox mode (e.g. "danger-full-access" vs "danger-full-access"). The plugin wraps both ctx.tools.execute() and the rc.6 Agent Loop scheduler's preparation entry point; for bash, pwsh, write, and edit, it removes the paired sandbox_permissions and justification fields when the requested mode is equal to or narrower than the calling session's effective mode, so the original runtime executes the call under its standing policy. Genuinely wider requests, unknown modes, malformed pairs, unrelated tools, and calls without escalation fields pass through unchanged. Disposal restores the original runtime methods. Documented as an out-of-tree workaround until a DSH release handles non-escalating requests in the shared sandbox escalation layer.

Infrastructure & Deployment ★ 4 updated 2026-08-14 ✅ runtime-tested
View on GitHub ↗

Install

npx @deepseek-ai/dsh@0.1.0-rc.6 plugin --profile web add "$PWD"

GitHub install per README (English, no npm package yet): git clone https://github.com/zhangzujian/dsh-same-mode-sandbox-noop.git && cd dsh-same-mode-sandbox-noop, then npx @deepseek-ai/dsh@0.1.0-rc.6 plugin --profile web add "$PWD" and restart dsh web. The package declares a DSH bundle, so dsh plugin adds its patch layer automatically. Remove with npx @deepseek-ai/dsh@0.1.0-rc.6 plugin --profile web remove @zhangzujian/dsh-same-mode-sandbox-noop.

Compatibility

DeepSeek Harness / DSH 0.1.0-rc.6 (the release that introduced the same-mode sandbox rejection).

Details

Recent updates

same-mode sandbox rejection workaround for rc.6; wraps tools.execute + scheduler prep; removes redundant sandbox_permissions/justification pairs; full disposal.

FAQ

Which DSH versions need this?
Only 0.1.0-rc.6 — the release that rejects tool calls when sandbox_permissions names a mode already covered by the effective sandbox mode.
Does it weaken sandboxing?
No — it only removes redundant permission fields for requests equal to or narrower than the session's effective mode; genuinely wider requests still go through DSH's original validation.
How do I remove it?
npx @deepseek-ai/dsh@0.1.0-rc.6 plugin --profile web remove @zhangzujian/dsh-same-mode-sandbox-noop — disposal restores the original runtime methods.

Alternatives

icy-river-dsh-sandbox-policy · damonkoy-dsh-tool-policy · pandashere/dsh-self-control-guard

More plugins in Infrastructure & Deployment

Browse more in Infrastructure & Deployment

Guides for Infrastructure & Deployment plugins