Diagnose Gateway
openclaw/openclaw
Diagnose Gateway, config, secrets, channels, and port failures with read-only one-liners.
Agent skill
by Zhou-Yujing114514 in Zhou-Yujing114514/deepseek-harness-linux
Use on Windows for unexpected DSH sandbox access denials: workspace writes or listing fail, or an ordinarily readable path cannot be read.
$ npx skills add Zhou-Yujing114514/deepseek-harness-linux --skill diagnose-windows-sandbox-acl -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Zhou-Yujing114514/deepseek-harness-linux diagnose-windows-sandbox-acl --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Zhou-Yujing114514/deepseek-harness-linux.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/sandbox/sandbox-windows-acl/assets/diagnose-windows-sandbox-acl .claude/skills/diagnose-windows-sandbox-acl && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "diagnose-windows-sandbox-acl" agent skill from https://github.com/Zhou-Yujing114514/deepseek-harness-linux/tree/master/packages/sandbox/sandbox-windows-acl/assets/diagnose-windows-sandbox-acl into .claude/skills/diagnose-windows-sandbox-acl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "diagnose-windows-sandbox-acl", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Zhou-Yujing114514/deepseek-harness-linux/tree/master/packages/sandbox/sandbox-windows-acl/assets/diagnose-windows-sandbox-aclType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Zhou-Yujing114514/deepseek-harness-linux --skill diagnose-windows-sandbox-acl -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Zhou-Yujing114514/deepseek-harness-linux diagnose-windows-sandbox-acl --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Zhou-Yujing114514/deepseek-harness-linux.git skills-src && mkdir -p .agents/skills && cp -r skills-src/packages/sandbox/sandbox-windows-acl/assets/diagnose-windows-sandbox-acl .agents/skills/diagnose-windows-sandbox-acl && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "diagnose-windows-sandbox-acl" agent skill from https://github.com/Zhou-Yujing114514/deepseek-harness-linux/tree/master/packages/sandbox/sandbox-windows-acl/assets/diagnose-windows-sandbox-acl into .agents/skills/diagnose-windows-sandbox-acl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "diagnose-windows-sandbox-acl", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Zhou-Yujing114514/deepseek-harness-linux --skill diagnose-windows-sandbox-acl -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Zhou-Yujing114514/deepseek-harness-linux diagnose-windows-sandbox-acl --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Zhou-Yujing114514/deepseek-harness-linux.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/packages/sandbox/sandbox-windows-acl/assets/diagnose-windows-sandbox-acl .cursor/skills/diagnose-windows-sandbox-acl && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "diagnose-windows-sandbox-acl" agent skill from https://github.com/Zhou-Yujing114514/deepseek-harness-linux/tree/master/packages/sandbox/sandbox-windows-acl/assets/diagnose-windows-sandbox-acl into .cursor/skills/diagnose-windows-sandbox-acl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "diagnose-windows-sandbox-acl", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Zhou-Yujing114514/deepseek-harness-linux.git --path packages/sandbox/sandbox-windows-acl/assets/diagnose-windows-sandbox-acl--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Zhou-Yujing114514/deepseek-harness-linux --skill diagnose-windows-sandbox-acl -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Zhou-Yujing114514/deepseek-harness-linux diagnose-windows-sandbox-acl --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Zhou-Yujing114514/deepseek-harness-linux.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/packages/sandbox/sandbox-windows-acl/assets/diagnose-windows-sandbox-acl .gemini/skills/diagnose-windows-sandbox-acl && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "diagnose-windows-sandbox-acl" agent skill from https://github.com/Zhou-Yujing114514/deepseek-harness-linux/tree/master/packages/sandbox/sandbox-windows-acl/assets/diagnose-windows-sandbox-acl into .gemini/skills/diagnose-windows-sandbox-acl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "diagnose-windows-sandbox-acl", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Zhou-Yujing114514/deepseek-harness-linux diagnose-windows-sandbox-aclInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Zhou-Yujing114514/deepseek-harness-linux --skill diagnose-windows-sandbox-acl -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Zhou-Yujing114514/deepseek-harness-linux.git skills-src && mkdir -p .github/skills && cp -r skills-src/packages/sandbox/sandbox-windows-acl/assets/diagnose-windows-sandbox-acl .github/skills/diagnose-windows-sandbox-acl && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "diagnose-windows-sandbox-acl" agent skill from https://github.com/Zhou-Yujing114514/deepseek-harness-linux/tree/master/packages/sandbox/sandbox-windows-acl/assets/diagnose-windows-sandbox-acl into .github/skills/diagnose-windows-sandbox-acl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "diagnose-windows-sandbox-acl", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Zhou-Yujing114514/deepseek-harness-linux --skill diagnose-windows-sandbox-acl -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Zhou-Yujing114514/deepseek-harness-linux diagnose-windows-sandbox-acl --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Zhou-Yujing114514/deepseek-harness-linux.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/packages/sandbox/sandbox-windows-acl/assets/diagnose-windows-sandbox-acl .opencode/skills/diagnose-windows-sandbox-acl && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "diagnose-windows-sandbox-acl" agent skill from https://github.com/Zhou-Yujing114514/deepseek-harness-linux/tree/master/packages/sandbox/sandbox-windows-acl/assets/diagnose-windows-sandbox-acl into .opencode/skills/diagnose-windows-sandbox-acl/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "diagnose-windows-sandbox-acl", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
diagnose-windows-sandbox-aclUse on Windows for unexpected DSH sandbox access denials: workspace writes or listing fail, or an ordinarily readable path cannot be read.
Diagnose Windows Sandbox Acl is an agent skill from Zhou-Yujing114514/deepseek-harness-linux. Use on Windows for unexpected DSH sandbox access denials: workspace writes or listing fail, or an ordinarily readable path cannot be read. One bundled command inspects the path and every ancestor and repairs the ACL problems it proves in that same run. Expected confinement denials need no ACL repair.
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts.
The repository describes itself as: First-class Linux packaging for DeepSeek Harness desktop — AppImage, .deb, .tar.gz for x64/arm64, built by native CI. The licence is MIT.
Read from SKILL.md and the folder at commit 35a829f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (PowerShell), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Diagnose Windows Sandbox Acl loads about 1.7k tokens when it runs. Until then it costs about 83 tokens; SKILL.md has 922 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from Zhou-Yujing114514/deepseek-harness-linux at commit 35a829f, republished under its MIT licence (© Zhou-Yujing114514). 922 words, ~1,679 tokens.
.claude/skills/diagnose-windows-sandbox-acl/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Write every approval request in plain words, in the user's language. The prompt is all the user reads before widening access, so it must stand alone: which folder the script touches, that it adds the signed-in user's full-control entry where a right is missing and removes foreign package entries, that file contents and owners are unchanged, and that the printed recovery command undoes each change. Keep error codes, WRITE_DAC/WRITE_OWNER, S-1-15-2-* SIDs, icacls, ACL, ACE, verdict names and switches out of the request: write Windows file permissions, not ACL or ACE. Ask once, for one command.
The script has no modes. -Path, -AllowRoot and -Out read the path and every ancestor and repair what the observations prove, in the same run:
WRITE_DAC or WRITE_OWNER receive a full-control allow ACE for the signed-in user, because DSH cannot provision its workspace grant without them;S-1-15-2-*, except the well-known groups ending in 1 or 2) are removed at their sources, ancestor first, which also removes those packages' access;truncated and unreadable directories; if truncated, pass the still-failing deeper path once more.Every change is backed up, then verified by re-reading it. -AllowRoot bounds all of it: an object is changed only when it is that directory or strictly inside it, so a workspace root can repair itself. Never split this into a diagnostic call and a repair call, never ask twice for one repair, and never pass a mode switch that does not exist.
& '<skill-directory>\scripts\diagnose-windows-sandbox-acl.ps1' -Path '<failing-path>' -AllowRoot '<authorized-directory>' -Out '<recovery-directory>'
exit $LASTEXITCODESubstitute full, quoted paths. Keep -Out persistent and user-owned, preferably beside the failing workspace; never use the skill resource directory, which is deleted when the skill unloads. Pass one path per invocation.
Repeat the failing operation once confined. The script writes permissions, which the confined token cannot do — run it there and it would report the sandbox's own restriction as a missing right — so request approval for that one command and run it unconfined. A confined run of the script is never useful. Unconfined does not elevate the Windows token.
Diagnose unexpected denials of workspace writes, listing, or plainly readable paths; explain expected ones instead: writes outside the workspace, any write in read-only, piped grandchild spawn EPERM, ConstrainedLanguage errors. If approval is refused or unavailable, report the path as undiagnosed and stop.
Every record reaches stdout, the acl-report-*.jsonl file under -Out, and the final RECAP line, which carries the verdicts, changes, verifications, refusals and scans. Tool output keeps only its tail, so read the recap first, and read specific records from the report when it is not enough. Trust verification records, never completed actions. Decide from details.nextAction:
nextAction | Meaning |
|---|---|
verify_original_confined_operation | Repairs verified; repeat the original operation confined. |
stop | Nothing repaired, or a refusal ended the run. Report and stop. |
restore_pending_then_stop | Rollback unverified. Run the printed recovery commands in order, then stop. |
A deny ACE's presence alone does not establish causation, and the script never removes one; DSH's S-1-4-* grants and the Everyone DeleteSubdirectoriesAndFiles deny are expected, not conflicts. A deny that blocks the repair ends the run without a repair (REPAIR_REFUSED, or GRANT_FAILED) after restoring what it attempted. Each change leaves two files in -Out (acl-backup-<id>.json and its .ps1), and the run prints the matching ROLLBACK command.
Repeat the original failed operation confined. A verified repair is not undone because the original operation fails for a further reason: continue from the new observations, and if a deeper path is still denied, run the same one command there — again one call, one approval.
Stop after any failed or refused repair, or failed verification. The script already restored that invocation's changes; do not repeat it or start another repair, and never remove a deny ACE by hand.
A stopped run still owes the user a decision. Name the blocking object and the right or ACE it lacks, what changed and what was rolled back, the recovery commands in order, and the report path. Only the user can lift confinement, so ask them to switch this session to full access (Chinese UI: 完全权限) temporarily, and say what that opens: keep working under it, or ask you to keep investigating this file-permission problem, since the report already records the mechanism and the evidence. Then ask them to send this session as feedback, quoting the report records that matter, so the unhandled scenario reaches us — only what reaches this conversation travels with it. For example:
这个工作区被 Windows 文件权限挡住了:
<对象>上<缺哪个权限 / 哪条权限项>。你可以把本会话切到「完全权限」(full access) 临时继续工作;切完之后既能直接干活,也可以让我继续排查这个文件权限问题(报告里已经有机制和证据)。也麻烦把这个会话作为反馈发出去,好让我们补上这个场景。This workspace is blocked by Windows file permissions:
<object><missing right / offending entry>. Switch this session to full access (完全权限) to keep working meanwhile; then either continue your work or have me keep investigating this file-permission problem from the report. Please also send this session as feedback so we can cover the case.
runas;-AllowRoot to reach an ancestor, or repeat a denied or failed call.Report in the user's language: analyzed paths, changes, verification, recovery commands, next step. Label an authorized unconfined run as such, not as a sandbox repair.
© Zhou-Yujing114514, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (scripts) in packages/sandbox/sandbox-windows-acl/assets/diagnose-windows-sandbox-acl of Zhou-Yujing114514/deepseek-harness-linux.
Open the folder on GitHubat commit 35a829f
Diagnose Windows Sandbox Acl next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Diagnose Windows Sandbox Acl this skillZhou-Yujing114514/deepseek-harness-linux | 120 | — | ~1.7k | Automated safety check: Pass | MIT | |
| Diagnose Gatewayopenclaw/openclaw | 392k | — | ~670 | Automated safety check: Pass | MIT | |
| Windows Desktop E2Eaffaan-m/ECC | 277k | 1 repos | ~7.6k | Automated safety check: Pass | MIT | |
| Windows Desktop E2Eaffaan-m/ECC | 276k | — | ~5.5k | Automated safety check: Pass | MIT | |
| Agent Sandboxruvnet/ruflo | 74k | 2 repos | ~777 | Automated safety check: Pass | MIT | |
| Diagnosegithub/awesome-copilot | 40k | 1 repos | ~1k | Automated safety check: Pass | MIT |
openclaw/openclaw
Diagnose Gateway, config, secrets, channels, and port failures with read-only one-liners.
affaan-m/ECC
E2E testing for Windows native desktop apps (WPF, WinForms, Win32/MFC, Qt) using pywinauto and Windows UI Automation.
affaan-m/ECC
E2E testing for Windows native desktop apps (WPF, WinForms, Win32/MFC, Qt) using pywinauto and Windows UI Automation.
ruvnet/ruflo
Agent skill for sandbox - invoke with $agent-sandbox. An agent skill from ruvnet/ruflo.
github/awesome-copilot
Perform a systematic diagnostic scan of an AI workflow across 5 quality dimensions — prompt quality, context efficiency, tool health, architecture fitness, and safety — producing a scored report…
vercel/next.js
Benchmark React or Next.js changes on Vercel Sandbox VMs with paired A/B statistics: react PR/commit vs base, or Next.js PR/commit vs base, measured end-to-end through the bench/render-pipeline app…
Zhou-Yujing114514/deepseek-harness-linux
A skill your agent uses when a deepseek-harness change breaks an externally perceptible surface (CLI, profiles, cordis.yml or settings keys, persisted user data, SDK or wire APIs, published package…
Zhou-Yujing114514/deepseek-harness-linux
A skill your agent uses when designing, reviewing, adding, enabling, disabling, installing, configuring, or debugging a plugin, bundle, feature, page, panel, tool, or MCP connection in the current…
Zhou-Yujing114514/deepseek-harness-linux
Design, review, and diagnose DeepSeek Harness tests and fixtures that can fail nondeterministically under CI concurrency, shared host resources, clocks, process-global state, subprocesses, network…
Zhou-Yujing114514/deepseek-harness-linux
Find evidence-backed simplifications in DeepSeek Harness code, APIs, configuration, tests, and prose; write or consolidate proposals, identify small inline cleanups, or assess simplifications from…
Zhou-Yujing114514/deepseek-harness-linux
Design and review DeepSeek Harness client UI changes — visual token discipline, reuse-before-adding, feedback surfaces (toast vs in-place notice vs empty state), overlay and menu safety, platform…
Zhou-Yujing114514/deepseek-harness-linux
A skill your agent uses when reviewing a pull request in the deepseek-harness repo — orients the reviewer to this codebase's standards (AGENTS.md conventions, defensive patterns, ADRs, quality…
Use on Windows for unexpected DSH sandbox access denials: workspace writes or listing fail, or an ordinarily readable path cannot be read. Diagnose Windows Sandbox Acl is an agent skill from Zhou-Yujing114514/deepseek-harness-linux. Use on Windows for unexpected DSH sandbox access denials: workspace writes or listing fail, or an ordinarily readable path cannot be read.
Run `npx skills add Zhou-Yujing114514/deepseek-harness-linux --skill diagnose-windows-sandbox-acl -a claude-code`. Or copy the skill folder (packages/sandbox/sandbox-windows-acl/assets/diagnose-windows-sandbox-acl in Zhou-Yujing114514/deepseek-harness-linux) into .claude/skills/diagnose-windows-sandbox-acl in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Zhou-Yujing114514/deepseek-harness-linux --skill diagnose-windows-sandbox-acl -a codex`. Or copy the skill folder (packages/sandbox/sandbox-windows-acl/assets/diagnose-windows-sandbox-acl in Zhou-Yujing114514/deepseek-harness-linux) into .agents/skills/diagnose-windows-sandbox-acl in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Zhou-Yujing114514/deepseek-harness-linux --skill diagnose-windows-sandbox-acl -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/diagnose-windows-sandbox-acl, .gemini/skills/diagnose-windows-sandbox-acl, .github/skills/diagnose-windows-sandbox-acl and .opencode/skills/diagnose-windows-sandbox-acl in your project.
Going by SKILL.md and its folder, Diagnose Windows Sandbox Acl needs PowerShell for the scripts in its folder. Our summary lists: PowerShell.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Diagnose Windows Sandbox Acl is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Diagnose Windows Sandbox Acl: Diagnose Gateway (openclaw/openclaw, 392k stars), Windows Desktop E2E (affaan-m/ECC, 277k stars), Windows Desktop E2E (affaan-m/ECC, 276k stars) and Agent Sandbox (ruvnet/ruflo, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Zhou-Yujing114514 (a GitHub user) maintains it in Zhou-Yujing114514/deepseek-harness-linux, which has 120 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 6, 2026.
Source: Zhou-Yujing114514/deepseek-harness-linux on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.