dsh-fs-sandbox 使用指南
在文件系统 seam 上强制沙箱隔离,按调用模式(read-only/workspace-write)控制写操作,读取始终放行,需配合 sandboxPolicy 使用,为 AI Agent 提供受控的文件系统访问边界
本文为派生内容(基于 wiki / faq / compatibility_json 自动组装),非 AI 即时创作。
本文由本站基于该插件已收录的字段自动派生(wiki / faq / compatibility_json / readme),非 AI 即时创作。每节末尾标源字段。
快速上手
在文件系统 seam 上强制沙箱隔离,按调用模式(read-only/workspace-write)控制写操作,读取始终放行,需配合 sandboxPolicy 使用,为 AI Agent 提供受控的文件系统访问边界
— 源: plugins.ai_summary
安装与验证
dsh plugin --profile web add npm:@deepseek-ai/dsh-fs-sandbox
复制以上命令在 DSH Web Profile 内运行。安装完成后在「插件列表」启用即可。
— 源: plugins.install
关键要点
read-only— denies every mutation with the structuredFS_SANDBOX_DENIED.danger-full-access— delegates unfenced.- Requires
ctx.sandboxPolicy— tools use it to resolve each session policy and the backend uses it for agentless-call fallbacks; the backend does not confine without it composed.
— 源: plugin_wiki.readme_zh (fallback readme_raw)
踩坑提醒
安装前请审阅上游仓库;本指南基于已收录字段自动派生,可能滞后于最新版本。如发现与官方文档冲突,请以上游为准。
— 来源:通用规则