dshbase

插件目录 / Security / dsh-sandbox-audit

dsh-sandbox-audit

已验证 · 实测可装 zoahdev

✓ 持续维护

查看 GitHub ↗ ← 返回插件目录

2Stars
0Forks
0未关闭 issue
JavaScript语言
2026-08-16最近推送
跨平台平台

功能简介

沙箱策略一致性静态审计

✅
我们的评价
可用 — 实测通过,早期项目

沙箱策略一致性静态审计 实测能干净安装、正常启动。早期项目,但功能可用。

「已验证」表示我们的自动化 CI 在干净 profile 里实际执行了 dsh plugin add 并启动成功——仅此而已。功能描述与版本兼容性均为作者声明。这不是安全审计,也不代表对第三方代码的背书。

README

dsh-sandbox-audit

Static sandbox-policy consistency audit for DeepSeek Harness presets and profiles.

It reads a cordis.patch.yml / agent.cordis.yml and reports every tool whose
sandbox wiring is inconsistent with the policy it claims to enforce — before you
ship the profile, not after an agent writes outside its workspace.

Community security tool. Not an official DeepSeek project and not a
replacement for the runtime sandbox; it audits the configuration that wires
tools to that sandbox.

The three families it catches

The audit is grounded in the upstream sandbox model (packages/sandbox,
packages/bundle/base/cordis.patch.yml), not in guessed rules:

Severity Finding Upstream discussion
HIGH A mutating filesystem tool (str_replace_editor, tool-fs) shares a bare fs-local backend. A bare backend silently ignores the policy, so read-only / workspace-write are only enforced if the tool self-enforces ctx.sandboxPolicy. #2066
MEDIUM A search tool (tool-fs-search / glob / grep) mounts no fs and reads outside the write policy ("co-located requirement, not runtime-validated"). #951
MEDIUM A shell tool has no operation-level destructive guard, so rm -rf <workspace> is indistinguishable from deleting a build dir. #149

Install / run

git clone https://github.com/zoahdev/dsh-sandbox-audit
cd dsh-sandbox-audit
pnpm install

node bin/dsh-sandbox-audit.mjs path/to/agent.cordis.yml
node bin/dsh-sandbox-audit.mjs path/to/cordis.patch.yml --json

Exit code is 1 when any HIGH finding is present, so it can gate CI.

Real output

Against the shipped minimal preset:

# dsh-sandbox-audit report
- default sandbox mode: read-only (default)
- findings: 1 high, 2 medium

## [HIGH] Mutating filesystem tool `str-replace-editor` shares a bare `fs-local` backend
- realm: root/filesystem
- ... enforce at the tool layer (upstream fix for #2066) ...

Against the base bundle (standard presets) it reports 0 high — the mutating
tools there are fenced by dsh-fs-sandbox, which is exactly the point: the tool
shows where a preset diverges from the confined baseline.

Why this exists

DeepSeek Harness's policy is a path-space, not an operation-space, and tools
join realms in composable ways. The same preset shape can be safe under a
confining backend and unsafe under a bare one. This tool makes that difference
visible and traceable to a source line and a discussion.

中文说明

dsh-sandbox-audit 是 DeepSeek Harness 的沙箱策略一致性静态审计工具:读取
cordis.patch.yml / agent.cordis.yml,找出「工具接线」与「它声称执行的策略」不一致的地方。

它只审计配置,不替代运行时沙箱;规则全部溯源到上游源码模型,覆盖三类问题:

  • HIGH:会写文件的工具(str_replace_editor / tool-fs)挂在一个裸 fs-local 后端上,
    而裸后端会静默忽略策略(read-only / workspace-write 只有工具自己 ctx.sandboxPolicy
    自执行时才生效)。见 #2066。
  • MEDIUM:搜索工具(tool-fs-search / glob / grep)不挂 fs,读范围不受写策略约束。见
    #951。
  • MEDIUM:shell 工具没有操作级破坏性门禁,rm -rf <workspace> 与删 build 目录无法区分。见
    #149。

有 HIGH 结果时退出码为 1,可直接接入 CI 门禁。这是社区安全工具,非官方项目。

License

MIT

安装

🧩 让 Agent 自动装(推荐)

装一次目录插件,之后本站所有插件都能让 DeepSeek Harness 自动找、自动装:

dsh plugin add dshbase-catalog

然后对 agent 说「帮我装 dsh-sandbox-audit」,它会在目录里找到并自动安装。文档:dshbase-catalog · 已验证场景包。

该插件是 GitHub 源码(未发 npm)——直接从仓库装:

Web profile:

dsh plugin --profile web add github:zoahdev/dsh-sandbox-audit

Headless(CLI)profile:

dsh plugin --profile headless add github:zoahdev/dsh-sandbox-audit

实测报告

验证通过:从 GitHub 源码完成 L1 安装 + L2 加载 + L3 运行(dsh 0.1.0-rc.6)。

使用场景

加固 agent 或其工作区——扫描、净化或审计——先拦下不可信内容和代码。

适合谁

在意供应链和提示注入风险、想要内置防护的人。

二次开发建议

检测器和策略是缝——加规则、作用域或更丰富的被标记项审计日志。

安全:尚未扫描——我们的每日静态扫描将很快覆盖它。

分享徽章

Security 里更多

浏览全部 7797 个插件 →