Skills Plugins MCP Prompt Model 导航 博客 资讯 我的中心

dsh-sandbox-arg-guard

让「同级或更窄的 sandbox_permissions」不再让工具调用直接失败。会升级的工具(pwsh、bash、write、edit)都广告完整的 sandbox_permissions 枚举,但 DSH 只接受严格更宽于当前生效级别的请求——其源码自称这是「deliberately not a schema constraint」。于是反射式带上该参数的模型往往填它已经在的那个级别,调用在执行前就死掉:"sandbox escalation to \"workspace-write\" is not strictly wider than this call's current \"workspace-write\" mode",某些模型还会为此烧掉一整轮重试。本插件只注册一个 tools/execute waterfall 监听器,且仅在那一条文档化拒绝上、且参数里确实带了升级字段时,把同一个调用去掉该参数重投一次。安全性由 DSH 自己的文档保证:拒绝发生在任何执行之前("nothing has run"),且改过的参数无法再次匹配,因此重投在结构上不成环。已端到端复现并验证——改造前 isError 为 true 且命令从未执行;改造后拿到命令的真实输出、isError 为 false,会话里只有一个 tool/call 与一个 tool/result。零依赖。

apex-mochen @apex-mochen ⬇ 2 ★ 0 main

安装

dsh plugin --profile web add github:apex-mochen/dsh-sandbox-arg-guard
下载安装清单

需要可复现安装时,可在仓库后追加 #commit 固定提交。

让「同级或更窄的 sandbox_permissions」不再让工具调用直接失败。会升级的工具(pwsh、bash、write、edit)都广告完整的 sandbox_permissions 枚举,但 DSH 只接受严格更宽于当前生效级别的请求——其源码自称这是「deliberately not a schema constraint」。于是反射式带上该参数的模型往往填它已经在的那个级别,调用在执行前就死掉:"sandbox escalation to \"workspace-write\" is not strictly wider than this call's current \"workspace-write\" mode",某些模型还会为此烧掉一整轮重试。本插件只注册一个 tools/execute waterfall 监听器,且仅在那一条文档化拒绝上、且参数里确实带了升级字段时,把同一个调用去掉该参数重投一次。安全性由 DSH 自己的文档保证:拒绝发生在任何执行之前("nothing has run"),且改过的参数无法再次匹配,因此重投在结构上不成环。已端到端复现并验证——改造前 isError 为 true 且命令从未执行;改造后拿到命令的真实输出、isError 为 false,会话里只有一个 tool/call 与一个 tool/result。零依赖。

该插件未提供要点说明,请参考仓库 README。

  1. 安装并启动 DeepSeek Harness:npx @deepseek-ai/dsh web
  2. 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
  3. 用 dsh plugins list 确认已安装,必要时重启 Harness 生效

插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。

代码仓库github.com/apex-mochen/dsh-sandbox-arg-guard
许可证MIT
主要语言main
下载量2
GitHub 星标0
最近推送2026-09-15
收录日期2026-09-19
分类安全与权限

事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。

以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。

# dsh-sandbox-arg-guard

**Keeps a redundant sandbox-escalation argument from failing a tool call.**

When an escalating tool (`pwsh`, `bash`, `write`, `edit`) is rejected because the model repeated its
own sandbox level, this plugin re-issues the same call once without that argument — so the call the
model actually intended just runs.

## The failure it prevents

Every escalating tool advertises the full `sandbox_permissions` enum, but DSH only accepts a request
for a level **strictly wider** than the one already in effect. From
`packages/sandbox/sandbox/src/escalation.ts:159-164`:

```ts
// Strict widening is an EXECUTION check against the call's effective mode —
// deliberately not a schema constraint (the enum is the closed target
// vocabulary; the effective mode is per-call truth).
if (!(WIDER_MODES[effectiveMode] ?? []).includes(mode as SandboxMode)) {
  throw new Error(`sandbox escalation to "${mode}" is not strictly wider than this call's current "${effectiveMode}" mode`)
}
```

The schema therefore cannot tell the model which values are legal *for this call*, and a model that
reflexively passes the argument — a very common habit — picks the level it is already at. The result:

```
Error: sandbox escalation to "workspace-write" is not strictly wider than this call's current "workspace-write" mode
```

Nothing runs. The model gets an error for a call that was perfectly reasonable apart from one
redundant field, and for some models that is a whole turn spent retrying. This is **item 1 of the
community-verified unfixed-issue list** in discussion
[#6520](https://github.com/deepseek-ai/deepseek-harness/discussions/6520) — the most-reported entry
there, with eight directly related discussions and three more in the same family.

## What the plugin does

Registers exactly one `tools/execute` waterfall listener. It calls `next()` exactly once and returns
what it produced. Only when the settled result is that one documented rejection **and** the arguments
actually carried an escalation field does it re-issue the identical call with `sandbox_permissions`
and `justification` removed.

**Why retrying is safe.** `escalation.ts:143-152` states the ordering:

> Resolve a sandbox-escalation request BEFORE anything executes … the tool registry turns the throw into
> the call's isError result, **and nothing has run. A non-widening request never prompts a human.**

Because the rejection precedes any work, re-issuing the same call minus the redundant field cannot
double-apply a side effect. The retry is also **loop-free by construction**: the corrected arguments no
longer contain an escalation field, so they cannot match the rejection pattern again.

**Why this seam and no other.** `tools/pre-execute` and `agent/pre-step` are waterfall hooks that return
a *decision* (`allow` / `ask` / `deny`) — neither can rewrite arguments. `tools/execute` is the one hook
whose return value *is* the execution result, and `ToolRuntime.execute(input)` is public with a
constructible input, so a listener may re-issue a corrected call.

## Verified

BEFORE and AFTER on real session logs, same stub, same tool call — raw output in
[EVIDENCE.md](./EVIDENCE.md):

| | guard absent | guard installed |
|---|---|---|
| `tool/result` | `Error: sandbox escalation to "workspace-write" is not strictly wider …` | `PROBE-EXECUTED` |
| `isError` | `true` | `false` |
| did the command run | no | **yes** |

The session contains exactly one `tool/call` and one `tool/result` in both cases: the retry is not
visible as a second call, and the command did not run twice.

## Install

```bash
dsh plugin --profile web add github:apex-mochen/dsh-sandbox-arg-guard
```

Restart the profile afterwards.

## Configuration

```yaml
- id: dsh-sandbox-arg-guard
  config:
    verbose: false   # log every repair
    enabled: true    # set false to keep it installed but inert
```

| Option | Type | Default | Meaning |
|---|---|---|---|
| `verbose` | boolean | `false` | Log each repair on the diagnostic channel |
| `enabled` | boolean | `true` | Turn the guard off without uninstalling |

## What it deliberately does not do

- **Only that one rejection.** An approval refusal, a genuine permission failure, or a tool's own error
  is passed through untouched — see the `isError` check in `test/smoke.mjs`.
- **Never twice.** A second retry is unreachable; a check asserts it.
- **Fails open.** If the corrected call cannot be issued at all, DSH's original and accurate error is
  what the caller sees.
- **No dependencies.** One implementation file, Node built-ins only. It never spawns, reads, writes, or
  fetches.

## This is a workaround, not a core fix

The real fix belongs in DSH: either make the advertised enum relative to the effective mode, or treat a
non-widening request as a no-op instead of an error. The source comment shows the current shape is
deliberate, so this plugin narrows the gap in **user-visible behaviour** without changing core. DSH does
not accept external pull requests today (`CONTRIBUTING.md`), so a plugin is the reachable seam.

## Compatibility

- DSH `0.1.x` (peer: `@deepseek-ai/cordis ^4.0.1`)
- Node.js 20+
- Registers exactly one waterfall listener (`tools/execute`) and contributes no tools

## License

MIT

数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

提交后我们会发送一封确认邮件,点击邮件里的链接才会开始收信。

完全免费,取消任意时间。我们不会发送垃圾邮件。