dsh-sandbox-arg-guard

Source candidate

Keeps a redundant sandbox-escalation argument from failing a tool call. Escalating tools (pwsh, bash, write, edit) advertise the full sandbox_permissions enum, but DSH only accepts a level strictly wider than the one already in effect — a check its own source calls 'deliberately not a schema constraint'. A model that reflexively passes the argument therefore picks the level it is already at and the call dies before running with 'sandbox escalation to "workspace-write" is not strictly wider than this call's current "workspace-write" mode', costing some models a whole turn of retries. This plugin registers one tools/execute waterfall listener and, only on that documented rejection and only when the arguments really carried an escalation field, re-issues the identical call once without it. Safe by DSH's own documentation: the rejection precedes any execution ('nothing has run'), and the corrected call cannot match again, so the retry is loop-free. Reproduced and verified end to end — before: isError true, the command never ran; after: the command's real output, isError false, one tool/call and one tool/result. Zero dependencies.

Author: apex-mochen · Security & Permissions · Catalog snapshot: 2026-09-19

What it may solve

Keeps a redundant sandbox-escalation argument from failing a tool call. Escalating tools (pwsh, bash, write, edit) advertise the full sandbox_permissions enum, but DSH only accepts a level strictly wider than the one already in effect — a check its own source calls 'deliberately not a schema constraint'. A model that reflexively passes the argument therefore picks the level it is already at and the call dies before running with 'sandbox escalation to "workspace-write" is not strictly wider than this call's current "workspace-write" mode', costing some models a whole turn of retries. This plugin registers one tools/execute waterfall listener and, only on that documented rejection and only when the arguments really carried an escalation field, re-issues the identical call once without it. Safe by DSH's own documentation: the rejection precedes any execution ('nothing has run'), and the corrected call cannot match again, so the retry is loop-free. Reproduced and verified end to end — before: isError true, the command never ran; after: the command's real output, isError false, one tool/call and one tool/result. Zero dependencies.

Imported third-party catalog description; not a Registry verification conclusion.

Sources and public signals

apex-mochen/dsh-sandbox-arg-guard

0 stars · — downloads

Signals were provided by the source catalog and do not imply quality or safety. 2026-09-19

What can currently be confirmed

Not analyzed

DSH compatibility

No exact-version test is available.

Not analyzed

Security analysis

No Registry security conclusion is available.

Not analyzed

Functional verification

No functional smoke evidence is available.

Not analyzed

Permissions

Plugin permissions have not been resolved.

Not analyzed

Package integrity

Package structure and integrity have not been analyzed.

Continue with the latest plugin manager

Describe your task in a DSH conversation and mention dsh-sandbox-arg-guard. After installing or updating the manager from npm latest, it can find this candidate through Registry, then inspect its actual source and version locally.

Install or update the plugin manager (latest)