Introduction¶
DeepSeek Harness (DSH) allows models to call tools under specific permissions, such as bash, pwsh, write, and edit. In an All Access session (danger-full-access + never), the model already has the highest privileges and no approval is required. However, the official tool definitions still require the model to provide the sandbox_permissions and justification parameters. This causes the model to fill in these parameters, but then encounter errors during execution due to parameter mismatches or permission conflicts (for example, invalid justification), which can lead to a retry loop.
dsh-sandbox-escalation-fix is a zero-configuration compatibility plugin designed to resolve the above issue. It dynamically projects the tool Schema visible to the model, ensuring that the tool definitions are consistent with the current session’s real-time sandbox mode and security policy.
Plugin Overview¶
- Name: dsh-sandbox-escalation-fix
- Positioning: Session-aware sandbox escalation compatibility plugin for DeepSeek Harness
- Author: HakureiMonika
- Type: Community plugin (admin-security)
Core Features¶
This plugin mainly addresses tool-call failures caused by third-party models in the DSH environment:
* Schema projection per session: Based on the current session’s Sandbox Mode and Approval Policy, it only shows the model the tool options that it can actually use.
* Escalation prompt fix: It fixes incorrect parameter prompts in All Access mode for tools such as bash, pwsh, write, and edit.
* Redundant request handling: It handles duplicate same-mode escalation requests at runtime.
* Full platform support: Supports Windows, Linux, and macOS.
Compatibility and Requirements¶
- DeepSeek Harness version: Compatible with 0.1.1-rc.1 through 0.1.6-alpha.2.
- DeepSeek Desktop version: Supports 2.0.3.
- Node.js version: Requires Node.js ^22.19.0 or >=24.0.0.
- Note: The official DSH version 0.1.6-alpha.2 has already significantly mitigated this issue. The plugin may stop being maintained after the next official release.
Installation and Usage¶
The plugin is designed to be zero-configuration and takes effect automatically after installation. Since specific command-line installation syntax is not provided, manual deployment is recommended using the following approaches:
* Manual deployment: Extract the plugin files and place them in the corresponding Profile directory.
* ZIP package deployment: Use the official Release ZIP package to extract and overwrite the existing files.
Notes¶
- Standalone community plugin: This plugin is developed and maintained by the community. It has not been released, maintained, or endorsed by DeepSeek officially, and it does not modify the DSH core package.
- Maintenance status: Given that DSH 0.1.6-alpha.2 has already greatly mitigated the issue and that this plugin may stop being maintained with the next official release, it is recommended to rely on the official behavior first. Install this plugin only when the retry count, overhead, or stability is unacceptable.
- Permission risk: As a compatibility plugin, please review the source code and license before installation.
Summary¶
dsh-sandbox-escalation-fix uses dynamic Schema projection to fix tool-call errors caused by third-party models in All Access sessions. For model retry loops caused by sandbox escalation parameters, this plugin provides a reliable local solution.
- Documentation directory: dsh-sandbox-escalation-fix - SkillHub
- Source code: GitHub - HakureiMonika/dsh-sandbox-escalation-fix