插件目录 / Security / dsh-sandbox-audit
dsh-sandbox-audit
已验证 · 实测可装 zoahdev
功能简介
沙箱策略一致性静态审计
可用 — 实测通过,早期项目
沙箱策略一致性静态审计 实测能干净安装、正常启动。早期项目,但功能可用。
「已验证」表示我们的自动化 CI 在干净 profile 里实际执行了 dsh plugin add 并启动成功——仅此而已。功能描述与版本兼容性均为作者声明。这不是安全审计,也不代表对第三方代码的背书。
README
dsh-sandbox-audit
Static sandbox-policy consistency audit for DeepSeek Harness presets and profiles.
It reads a cordis.patch.yml / agent.cordis.yml and reports every tool whose
sandbox wiring is inconsistent with the policy it claims to enforce — before you
ship the profile, not after an agent writes outside its workspace.
Community security tool. Not an official DeepSeek project and not a
replacement for the runtime sandbox; it audits the configuration that wires
tools to that sandbox.
The three families it catches
The audit is grounded in the upstream sandbox model (packages/sandbox,packages/bundle/base/cordis.patch.yml), not in guessed rules:
| Severity | Finding | Upstream discussion |
|---|---|---|
| HIGH | A mutating filesystem tool (str_replace_editor, tool-fs) shares a bare fs-local backend. A bare backend silently ignores the policy, so read-only / workspace-write are only enforced if the tool self-enforces ctx.sandboxPolicy. |
#2066 |
| MEDIUM | A search tool (tool-fs-search / glob / grep) mounts no fs and reads outside the write policy ("co-located requirement, not runtime-validated"). |
#951 |
| MEDIUM | A shell tool has no operation-level destructive guard, so rm -rf <workspace> is indistinguishable from deleting a build dir. |
#149 |
Install / run
git clone https://github.com/zoahdev/dsh-sandbox-audit
cd dsh-sandbox-audit
pnpm install
node bin/dsh-sandbox-audit.mjs path/to/agent.cordis.yml
node bin/dsh-sandbox-audit.mjs path/to/cordis.patch.yml --json
Exit code is 1 when any HIGH finding is present, so it can gate CI.
Real output
Against the shipped minimal preset:
# dsh-sandbox-audit report
- default sandbox mode: read-only (default)
- findings: 1 high, 2 medium
## [HIGH] Mutating filesystem tool `str-replace-editor` shares a bare `fs-local` backend
- realm: root/filesystem
- ... enforce at the tool layer (upstream fix for #2066) ...
Against the base bundle (standard presets) it reports 0 high — the mutating
tools there are fenced by dsh-fs-sandbox, which is exactly the point: the tool
shows where a preset diverges from the confined baseline.
Why this exists
DeepSeek Harness's policy is a path-space, not an operation-space, and tools
join realms in composable ways. The same preset shape can be safe under a
confining backend and unsafe under a bare one. This tool makes that difference
visible and traceable to a source line and a discussion.
中文说明
dsh-sandbox-audit 是 DeepSeek Harness 的沙箱策略一致性静态审计工具:读取cordis.patch.yml / agent.cordis.yml,找出「工具接线」与「它声称执行的策略」不一致的地方。
它只审计配置,不替代运行时沙箱;规则全部溯源到上游源码模型,覆盖三类问题:
- HIGH:会写文件的工具(
str_replace_editor/tool-fs)挂在一个裸fs-local后端上,
而裸后端会静默忽略策略(read-only/workspace-write只有工具自己ctx.sandboxPolicy
自执行时才生效)。见 #2066。 - MEDIUM:搜索工具(
tool-fs-search/ glob / grep)不挂fs,读范围不受写策略约束。见
#951。 - MEDIUM:shell 工具没有操作级破坏性门禁,
rm -rf <workspace>与删 build 目录无法区分。见
#149。
有 HIGH 结果时退出码为 1,可直接接入 CI 门禁。这是社区安全工具,非官方项目。
License
MIT
安装
装一次目录插件,之后本站所有插件都能让 DeepSeek Harness 自动找、自动装:
dsh plugin add dshbase-catalog 然后对 agent 说「帮我装 dsh-sandbox-audit」,它会在目录里找到并自动安装。文档:dshbase-catalog · 已验证场景包。
该插件是 GitHub 源码(未发 npm)——直接从仓库装:
Web profile:
dsh plugin --profile web add github:zoahdev/dsh-sandbox-audit Headless(CLI)profile:
dsh plugin --profile headless add github:zoahdev/dsh-sandbox-audit 实测报告
验证通过:从 GitHub 源码完成 L1 安装 + L2 加载 + L3 运行(dsh 0.1.0-rc.6)。
使用场景
加固 agent 或其工作区——扫描、净化或审计——先拦下不可信内容和代码。
适合谁
在意供应链和提示注入风险、想要内置防护的人。
二次开发建议
检测器和策略是缝——加规则、作用域或更丰富的被标记项审计日志。