FengLingYaaa/dsh-gpt-perm-strip

FengLingYaaa★ 0TypeScriptLast synced: 2026-08-17

Open on GitHub

DSH plugin: strip leftover GPT sandbox_permissions that are not strictly wider than the current session.

README excerpt

dsh-gpt-perm-strip A DeepSeek Harness plugin that runs only for GPT-family models . Before a tool body hits DSH's sandbox escalation check, it removes sandbox permissions / justification that are not strictly wider than the current session. Why DSH requires sandbox permissions to be strictly wider than the session. The same (or a narrower) mode fails immediately: GPT-family models habitually send a permission field even when the session already has that access. This plugin drops those leftover fields and leaves real escalations ( workspace-write → danger-full-access ) untouched. tools/pre-execute cannot rewrite frozen arguments. The plugin wraps each tool's execute and passes a cloned argument object with the unnecessary fields removed. The durable tool/call record still shows what the model emitted. GPT-only Matching is by model id, not provider (OpenAI-compatible gateways often host GPT, Grok, and DeepSeek under one provider): - gpt-4o , gpt-5.6-sol , chatgpt-4o-latest , openai/gpt-4.1 , ft:gpt-4o:… - optional: o1 / o3 / o4 ( includeOpenAiReasoning , default on) Grok and DeepSeek are ignored unless you add extraModelPatterns . Repo: https://github.com/FengLingYaaa/dsh-gpt-perm-st…

View full README on GitHub →
Tools / Devdeepseek-harnessdsh-plugingpt

Category