Introduction

The DeepSeek Harness (DSH) ecosystem supports extending functionality through plugins. Some GPT/Codex models habitually include the sandbox_permissions and justification fields when performing write operations. DSH defines these two fields as a one-time privilege escalation retry after a sandbox denial. Requests at the same level or narrower are rejected before tool execution. This causes tool calls to fail repeatedly. yaoay/dsh-gpt-compat specifically addresses compatibility issues with GPT/Codex sandbox privilege escalation parameters, cleaning up redundant fields so that tools execute normally according to the current session policy.

Plugin Purpose

yaoay/dsh-gpt-compat is a GPT/Codex sandbox privilege escalation parameter compatibility plugin for DeepSeek Harness. The project is maintained by YaoaY and licensed under the MIT license.

Core Features

The plugin mainly provides the following capabilities:

  • Handling redundant parameters: Identifies and handles redundant sandbox privilege escalation parameters sent by models.
  • Fail-closed security policy: Follows a fail-closed rule and processes only calls allowed by both providers and tools, ensuring secure boundaries.
  • Schema validation: Validates whether the schemas of registered tools declare both DSH’s sandbox_permissions enum and the justification field.
  • Cleaning up redundant fields: Removes these two fields only when the redundancy of the request can be proved, allowing tools to execute according to the current session policy.

Installation and Configuration

Install the plugin to the target DSH profile:

dsh plugin --profile web add dsh-gpt-compat

After the plugin is installed, configuration is required. The default bundle configuration is as follows:

providers: ["*"]
tools: ["bash", "pwsh", "write", "edit"]
Field Type Default Value Description
providers string[] [] Provider IDs that are allowed to be processed. An empty array disables the plugin; an explicit '*' means all providers.
tools string[] ['bash', 'pwsh', 'write', 'edit'] Native DSH privilege escalation tool names that are allowed to be processed. An empty array disables the plugin.

If you need to override the configuration via a profile- or home-level cordis.patch.yml, the full configuration must be restated:

- id: gpt-compat
  config:
    providers: ["your-gpt-provider"]
    tools: ["bash", "write", "edit"]

Usage Notes

  • Environment dependency: The plugin requires Node.js 20 or later.
  • Security rule: The fail-closed rule requires requests that genuinely escalate privileges to include a non-empty justification. The plugin does not downgrade an escalation request missing a non-empty justification into a normal call.
  • Disabling configuration: If providers or tools is empty, the plugin is disabled.
  • Permission note: The plugin runs with the current dsh process permissions. Review the source code and license before installation.

Conclusion

By intelligently cleaning up redundant parameters, this plugin resolves tool call failures caused by conflicts between GPT/Codex models and DSH sandbox policies, improving agent stability.

Plugin catalog: https://www.skillhub.cn/plugins/YaoaY/dsh-gpt-compat
Repository: https://github.com/YaoaY/dsh-gpt-compat