dsh-gpt-perm-strip
Manifest valid★ 2DSH plugin: strip GPT-family tool-call sandbox_permissions that are not strictly wider than the current session.
dsh-gpt-perm-strip
A DeepSeek Harness plugin that runs only for GPT-family models. Before a tool body hits DSH's sandbox escalation check, it removes sandbox_permissions / justification that are not strictly wider than the current session.
Why
DSH requires sandbox_permissions to be strictly wider than the session. The same (or a narrower) mode fails immediately:
sandbox escalation to "danger-full-access" is not strictly wider than this call's current "danger-full-access" mode
GPT-family models habitually send a permission field even when the session already has that access. This plugin drops those leftover fields and leaves real escalations (workspace-write → danger-full-access) untouched.
tools/pre-execute cannot rewrite frozen arguments. The plugin wraps each tool's execute and passes a cloned argument object with the unnecessary fields removed. The durable tool/call record still shows what the model emitted.
GPT-only
Matching is by model id, not provider (OpenAI-compatible gateways often host GPT, Grok, and DeepSeek under one provider):
gpt-4o,gpt-5.6-sol,chatgpt-4o-latest,openai/gpt-4.1,ft:gpt-4o:…- optional:
o1/o3/o4(includeOpenAiReasoning, default on)
Grok and DeepSeek are ignored unless you add extraModelPatterns.
Repo: https://github.com/FengLingYaaa/dsh-gpt-perm-strip
Install
dsh plugin --profile web add github:FengLingYaaa/dsh-gpt-perm-strip
Or from a local checkout:
git clone https://github.com/FengLingYaaa/dsh-gpt-perm-strip.git
cd dsh-gpt-perm-strip
pnpm install
pnpm test
pnpm build
dsh plugin --profile web add .
Config
| Field | Default | Meaning |
|---|---|---|
includeOpenAiReasoning | true | Treat o1/o3/o4 as GPT-family |
extraModelPatterns | [] | Extra regexes against provider, model, or provider/model |
injectPrompt | true | GPT-only runtime-context reminder |
logStrips | true | Log each strip as [gpt-perm-strip] stripped … |
Behavior
| Session | GPT argument | Result |
|---|---|---|
danger-full-access | sandbox_permissions: danger-full-access | stripped, call runs |
workspace-write | sandbox_permissions: workspace-write | stripped |
workspace-write | sandbox_permissions: danger-full-access | kept (real escalation) |
read-only | sandbox_permissions: workspace-write | kept |
| non-GPT model | any permission | unchanged |
permission / permissions are treated as sandbox fields only when the value is a known sandbox mode.
Comments
Loading…
From the same category
by tt-a1i
Agent skill for beautiful, verifiable architecture, workflow, sequence, data-flow, and lifecycle diagrams—self-contained HTML with motion and crisp export.
★ 69.2k
↓ 3.5k/wk
MIT
JavaScript
Sep 21, 2026
dsh plugin --profile web add @tt-a1i/archify-dshDeepSeek Harness plugin for Reactive Resume: bridges your resumes and job applications into a Harness session over MCP.
★ 41.7k
↓ 251/wk
MIT
Aug 24, 2026
dsh plugin --profile web add dsh-plugin-reactive-resumeby Tencent
Open-source LLM knowledge platform: turn raw documents into a queryable RAG, an autonomous reasoning agent, and a self-maintaining Wiki.
★ 28.6k
↓ 831/wk
NOASSERTION
Go
Sep 21, 2026
dsh plugin --profile web add @wxg-prc-cpg/dsh-weknoraby anywhere-labs
为 DeepSeek Harness (DSH) 插件生态打造的现代化桌面端解决方案。万物皆「插件」,桌面本身也是「插件」。
★ 28.3k
↓ 170/wk
MIT
TypeScript
Sep 22, 2026
dsh plugin --profile web add dsh-plugin-desktopby titanwings
Distilly — Distill how they think into reusable Skills for any Agent or Bot. Formerly Colleague Skill(原同事 Skill).
★ 24.9k
MIT
TypeScript
Sep 16, 2026
by Nagi-ovo
Enhancement suite for Gemini, AI Studio, Claude & ChatGPT — plus a prompt manager for any websites, DeepSeek Harness included. / 面向 Gemini、AI Studio、Claude 与 ChatGPT 的增强套件;其中的提示词管理器可用于任意网站,如 DeepSeek
★ 20.1k
GPL-3.0
TypeScript
Sep 21, 2026