Microsoft cross-platform sandbox support.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:omdsh-dev/sandbox-mxc
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
English | 中文
A Stent sidecar that runs the DSH bash, PowerShell, and persistent-terminal payloads through MXC without modifying DeepSeek Harness source files. The package is an explicit opt-in bundle: DSH keeps ownership of ctx.sandbox, subprocess I/O, deadlines, signals, terminal sessions, and teardown; Stent supplies the controlled load-time hooks that replace only the consumer call paths.
Package surface
package.json # publishable bundle and public dependencies
cordis.patch.yml # row plus config.stent.patches descriptors
src/stent-entry.ts # named Stent function plugin: name/inject/Config/apply
src/stent-handlers.ts # descriptors and lifecycle-safe handlers
src/index.ts # MXC policy compiler and compatibility provider
src/invariant.ts # package invariant companion
tests/ # policy, provider, hook, and publish-path tests
legacy/ # historical host patch, never applied by this bundle
The package root is the Stent function plugin and deliberately has no default export. The compatibility provider and policy compiler are also available from @deepseek-ai/dsh-sandbox-mxc/provider; new profiles should load the package root through the bundle row.
The MXC runtime is the public @omdsh-dev/mxc-sdk 0.7.0 GitHub Release asset:
https://github.com/omdsh-dev/sandbox-mxc/releases/download/v0.7.0/omdsh-dev-mxc-sdk-0.7.0.tgz
sha256: ffd9a83b9f6a509ee99a59e60ab6bd68889c106d5d8f14d1fa402efd157e8c72
The package keeps the immutable v0.7.0 release URL in dependencies and lists @omdsh-dev/mxc-sdk in bundleDependencies. npm pack therefore places the SDK, its native executors, and its denial-capture assets under node_modules/@omdsh-dev/mxc-sdk inside the published tarball; consumers do not need to resolve the GitHub URL again.
Stent bundle behavior
The row is disabled in ordinary profiles. stent-dsh reads the descriptors under config.stent.patches, installs transformations before target modules load, and enables the row only for the Stent composition:
- id: sandbox-mxc
name: '@deepseek-ai/dsh-sandbox-mxc'
disabled: true
config:
enabled: true
useResultEnvelope: true
stent:
patches:
# The complete descriptor list is shipped in cordis.patch.yml.
Handlers cover the existing public seams:
- foreground and background
@deepseek-ai/dsh-bash-sandboxcalls; - foreground and background
@deepseek-ai/dsh-pwsh-sandboxcalls; - process settlement hooks in the local bash and PowerShell executors;
terminal-bashbackend creation immediately before the local terminal primitive spawns;dsh-subprocess-local.spawnTerminalargument replacement;@deepseek-ai/dsh-sandbox-local.confineterminal-only bypass, preventing the original terminal path from wrapping the MXC launch a second time.
Each confined call prepares one MXC controller with exact argv, cwd, and the scrubbed-plus-explicit environment. The controller settles from the versioned result envelope and is disposed exactly once. The host subprocess or terminal service still owns the process tree, timeout, signal, stdio, and quiescence operations. danger-full-access delegates to the original host call and never invokes MXC. Any MXC qualification or runner failure raises SANDBOX_UNAVAILABLE; it never falls back to an unconfined payload.
The workspace uses pnpm's nodeLinker: hoisted because pnpm cannot materialize bundleDependencies from an isolated linker. Keep this setting for development installs. Use npm pack/npm publish for the final bundled artifact; the current pnpm packer normalizes nested bundled executable modes.
Development
pnpm install
pnpm run typecheck
pnpm run build
pnpm test
pnpm run prepare
npm pack --dry-run
pnpm run test:e2e
The real-executor suites self-skip when the platform-specific binary is unavailable. The release asset contains the native executor and denial-capture files; no GitHub Packages credentials or .npmrc scope override is required.
Model Experience
This package adds no model-visible prompt, tool, or result text. Existing DSH bash and terminal consumers retain their rendering and error semantics; the sandbox seam owns the SANDBOX_UNAVAILABLE diagnostic.
KV Cache effect
No direct invalidation. The existing consumer owns any request-prefix changes.
Known Limitations and Deferred Work
- MXC qualification requires a usable Bubblewrap/user-namespace host on Linux; macOS and Windows acceptance remains platform-dependent, and Windows Tier 3 requires explicit host DACL permission.
- The SDK release is Public Preview. Its policy schema and native backends may change in a later SDK minor version; upgrading requires a deliberate dependency and policy-version review.
- The Stent descriptors are optional because DSH profiles choose bash or PowerShell by platform. A profile that enables the bundle without loading a matching consumer does not receive a hook; the host must still compose a supported sandbox consumer.
legacy/mxc-host-integration.patchis historical evidence only. It is not read, applied, or required by the Stent bundle.
Links
More in this category
toby-bridges/api-relay-audit★ 860
Runs local security audits of AI API relays and LLM proxies from DeepSeek Harness, producing Markdown reports for prompt injection, model substitution signals, tool-call rewriting, error leakage, stream integrity, and profile-gated Web3 risks.
SeaOf0/dsh-redteam-model★ 638
Authorized-security DSH collection: nine work modes (redteam coordinator, pentest, code audit, binary analysis, attack-defense, AV evasion, incident response, cloud security, CTF solving) and fifteen runtime plugins, managed from a settings page with one-click deploy, install, update and uninstall.
howmp/dsh-pentest★ 558
Authorized pentest mode for DeepSeek Harness — exploration chain, assets and findings with a Web view.
PerryLink/dsh-auto-review★ 206
Second-model auto-review on the approval answerer chain: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default.
NanmiCoder/dsh-auto-mode★ 163
Adds an Auto permission preset between Workspace Write and Full access: routine work stays in the official workspace-write sandbox while the current session model reviews escalation and destructive calls, granting one exact wider access once, asking when the intent is ambiguous, and denying critical paths.
PerryLink/dsh-permission-rules★ 114
Claude Code-style declarative permission rules: ordered allow/deny/ask YAML rules matching tool names, arguments, workspace paths, and agent identity on the tools/pre-execute waterfall, with full session-log audit, dry-run mode, and hot reload.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.