Preface

Some model callers (for example, gpt-5.6-terra routed through a third-party provider) attach privilege escalation parameters to every tool call. This causes the call to fail during parameter validation. The DSH plugin dsh-gpt-tool-compat resolves this problem.

Plugin Overview

This is a non-destructive DSH tool call compatibility layer maintained by YoungUsing. It intercepts and strips privilege escalation parameters that would inevitably fail validation during the tools/pre-execute phase, restoring the call to the ordinary call the model intended to execute.

Core Features

  1. Intercept and strip: intercepts privilege escalation parameters during the tools/pre-execute phase.
  2. Fault-tolerant handling: strips empty justification or unpaired fields.
  3. Preserves valid escalation: allows genuinely wider escalations (such as read-only -> workspace-write) to pass through.
  4. Exception protection: unexpected exceptions are caught and the original call is allowed to proceed.

Installation and Activation

  1. Install this package into the web profile’s node_modules:
   cd $env:USERPROFILE\.dsh\profiles\web
   npm install <本包路径,如 D:\Users\yq\Documents\code-and-repos\dsh-workspace\dsh-gpt-tool-compat>
  1. Add "dsh-gpt-tool-compat" to the dsh.profile.bundles array in ~\.dsh\profiles\web\package.json:
   "dsh": {
     "profile": {
       "bundles": [
         "@deepseek-ai/dsh-base",
         "@deepseek-ai/dsh-web-app",
         "dsh-gpt-tool-compat"
       ]
     }
   }
  1. Restart the dsh web service and refresh the page.

Option B: Direct line insertion

  1. Install the package into the profile’s node_modules as above.
  2. Insert the following in ~\.dsh\profiles\web\cordis.patch.yml:
   - insert:
       - id: gpt-tool-compat
         name: 'dsh-gpt-tool-compat'
  1. Restart the dsh web service.

Verification and Usage

After restarting the service, test with a tool call that has an empty justification, or observe retries of previously failed conversations. The call should execute normally and no longer report invalid justification / not strictly wider errors.

Principles and Security Boundaries

  • Stripping rules: applies only to four situations that are inevitably rejected under any sandbox mode: an empty/non-string justification, sandbox_permissions and justification not being paired, and an escalation whose requested mode is not strictly wider than the currently effective mode.
  • Real approval: genuinely wider escalations (such as read-only → workspace-write + a valid reason) pass through unchanged and continue through real user approval as usual.
  • Exception handling: any unexpected exception is caught and the original call is allowed to proceed; this layer never makes a call worse.

Notes

  • Strip only parameters that are inevitably rejected under any sandbox mode.
  • Do not modify calls that would originally succeed.
  • Do not bypass real privilege escalation approval.
  • Do not block unhandled calls.
  • Depends on @deepseek-ai/cordis, @deepseek-ai/dsh-sandbox-policy, @deepseek-ai/dsh-tools.
  • Requires Node >= 22.

Conclusion

This plugin provides a compatibility layer that resolves the parameter validation issue caused by certain model callers without breaking security boundaries. Source code and license information can be found on the directory page or GitHub.

Directory page: https://www.skillhub.cn/plugins/YoungUsing/dsh-gpt-tool-compat
GitHub: https://github.com/YoungUsing/dsh-gpt-tool-compat