When building agents with DeepSeek Harness (DSH), some models may automatically include the sandbox_permissions field and its accompanying justification field in tool call parameters due to post-training tendencies. If the current session already has a high permission level (for example, full access), the included values are often not “strictly wider,” which can trigger false rejection errors in the DSH sandbox:

Error: sandbox escalation to "workspace-write" is not strictly wider than this call's current "workspace-write" mode

In this scenario, development and debugging can be interrupted, requiring repeated adjustments to prompts or permission configurations.

Plugin Introduction

dsh-strip-sandbox-permissions is a zero-dependency DeepSeek Harness (DSH) plugin. It is maintained by the user Sharl210 and belongs to the admin-security category. The core function of the plugin is to remove the sandbox_permissions and justification fields from the model tool call parameter object, thereby avoiding false rejections caused by these permission-related fields.

Working Principles

Every model tool call passes through the llm/stream waterfall pipeline, which is a mandatory interception point for all adapters. The plugin parses the tool call parameter object inside the block-end block, removes these two top-level escalation-specific fields, and then re-serializes the output.

The plugin strips only these two fields; all other parameters are preserved as-is. If these fields do not exist, the original block is passed through directly with zero overhead. In addition, the plugin is fault-tolerant: invalid JSON, non-object parameters, and non-tool-call blocks are left unchanged.

Installation and Activation

The plugin is published via npm. The installation steps are as follows:

dsh plugin --profile <your-profile> add dsh-strip-sandbox-permissions

After installation, DSH must be restarted for the changes to take effect. You can verify whether the plugin was installed successfully with the following command:

dsh plugin --profile <your-profile> list

Applicable Scenarios and Notes

This plugin is suitable for scenarios where you want to bypass automatically included permission fields in model tool calls and prevent false rejections caused by strict permission checks.

Notes:
* The plugin runs with the permissions of the current DSH process. It is recommended that you inspect the source code before installation.
* The plugin is distributed under the MIT license.

By following the steps above, developers can eliminate sandbox false rejections caused by post-training tendencies in models and ensure smooth tool call workflows.