DeepSeek Harness plugin

dsh-gpt-perm-strip

DSH plugin: strip GPT-family tool-call sandbox_permissions that are not strictly wider than the current session.

Jump to install

Source facts

Repository
FengLingYaaa/dsh-gpt-perm-strip
Latest update
Aug 17, 2026
Category
Tools & Capabilities
GitHub stars
1
Format
plugin
Catalog evidence
Upstream dsh.bundle evidence
Evidence path
package.json#dsh.bundle
Checked against
0.1.0-rc.8
Upstream check date
2026-08-20

This evidence comes from the upstream catalog. This site has not installed, run, or security-reviewed the plugin.

Install

Start with a prompt that asks an agent to review the GitHub repository and source. Switch to the command if you want to install it yourself.

Copy this prompt into DSH, Codex, or another agent and ask it to review the GitHub repository and source first.

Do not install or run any commands yet. Read this plugin's GitHub repository, README, and relevant source code. Then answer the questions below clearly and directly so I can decide whether it fits my needs:

1. What is this plugin, and what problem does it solve?
2. Who is it for, and what are its typical use cases?
3. How is it used after installation? Include one minimal example.
4. What known limitations or privacy, security, compatibility, or maintenance risks does it have?
5. Give a clear recommendation: recommend, conditionally recommend, or do not recommend, with reasons.

Distinguish statements documented by the repository, inferences from source code, and unknowns. If evidence is insufficient, say so explicitly. Do not guess or simply repeat the README.

GitHub: https://github.com/FengLingYaaa/dsh-gpt-perm-strip
Plugin: dsh-gpt-perm-strip
Author: FengLingYaaa

Check the source files

Read the README and other files from this plugin directory before installing.

File explorer3 files
README.mdSource · read only

dsh-gpt-perm-strip

A DeepSeek Harness plugin that runs only for GPT-family models. Before a tool body hits DSH's sandbox escalation check, it removes sandbox_permissions / justification that are not strictly wider than the current session.

Why

DSH requires sandbox_permissions to be strictly wider than the session. The same (or a narrower) mode fails immediately:

sandbox escalation to "danger-full-access" is not strictly wider than this call's current "danger-full-access" mode

GPT-family models habitually send a permission field even when the session already has that access. This plugin drops those leftover fields and leaves real escalations (workspace-writedanger-full-access) untouched.

tools/pre-execute cannot rewrite frozen arguments. The plugin wraps each tool's execute and passes a cloned argument object with the unnecessary fields removed. The durable tool/call record still shows what the model emitted.

GPT-only

Matching is by model id, not provider (OpenAI-compatible gateways often host GPT, Grok, and DeepSeek under one provider):

  • gpt-4o, gpt-5.6-sol, chatgpt-4o-latest, openai/gpt-4.1, ft:gpt-4o:…
  • optional: o1 / o3 / o4 (includeOpenAiReasoning, default on)

Grok and DeepSeek are ignored unless you add extraModelPatterns.

Repo: https://github.com/FengLingYaaa/dsh-gpt-perm-strip

Install

dsh plugin --profile web add github:FengLingYaaa/dsh-gpt-perm-strip

Or from a local checkout:

git clone https://github.com/FengLingYaaa/dsh-gpt-perm-strip.git
cd dsh-gpt-perm-strip
pnpm install
pnpm test
pnpm build
dsh plugin --profile web add .

Config

FieldDefaultMeaning
includeOpenAiReasoningtrueTreat o1/o3/o4 as GPT-family
extraModelPatterns[]Extra regexes against provider, model, or provider/model
injectPrompttrueGPT-only runtime-context reminder
logStripstrueLog each strip as [gpt-perm-strip] stripped …

Behavior

SessionGPT argumentResult
danger-full-accesssandbox_permissions: danger-full-accessstripped, call runs
workspace-writesandbox_permissions: workspace-writestripped
workspace-writesandbox_permissions: danger-full-accesskept (real escalation)
read-onlysandbox_permissions: workspace-writekept
non-GPT modelany permissionunchanged

permission / permissions are treated as sandbox fields only when the value is a known sandbox mode.