Plugin directory / Developer / sandbox-micro
sandbox-micro
Unverified omdsh-dev
What it does
microsandbox support
Unverified — not yet verified
microsandbox support Not yet verified — install and test it yourself.
“Unverified” means our automated CI has not yet installed this plugin. Feature descriptions and version compatibility are the author’s claims. This is not a security audit and not an endorsement of third-party code.
README
@deepseek-ai/dsh-sandbox-microsandbox
English | 中文
A DSH profile bundle for the fail-closed microsandbox microVM capability. The root package contains the ctx.microsandbox provider and exports the model-facing tools as @deepseek-ai/dsh-sandbox-microsandbox/tool.
Repository shape
package.json # provider/tool package and dsh.bundle manifest
cordis.patch.yml # dormant provider and tool rows
src/ # provider, runtime, resolver, and tool subpath
lib/ # generated install artifacts
legacy/ # source-compatible host integration patch for older DSH snapshots
docs/ # detailed provider/tool references
tests/provider/ # provider, resolver, SDK, and host tests
tests/tool/ # model-tool and renderer tests
The single root artifact keeps Git/profile installation self-contained while preserving two Cordis entry points:
- id: microsandbox
name: '@deepseek-ai/dsh-sandbox-microsandbox'
- id: tool-microsandbox
name: '@deepseek-ai/dsh-sandbox-microsandbox/tool'
Both rows are disabled by the bundle. To enable the capability, a profile must explicitly enable the provider with config.enabled: true and enable the tool row separately. This prevents installation from starting a microVM capability or exposing model-facing tools implicitly.
Capability boundary
ctx.microsandbox is an environment-coherent microVM service, not a dsh-sandbox same-world provider. It uses the pinned [email protected] SDK, package-owned msb resolution, bounded functional qualification, and fail-closed platform checks. It never degrades to unconfined host execution.
The tool entry exposes:
microsandbox_exec exact argv execution with captured output
microsandbox_fs guest file read, write, and directory listing
The old host integration patch remains under legacy/ for DSH snapshots that do not yet provide the provider/tool catalog and composition seams. A new bundle layer does not modify DSH host source.
Development
A full typecheck expects sibling checkouts:
~/git/deepseek-harness
~/git/sandbox-micro
pnpm install
pnpm run typecheck
pnpm test
pnpm run build
The prepare script builds provider, invariant, and tool entries directly from src/, so a Git install does not require sibling project references. pnpm 10 may require the profile to allow the package's prepare script; only approve a pinned, trusted checkout.
Model Experience
The provider adds no prompt text. The tool subpath adds microsandbox_exec and microsandbox_fs to the authoritative tools service; their output preserves guest exit codes, captured streams, runner failures, timeout/abort classification, and guest file content.
Known Limitations and Deferred Work
- Linux requires
/dev/kvm; unsupported or unqualified hosts remain unavailable. - macOS Apple Silicon real-host acceptance is not included in the first release posture.
- Secrets, network policy, snapshots, and image/volume lifecycle tools remain provider-only or fail closed.
- The external SDK and platform binaries are pinned to
0.6.7and require their corresponding registry packages.
Install
Install the catalog once, then DeepSeek Harness can find and install any plugin from this site automatically:
dsh plugin add dshbase-catalog Then say "install sandbox-micro for me" — your agent finds it in the directory and installs it. Docs: dshbase-catalog · verified packs.
This plugin is GitHub source (not published to npm) — install it straight from the repo:
Web profile:
dsh plugin --profile web add github:omdsh-dev/sandbox-micro Headless (CLI) profile:
dsh plugin --profile headless add github:omdsh-dev/sandbox-micro Test report
Not yet L3-verified — see failure note below if we already ran it.
Note: 验证: install-fail (0.1.0-rc.6) Browse all pending failures →
When to use it
Extend the agent's coding surface — give it a new tool, workflow, or integration so it handles a dev task it couldn't before.
Who it's for
Developers who want dsh to behave like a teammate on real codebases — editing, running, and verifying changes rather than just answering.
For developers — extending it
The tool/command surface is the seam: expose more of the SDK, add smarter context wiring, or tighten the loop between code changes and verification.