Back to catalog

Hanihahaha /

dsh-sandbox-argument-normalizer

Verified

This repository has no description yet.

0 Stars0 Forks0 IssuesN/A Community rating0 Confirmed installs
READMESource: main@7453e259

dsh-sandbox-argument-normalizer

中文

A DeepSeek Harness host plugin that removes invalid sandbox_permissions and justification arguments before native tool dispatch.

Problem Solved

Some models or OpenAI-compatible gateways include every advertised optional argument in ordinary pwsh, write, or edit calls. When the injected sandbox_permissions equals the session's current mode, or is narrower, DSH correctly rejects the call before it runs with an error such as:

sandbox escalation to "workspace-write" is not strictly wider than this call's current "workspace-write" mode

The same failure occurs in a danger-full-access session when the model still sends either advertised escalation mode. This is not a real sandbox denial; the session already has sufficient access, but the invalid escalation fields prevent the intended tool call from executing.

It only removes a request when it is not strictly wider than the calling session's effective sandbox mode. Valid escalation requests remain unchanged and continue through DSH's normal approval flow.

Examples:

  • workspace-write session + sandbox_permissions: workspace-write: removed.
  • danger-full-access session + either advertised mode: removed.
  • read-only session + sandbox_permissions: workspace-write: preserved for the regular approval flow.

The plugin hooks the tools/execute waterfall. It does not auto-approve requests and does not alter session permission state.

/ 5

No ratings yet

Community comments

No comments yet. Be the first to write one.