tancheng33/dsh-code-runtime-container

Container-isolated backend for the ctx.codeRuntime seam: each Code Mode program runs in a fresh container with no network, a read-only rootfs, dropped capabilities, and kernel-enforced memory, CPU and pid ceilings.

Moves Code Mode execution off the agent's own process. A run_code program is model-written code, and the shipped worker-thread backend executes it inside the agent process with the agent's network access, filesystem and environment; this backend instead spawns a fresh container per run with no network, a read-only root filesystem, all capabilities dropped and kernel ceilings on memory, CPU and pids, so a deployment that cannot accept bash-equivalent containment gets a real isolation boundary for code execution. The README contrasts the two substrates side by side and documents the semantics the seam has to preserve.

Development & Runtime ★ 0 updated 2026-08-16
View on GitHub ↗

Install

⚠️ Install command not yet confirmed — check the README on GitHub for the exact command.

Compatibility

README: it implements the DeepSeek Harness code-execution seam (ctx.codeRuntime) with a container substrate. The shipped worker-thread backend runs Code Mode programs in the agent's own process; this backend runs each program in a fresh container with --network=none, a read-only root filesystem, every capability dropped and kernel-enforced memory, CPU and pid ceilings. The README quotes the upstream repository's own statement that only the worker-thread backend ships and that a hard security boundary awaits a container backend, and it publishes a threat model and a limitations section.

Details

Recent updates

The README documents the motivation, the threat model, the semantics and the limitations rather than a release-by-release table.

FAQ

Why would I need this?
The README's argument is that the shipped worker-thread backend runs Code Mode programs inside the agent's own process with the agent's network and filesystem access, and that a deployment which cannot accept that needs a container backend.
What isolation does it provide?
Per the README: a fresh container per run, --network=none, a read-only root filesystem, every capability dropped, and kernel-enforced memory, CPU and pid ceilings.
How do I install it?
The README's line names the bundle but leaves the --profile value blank, and the npm name returned 404 on 2026-09-17, so confirm the package source and use your own profile name.

More plugins in Development & Runtime

Browse more in Development & Runtime

Guides for Development & Runtime plugins