dshbase

Plugin directory / Developer / sandbox-micro

sandbox-micro

Unverified omdsh-dev

✓ Actively maintained Builds on 4 official DSH packages Pure TypeScript

View on GitHub ↗ ← Back to plugin directory

3Stars
0Forks
0Open issues
TypeScriptLanguage
2026-08-15Last push
Cross-platformPlatform

What it does

microsandbox support

Our take
Unverified — not yet verified

microsandbox support Not yet verified — install and test it yourself.

“Unverified” means our automated CI has not yet installed this plugin. Feature descriptions and version compatibility are the author’s claims. This is not a security audit and not an endorsement of third-party code.

Plugin author? Get the “Verified” label — submit your own evidence (screenshots, logs, or a short demo) and we'll review and flip the badge.

Submit verification evidence ↗

README

@deepseek-ai/dsh-sandbox-microsandbox

English | 中文

A DSH profile bundle for the fail-closed microsandbox microVM capability. The root package contains the ctx.microsandbox provider and exports the model-facing tools as @deepseek-ai/dsh-sandbox-microsandbox/tool.

Repository shape

package.json              # provider/tool package and dsh.bundle manifest
cordis.patch.yml          # dormant provider and tool rows
src/                      # provider, runtime, resolver, and tool subpath
lib/                      # generated install artifacts
legacy/                   # source-compatible host integration patch for older DSH snapshots
docs/                     # detailed provider/tool references
tests/provider/            # provider, resolver, SDK, and host tests
tests/tool/                # model-tool and renderer tests

The single root artifact keeps Git/profile installation self-contained while preserving two Cordis entry points:

- id: microsandbox
  name: '@deepseek-ai/dsh-sandbox-microsandbox'

- id: tool-microsandbox
  name: '@deepseek-ai/dsh-sandbox-microsandbox/tool'

Both rows are disabled by the bundle. To enable the capability, a profile must explicitly enable the provider with config.enabled: true and enable the tool row separately. This prevents installation from starting a microVM capability or exposing model-facing tools implicitly.

Capability boundary

ctx.microsandbox is an environment-coherent microVM service, not a dsh-sandbox same-world provider. It uses the pinned [email protected] SDK, package-owned msb resolution, bounded functional qualification, and fail-closed platform checks. It never degrades to unconfined host execution.

The tool entry exposes:

microsandbox_exec  exact argv execution with captured output
microsandbox_fs    guest file read, write, and directory listing

The old host integration patch remains under legacy/ for DSH snapshots that do not yet provide the provider/tool catalog and composition seams. A new bundle layer does not modify DSH host source.

Development

A full typecheck expects sibling checkouts:

~/git/deepseek-harness
~/git/sandbox-micro
pnpm install
pnpm run typecheck
pnpm test
pnpm run build

The prepare script builds provider, invariant, and tool entries directly from src/, so a Git install does not require sibling project references. pnpm 10 may require the profile to allow the package's prepare script; only approve a pinned, trusted checkout.

Model Experience

The provider adds no prompt text. The tool subpath adds microsandbox_exec and microsandbox_fs to the authoritative tools service; their output preserves guest exit codes, captured streams, runner failures, timeout/abort classification, and guest file content.

Known Limitations and Deferred Work

  • Linux requires /dev/kvm; unsupported or unqualified hosts remain unavailable.
  • macOS Apple Silicon real-host acceptance is not included in the first release posture.
  • Secrets, network policy, snapshots, and image/volume lifecycle tools remain provider-only or fail closed.
  • The external SDK and platform binaries are pinned to 0.6.7 and require their corresponding registry packages.

Install

🧩 Let your agent install it (recommended)

Install the catalog once, then DeepSeek Harness can find and install any plugin from this site automatically:

dsh plugin add dshbase-catalog

Then say "install sandbox-micro for me" — your agent finds it in the directory and installs it. Docs: dshbase-catalog · verified packs.

This plugin is GitHub source (not published to npm) — install it straight from the repo:

Web profile:

dsh plugin --profile web add github:omdsh-dev/sandbox-micro

Headless (CLI) profile:

dsh plugin --profile headless add github:omdsh-dev/sandbox-micro

Test report

Not yet L3-verified — see failure note below if we already ran it.

Status: pending
Note: 验证: install-fail (0.1.0-rc.6) Browse all pending failures →

When to use it

Extend the agent's coding surface — give it a new tool, workflow, or integration so it handles a dev task it couldn't before.

Who it's for

Developers who want dsh to behave like a teammate on real codebases — editing, running, and verifying changes rather than just answering.

For developers — extending it

The tool/command surface is the seam: expose more of the SDK, add smarter context wiring, or tighten the loop between code changes and verification.

Security: not yet scanned — our daily static scan will cover it shortly.

Share this badge

More in Developer

Browse all 7795 plugins →