DeepSeek Harness 插件

dsh-gpt-perm-strip

DSH plugin: strip GPT-family tool-call sandbox_permissions that are not strictly wider than the current session.(英文原文)

跳到安装方式

来源信息

GitHub 仓库
FengLingYaaa/dsh-gpt-perm-strip
最近更新
2026年8月17日
分类
工具与能力
GitHub stars
1
载体类型
plugin
目录证据
上游声明已找到 dsh.bundle
证据路径
package.json#dsh.bundle
核对版本
0.1.0-rc.8
上游核对日期
2026-08-20

该证据由上游目录提供。本站没有安装、运行或安全审核这个插件。

安装

默认先复制一段 Prompt,让 Agent 读 GitHub 仓库和源码;需要自己装时再切到命令。

复制这段 Prompt,发给 DSH、Codex 或其他 Agent,让它先读 GitHub 仓库和源码。

请先不要安装或执行任何命令。阅读这个插件的 GitHub 仓库、README 和关键源码,然后用清楚、直接的方式回答以下问题,帮助我判断它是否适合我的需求:

1. 这个插件是什么,解决什么问题;
2. 适合哪些用户和典型使用场景;
3. 安装后如何使用,并给出一个最小使用示例;
4. 有哪些已知限制,以及隐私、安全、兼容性或维护风险;
5. 给出“推荐 / 有条件推荐 / 不推荐”的明确建议和理由。

请区分仓库明确说明、根据源码推断和未知信息。证据不足时请明确说明,不要猜测或照抄 README。

GitHub:https://github.com/FengLingYaaa/dsh-gpt-perm-strip
插件名:dsh-gpt-perm-strip
作者:FengLingYaaa

检查来源文件

安装前先看这个插件目录里的 README 和其他文件。

文件资源管理器3 个文件
README.md来源说明 · 只读预览

dsh-gpt-perm-strip

A DeepSeek Harness plugin that runs only for GPT-family models. Before a tool body hits DSH's sandbox escalation check, it removes sandbox_permissions / justification that are not strictly wider than the current session.

Why

DSH requires sandbox_permissions to be strictly wider than the session. The same (or a narrower) mode fails immediately:

sandbox escalation to "danger-full-access" is not strictly wider than this call's current "danger-full-access" mode

GPT-family models habitually send a permission field even when the session already has that access. This plugin drops those leftover fields and leaves real escalations (workspace-writedanger-full-access) untouched.

tools/pre-execute cannot rewrite frozen arguments. The plugin wraps each tool's execute and passes a cloned argument object with the unnecessary fields removed. The durable tool/call record still shows what the model emitted.

GPT-only

Matching is by model id, not provider (OpenAI-compatible gateways often host GPT, Grok, and DeepSeek under one provider):

  • gpt-4o, gpt-5.6-sol, chatgpt-4o-latest, openai/gpt-4.1, ft:gpt-4o:…
  • optional: o1 / o3 / o4 (includeOpenAiReasoning, default on)

Grok and DeepSeek are ignored unless you add extraModelPatterns.

Repo: https://github.com/FengLingYaaa/dsh-gpt-perm-strip

Install

dsh plugin --profile web add github:FengLingYaaa/dsh-gpt-perm-strip

Or from a local checkout:

git clone https://github.com/FengLingYaaa/dsh-gpt-perm-strip.git
cd dsh-gpt-perm-strip
pnpm install
pnpm test
pnpm build
dsh plugin --profile web add .

Config

FieldDefaultMeaning
includeOpenAiReasoningtrueTreat o1/o3/o4 as GPT-family
extraModelPatterns[]Extra regexes against provider, model, or provider/model
injectPrompttrueGPT-only runtime-context reminder
logStripstrueLog each strip as [gpt-perm-strip] stripped …

Behavior

SessionGPT argumentResult
danger-full-accesssandbox_permissions: danger-full-accessstripped, call runs
workspace-writesandbox_permissions: workspace-writestripped
workspace-writesandbox_permissions: danger-full-accesskept (real escalation)
read-onlysandbox_permissions: workspace-writekept
non-GPT modelany permissionunchanged

permission / permissions are treated as sandbox fields only when the value is a known sandbox mode.