@nanmicoder/dsh-auto-mode
Sandbox-first automatic permission policy for DeepSeek Harness
87 results
Sandbox-first automatic permission policy for DeepSeek Harness
dsh-passwords: a server-grade gateway that turns DeepSeek Harness into a multi-tenant platform — remote access + automatic HTTPS, per-subuser permissions & quotas, sandbox enforcement, first-run setup, SQLite auth with at-rest encryption, rate-limit and audit log (bilingual zh/en UI)
DSH sandbox extension: configurable trusted writable roots outside the workspace, read restrictions, and capability-based command allow-listing for sandboxed CLI commands. 为 DSH 默认沙箱增加「沙箱授权目录」「禁读规则」与按能力类判定的「命令放行」规则。
Tensorlake sandbox execution providers for DeepSeek Harness
Approval mode control for DeepSeek Harness: default approval, bypass approval, or bypass that still asks before a sandbox escalation, next to the permission selector. DSH 审批模式插件。
Sprites remote development environments for DeepSeek Harness through Cordis and MCP.
Net Access permission preset for DeepSeek Harness (Windows): HTTPS works inside the sandbox while file writes stay confined like workspace-write.
DSH 测试沙盒插件:把开发/测试任务路由到进程级隔离的沙盒实例(独立进程 + 独立 DSH_HOME + 独立端口),提供创建/注入/运行/健康检查/停止/销毁/清理与门禁式合回等原生工具,全程零影响本体(3080)。
Autonomous six-phase security audit engine for DSH: vendored cloudflare/security-audit-skill + sandboxed execution + subagent orchestration
DSH 权限预设 workspace-write++:工作区内写文件,可在设置里配置放行 Git Bash / PowerShell 等进程沙箱(修复 Windows ACL 下 MSYS 内存映射错误)。
dsh-yolo-mode —— DeepSeek Harness 双面包插件:当会话处于可写沙箱模式且审批策略为 ask 时,用大模型自动裁决沙箱升权申请,支持内置预设与自定义权限层级,并提供宿主 settings + 自发布设置桥(/yolo-mode)与 Web 客户端 UI。
DSH tool-call compatibility: strips sandbox_permissions/justification from tool-call arguments for third-party models (GPT etc.), and lets the user skip possibly-stuck tool calls with an LLM-facing notice.
DSH context-window relief: knowledge base (ctx_index/search), routing enforcement (deny flood tools), sandboxed execution (ctx_execute/batch Think-in-Code), and session continuity (post-compaction restore).
Fail-closed microsandbox microVM provider and model-facing guest tools
Audit deepseek-harness (DSH) plugins before install, guard them at runtime. Static verdict + pre-install audit protocol; supply-chain checks (typosquat, OSV); exfiltration & ransomware detection, honeypot canaries, integrity baseline. Alarm-only; blocks confirmed destructive ops.
OrbStack VM sandbox v0.5.0: 适配 DeepSeek Harness 0.2.0-rc.2(客户端 inject 由已移除的 dsh-client-runtime 迁移到 dsh-client-ui-renderer、补齐 DSH peer 版本闸门、宿主服务 inject 补全、会话标题读取修复)。保留 45 个 vm_* 工具、交互终端、快照/回滚、导入导出、配额/告警与「虚拟机」页签。
DeepSeek Harness 的 Docker 容器沙箱部署级插件(与 dsh-plugin-vm-sandbox 全能力对齐):39 个 docker_* 模型工具、快照/回滚、文件传输、端口转发、后台任务、审计、共享/配额/回收、网络策略、多容器并行执行与华丽原生 UI。无需 OrbStack,Linux/Windows/macOS 均可使用。
DSH sandbox extension: keep declared workspace subpaths (e.g. .git) read-only, honor a read-only rules file at the workspace root, grant extra writable roots under workspace-write, and let the model request session-scoped write access; enforced for sandboxed CLI commands and the write/edit tools. 为 DSH 沙箱增加工作区子路径只读保护 (例如 .git), 支持工作区根下的只读规则文件, 可在 workspace-write 下声明额外可写根, 并允许模型申请本会话的可写授权; 命令沙箱与 write/edit 工具都生效.
Multi-root Workspace for DeepSeek Harness: adds N additional roots to the workspace sandbox scope as an out-of-tree bundle
Zero-dependency static + sandbox smoke detector for DeepSeek Harness (dsh) plugins: package-structure gates (R), cordis contract scans (K), keyless-headless sandbox smoke (D), and ecosystem-listing checks (CC).
dsh-bash-native: a Windows-native POSIX bash executor for the DSH shell seam, with engine resolution and DSH's three-tier file sandbox honored.
Benchmark-driven self-evolution plugin for DeepSeek Harness: iterate on a frozen benchmark and accept only when strictly better; real execution remains fail-closed until transactional sandbox support.
Blaxel sandbox execution plugin for DeepSeek Harness (DSH)
DSH plugin: strip GPT-family tool-call sandbox_permissions that are not strictly wider than the current session.