# dsh-fs-sandbox

> Sandbox-enforcing implementation of the DeepSeek Harness filesystem seam: fences write/edit by the per-call sandbox mode (read-only denies mutation, workspace-write contains it to the workspace + temp roots) while reads pass through

## Metadata

- Author: [@deepseek-ai](https://github.com/deepseek-ai)
- Repo: <https://github.com/deepseek-ai/deepseek-harness>
- GitHub: [deepseek-ai/deepseek-harness](https://github.com/deepseek-ai/deepseek-harness)
- Stars: 175,333
- Language: TypeScript
- License: [MIT](https://spdx.org/licenses/MIT.html)
- Homepage: <https://deepseek.com/harness>
- Topics: `ai-agents`, `cordis`, `dsh`, `dsh-plugin`
- Forks: 18,970
- Open Issues: 0
- Last push: 2026-08-19T15:37:57.000Z
- Added: 2026-08-10T00:00:00.000Z

## Install

```bash
dsh plugin --profile web add npm:@deepseek-ai/dsh-fs-sandbox
```

---

This document is auto-generated by [deepseek-plugin.org](https://deepseek-plugin.org). HTML page: [dsh-fs-sandbox](https://deepseek-plugin.org/plugins/deepseek-ai/deepseek-harness/packages/fs/fs-sandbox)
