Skip to content
dsh.fish
Bundle

dsh-sandbox-argument-normalizer

Normalize invalid non-widening sandbox escalation arguments before DSH tool dispatch.

Source
Hanihahaha
License
MIT
Updated
Updated 2 days ago

Readme

# dsh-sandbox-argument-normalizer

[中文](README.zh.md)

A DeepSeek Harness host plugin that removes invalid `sandbox_permissions` and
`justification` arguments before native tool dispatch.

## Install

```powershell
# Run from the repository root.
dsh plugin --profile web add ".\dsh-sandbox-argument-normalizer"
```

Restart `dsh web` after installation.

## Problem Solved

Some models or OpenAI-compatible gateways include every advertised optional
argument in ordinary `pwsh`, `write`, or `edit` calls. When the injected
`sandbox_permissions` equals the session's current mode, or is narrower, DSH
correctly rejects the call before it runs with an error such as:

```text
sandbox escalation to "workspace-write" is not strictly wider than this call's current "workspace-write" mode
```

The same failure occurs in a `danger-full-access` session when the model still
sends either advertised escalation mode. This is not a real sandbox denial;
the session already has sufficient access, but the invalid escalation fields
prevent the intended tool call from executing.

It only removes a request when it is not strictly wider than the calling
session's effective sandbox mode. Valid escalation requests remain unchanged
and continue through DSH's normal approval flow.

Examples:

- `workspace-write` session + `sandbox_permissions: workspace-write`: removed.
- `danger-full-access` session + either advertised mode: removed.
- `read-only` session + `sandbox_permissions: workspace-write`: preserved for
  the regular approval flow.

The plugin hooks the `tools/execute` waterfall. It does not auto-approve
requests and does not alter session permission state.

Install

dsh plugin --profile web add github:Hanihahaha/dsh-sandbox-argument-normalizer#f71edd783caac3536fbcd4fa610f3976929f5155

Profile: web

Source