Support for the microsandbox backend.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:omdsh-dev/sandbox-micro
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
English | 中文
A DSH profile bundle for the fail-closed microsandbox microVM capability. The root package contains the ctx.microsandbox provider and exports the model-facing tools as @deepseek-ai/dsh-sandbox-microsandbox/tool.
Repository shape
package.json # provider/tool package and dsh.bundle manifest
cordis.patch.yml # dormant provider and tool rows
src/ # provider, runtime, resolver, and tool subpath
lib/ # generated install artifacts
legacy/ # source-compatible host integration patch for older DSH snapshots
docs/ # detailed provider/tool references
tests/provider/ # provider, resolver, SDK, and host tests
tests/tool/ # model-tool and renderer tests
The single root artifact keeps Git/profile installation self-contained while preserving two Cordis entry points:
- id: microsandbox
name: '@deepseek-ai/dsh-sandbox-microsandbox'
- id: tool-microsandbox
name: '@deepseek-ai/dsh-sandbox-microsandbox/tool'
Both rows are disabled by the bundle. To enable the capability, a profile must explicitly enable the provider with config.enabled: true and enable the tool row separately. This prevents installation from starting a microVM capability or exposing model-facing tools implicitly.
Capability boundary
ctx.microsandbox is an environment-coherent microVM service, not a dsh-sandbox same-world provider. It uses the pinned microsandbox@0.6.7 SDK, package-owned msb resolution, bounded functional qualification, and fail-closed platform checks. It never degrades to unconfined host execution.
The tool entry exposes:
microsandbox_exec exact argv execution with captured output
microsandbox_fs guest file read, write, and directory listing
The old host integration patch remains under legacy/ for DSH snapshots that do not yet provide the provider/tool catalog and composition seams. A new bundle layer does not modify DSH host source.
Development
A full typecheck expects sibling checkouts:
~/git/deepseek-harness
~/git/sandbox-micro
pnpm install
pnpm run typecheck
pnpm test
pnpm run build
The prepare script builds provider, invariant, and tool entries directly from src/, so a Git install does not require sibling project references. pnpm 10 may require the profile to allow the package's prepare script; only approve a pinned, trusted checkout.
Model Experience
The provider adds no prompt text. The tool subpath adds microsandbox_exec and microsandbox_fs to the authoritative tools service; their output preserves guest exit codes, captured streams, runner failures, timeout/abort classification, and guest file content.
Known Limitations and Deferred Work
- Linux requires
/dev/kvm; unsupported or unqualified hosts remain unavailable. - macOS Apple Silicon real-host acceptance is not included in the first release posture.
- Secrets, network policy, snapshots, and image/volume lifecycle tools remain provider-only or fail closed.
- The external SDK and platform binaries are pinned to
0.6.7and require their corresponding registry packages.
Links
More in this category
toby-bridges/api-relay-audit★ 860
Runs local security audits of AI API relays and LLM proxies from DeepSeek Harness, producing Markdown reports for prompt injection, model substitution signals, tool-call rewriting, error leakage, stream integrity, and profile-gated Web3 risks.
SeaOf0/dsh-redteam-model★ 638
Authorized-security DSH collection: nine work modes (redteam coordinator, pentest, code audit, binary analysis, attack-defense, AV evasion, incident response, cloud security, CTF solving) and fifteen runtime plugins, managed from a settings page with one-click deploy, install, update and uninstall.
howmp/dsh-pentest★ 558
Authorized pentest mode for DeepSeek Harness — exploration chain, assets and findings with a Web view.
PerryLink/dsh-auto-review★ 206
Second-model auto-review on the approval answerer chain: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default.
NanmiCoder/dsh-auto-mode★ 163
Adds an Auto permission preset between Workspace Write and Full access: routine work stays in the official workspace-write sandbox while the current session model reviews escalation and destructive calls, granting one exact wider access once, asking when the intent is ambiguous, and denying critical paths.
PerryLink/dsh-permission-rules★ 114
Claude Code-style declarative permission rules: ordered allow/deny/ask YAML rules matching tool names, arguments, workspace paths, and agent identity on the tools/pre-execute waterfall, with full session-log audit, dry-run mode, and hot reload.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.