FengLingYaaa / dsh-gpt-perm-strip

목록에 있음

DSH plugin: strip leftover GPT sandbox_permissions that are not strictly wider than the current session.

main세션샌드박스 소스 보기

설치

npx -y @deepseek-ai/dsh plugin --profile web add github:FengLingYaaa/dsh-gpt-perm-strip

이 설치 명령은 GitHub 저장소 주소에서 생성된 확인되지 않은 시작점입니다.

README

유지 관리자가 작성한 문서 스냅샷입니다.

GitHub에서 보기 ↗
커밋 e70b9f2동기화 2026. 8. 18.

dsh-gpt-perm-strip

A DeepSeek Harness plugin that runs only for GPT-family models. Before a tool body hits DSH's sandbox escalation check, it removes sandbox_permissions / justification that are not strictly wider than the current session.

Why

DSH requires sandbox_permissions to be strictly wider than the session. The same (or a narrower) mode fails immediately:

sandbox escalation to "danger-full-access" is not strictly wider than this call's current "danger-full-access" mode

GPT-family models habitually send a permission field even when the session already has that access. This plugin drops those leftover fields and leaves real escalations (workspace-writedanger-full-access) untouched.

tools/pre-execute cannot rewrite frozen arguments. The plugin wraps each tool's execute and passes a cloned argument object with the unnecessary fields removed. The durable tool/call record still shows what the model emitted.

GPT-only

Matching is by model id, not provider (OpenAI-compatible gateways often host GPT, Grok, and DeepSeek under one provider):

  • gpt-4o, gpt-5.6-sol, chatgpt-4o-latest, openai/gpt-4.1, ft:gpt-4o:…
  • optional: o1 / o3 / o4 (includeOpenAiReasoning, default on)

Grok and DeepSeek are ignored unless you add extraModelPatterns.

Repo: https://github.com/FengLingYaaa/dsh-gpt-perm-strip

Install

dsh plugin --profile web add github:FengLingYaaa/dsh-gpt-perm-strip

Or from a local checkout:

git clone https://github.com/FengLingYaaa/dsh-gpt-perm-strip.git
cd dsh-gpt-perm-strip
pnpm install
pnpm test
pnpm build
dsh plugin --profile web add .

Config

FieldDefaultMeaning
includeOpenAiReasoningtrueTreat o1/o3/o4 as GPT-family
extraModelPatterns[]Extra regexes against provider, model, or provider/model
injectPrompttrueGPT-only runtime-context reminder
logStripstrueLog each strip as [gpt-perm-strip] stripped …

Behavior

SessionGPT argumentResult
danger-full-accesssandbox_permissions: danger-full-accessstripped, call runs
workspace-writesandbox_permissions: workspace-writestripped
workspace-writesandbox_permissions: danger-full-accesskept (real escalation)
read-onlysandbox_permissions: workspace-writekept
non-GPT modelany permissionunchanged

permission / permissions are treated as sandbox fields only when the value is a known sandbox mode.

프로젝트 파일 및 신호

표시된 항목은 디렉터리 스냅샷에서 감지된 공개 저장소 신호입니다.

테스트감지됨

저장소 정보

언어
TypeScript
라이선스
MIT
마지막 업데이트
2026. 8. 17. AM 4:00

신중하게 설치하기

소스 코드, 권한, 수명 주기 스크립트, 의존성 및 네트워크 접근을 검토하고 신뢰하지 않는 플러그인은 격리 환경에서 테스트하세요.