Skip to content
dsh.fish
Bundle

dsh-gpt-perm-strip

DSH plugin: strip GPT-family tool-call sandbox_permissions that are not strictly wider than the current session.

Source
FengLingYaaa
stars
1 stars
License
MIT
Updated
Updated 14 days ago

Readme

# dsh-gpt-perm-strip

A DeepSeek Harness plugin that runs **only for GPT-family models**. Before a tool body hits DSH's sandbox escalation check, it removes `sandbox_permissions` / `justification` that are **not strictly wider** than the current session.

## Why

DSH requires `sandbox_permissions` to be *strictly* wider than the session. The same (or a narrower) mode fails immediately:

```
sandbox escalation to "danger-full-access" is not strictly wider than this call's current "danger-full-access" mode
```

GPT-family models habitually send a permission field even when the session already has that access. This plugin drops those leftover fields and leaves real escalations (`workspace-write` → `danger-full-access`) untouched.

`tools/pre-execute` cannot rewrite frozen arguments. The plugin wraps each tool's `execute` and passes a cloned argument object with the unnecessary fields removed. The durable `tool/call` record still shows what the model emitted.

## GPT-only

Matching is by model id, not provider (OpenAI-compatible gateways often host GPT, Grok, and DeepSeek under one provider):

- `gpt-4o`, `gpt-5.6-sol`, `chatgpt-4o-latest`, `openai/gpt-4.1`, `ft:gpt-4o:…`
- optional: `o1` / `o3` / `o4` (`includeOpenAiReasoning`, default on)

Grok and DeepSeek are ignored unless you add `extraModelPatterns`.

Repo: https://github.com/FengLingYaaa/dsh-gpt-perm-strip

## Install

```sh
dsh plugin --profile web add github:FengLingYaaa/dsh-gpt-perm-strip
```

Or from a local checkout:

```sh
git clone https://github.com/FengLingYaaa/dsh-gpt-perm-strip.git
cd dsh-gpt-perm-strip
pnpm install
pnpm test
pnpm build
dsh plugin --profile web add .
```

## Config

| Field | Default | Meaning |
|---|---|---|
| `includeOpenAiReasoning` | `true` | Treat o1/o3/o4 as GPT-family |
| `extraModelPatterns` | `[]` | Extra regexes against `provider`, `model`, or `provider/model` |
| `injectPrompt` | `true` | GPT-only runtime-context reminder |
| `logStrips` | `true` | Log each strip as `[gpt-perm-strip] stripped …` |

## Behavior

| Session | GPT argument | Result |
|---|---|---|
| `danger-full-access` | `sandbox_permissions: danger-full-access` | stripped, call runs |
| `workspace-write` | `sandbox_permissions: workspace-write` | stripped |
| `workspace-write` | `sandbox_permissions: danger-full-access` | **kept** (real escalation) |
| `read-only` | `sandbox_permissions: workspace-write` | **kept** |
| non-GPT model | any permission | unchanged |

`permission` / `permissions` are treated as sandbox fields only when the value is a known sandbox mode.

Install

dsh plugin --profile web add github:FengLingYaaa/dsh-gpt-perm-strip

Profile: web

  • This package builds from source on install. pnpm will ask you to allow its build script — that is permission to run the package’s code on your machine, outside the agent sandbox. Only allow sources you trust.
  • This source has no pinned commit, so a later push upstream changes what installs. Prefer pinning a commit.
Source