dsh-sandbox-escalation-fix: Resolving Sandbox Escalation Compatibility for Third-Party Model Tool Calls in DeepSeek Harness
hakureimonika/dsh-sandbox-escalation-fix
A session-aware sandbox escalation compatibility plugin for DeepSeek Harness that fixes invalid escalation retry loops when third-party models call tools like bash and write under All Access.
dsh-sandbox-escalation-fix is a third-party session-aware sandbox escalation compatibility plugin for DeepSeek Harness (DSH), specifically addressing the issue where models like GPT repeatedly retry when calling tools such as bash, pwsh, write, and edit under All Access mode due to incorrect escalation parameter prompts. It corrects the registry-global escalation schemas and execution-time validation flaws in DSH's built-in implementation, preventing tool calls from being misjudged as illegal escalations in the same mode. The plugin works with zero configuration, supports DSH 0.1.2-alpha.1 and Desktop 2.0.3, and is compatible with link and external plugin layouts, making it a practical choice for DSH users facing sandbox escalation errors.
How to Install
dsh plugin --profile web add github:hakureimonika/dsh-sandbox-escalation-fix- Category
- Sessions & Messages
- Platform
- DSH Plugin
- Author
- hakureimonika
- Distribution
- Plugin
dsh-sandbox-escalation-fix Key Features
dsh-sandbox-escalation-fix Repo Summary
What Does It Do?
dsh-sandbox-escalation-fix is a third-party session-aware sandbox escalation compatibility plugin for DeepSeek Harness (DSH) that resolves the issue where third-party models like GPT fail to call tools such as bash, pwsh, write, and edit under DSH All Access, causing repeated retries due to incorrect sandbox escalation parameter prompts. It fixes the registry-global escalation schemas and execution-time validation flaws in DSH's built-in implementation by making escalation decisions session-aware. Maintained by HakureiMonika under the MIT license, it supports DSH 0.1.2-alpha.1 and Desktop 2.0.3 with zero configuration.
Core Features
- Session-aware escalation: dynamically adjusts sandbox escalation parameters based on the current session mode, avoiding misjudgments caused by registry-global schemas.
- Fixes common errors: directly addresses errors like invalid justification and sandbox escalation not strictly wider.
- Multi-version compatibility: supports DSH 0.1.1-rc series, 0.1.2-alpha.1, and Desktop 2.0.3 with tailored logic for each.
- Strict runtime validation: falls back to strict runtime tool-contract validation when complete manifests are not readable, ensuring safety.
- Supports linked and external plugin layouts: works with link, workspace symlinks, and external plugin directories, reading the host dependency tree from the working directory.
How to Use This Plugin?
After enabling this plugin in DSH, no extra configuration is needed. When a third-party model calls a tool, the plugin intercepts and corrects the sandbox escalation parameters, allowing the call to proceed normally. If escalation failures or retry loops occur, the plugin re-evaluates the request based on the current session mode. For Desktop 2.0.3, it detects the visibility of host manifests and falls back to strict runtime validation if all are hidden. It is recommended to observe DSH's built-in behavior first and install this plugin only after reproducing the same-mode escalation, blank justification, or retry-loop failures described in the README.
This page is an independent rewrite of the plugin's official README — for authoritative documentation and the latest changes, refer to the source: hakureimonika/dsh-sandbox-escalation-fix. The plugin is third-party code that runs on your machine once installed; inclusion does not imply endorsement — please review the source before installing.
