cuddly-guacamole/dsh-auto-approval-llm 预览 preview

cuddly-guacamole/dsh-auto-approval-llm

LLM-assisted auto approval + timeout fallback for the DeepSeek Harness Auto preset

Project Overview项目介绍

This is a native DeepSeek Harness plugin that adds LLM-assisted automatic approval for the DSH auto-approval permission level. It acts as the sole final arbiter for all approval requests in this permission tier. Routine operations are approved directly via static rules, while dangerous or ambiguous operations are sent to LLM for review before a decision is made. The plugin uses a default fail-closed security model and implements a countdown timer with automatic fallback for pending approvals. It is designed to work alongside the official upstream auto-review plugin, occupying a separate permission tier so both can be enabled at the same time.

This plugin is built for DSH users who want to balance security and operational efficiency when working with the auto-approval permission level. Its full workflow starts after a tool call is initiated, first passing through a hard rejection gate that blocks obviously malicious or forbidden operations. Next, it runs a static rule assessment, sending ambiguous operations to an LLM pre-classifier. Operations that remain unclear after classification are routed to a human approval panel with an active countdown timer, and the final decision is fed back to the model for future context. This workflow retains a human fallback for auditing while keeping routine operations fast.

To install this plugin, you must first have DSH version 0.1.5-rc.2 or newer, and Node.js version 22.19.0 or newer (or 24+). Installation is done via the DSH CLI command dsh plugin --profile web add @quill507/dsh-auto-approval-llm, and you must restart DSH after installation for the plugin to take effect. Users must also switch DSH to the auto-approval permission tier via /permission auto-approval after installation. It is released under the permissive BSD-3-Clause open source license. Currently, the plugin has not been verified by real users on non-Windows platforms, and it has several documented minor limitations that users should review before installation.

这是一款专为 DeepSeek Harness 开发的原生插件,用于为 DSH 的 auto-approval 权限档提供 LLM 辅助自动审批能力。插件作为该权限档位下审批请求的唯一终结裁决者,常规操作可经静态规则直接放行,危险或模糊操作会交由 LLM 评审,并自带倒计时超时兜底和默认fail-closed机制,可与上游 auto-review 插件分档并存同时启用。

该插件面向需要在自动审批档位下平衡操作效率与安全的 DSH 用户,其工作流遵循工具调用发起后先经硬拒闸门筛选,再走静态规则评估环节,模糊操作会转 LLM 预分类,仍不确定的操作进入人工面板加倒计时流程,最终裁决结果会回灌模型,全程保留人工审计兜底,既保障安全又不降低常规操作的效率。

该插件要求 DSH 版本不低于 0.1.5-rc.2,Node.js 版本需为 ^22.19.0 或 >=24.0.0,采用 BSD-3-Clause 开源许可,免费可商用。目前已知非 Windows 平台未经过真实用户验证,存在部分已知局限如规则解析错误整段失效等,用户安装后需重启 DSH 才可生效。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 note1 项提示
  • 11 stars - an early-stage project星标 11,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add @quill507/dsh-auto-approval-llm

把 cuddly-guacamole/dsh-auto-approval-llm 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

@quill507/dsh-auto-approval-llm

为 DeepSeek Harness 的 Auto 权限档提供 LLM 辅助自动审批 + 超时自动兜底

常规操作静态放行 · 危险与模糊操作走 LLM 评审 + 人工倒计时 · 默认 fail-closed

npm downloads DSH license Awesome DSH Plugin

文档站 · English · Issues

Auto 档(machine value auto-approval;host 显示名 Auto approval;中文客户端显示 自动审批)= sandbox: danger-full-access + approval: ask。本插件在本档会话里充当 approval/request 的唯一终结裁决者:常规操作经静态规则直接放行,危险/模糊操作走「静态规则 → LLM 分类 → LLM/人工裁决 → 倒计时兜底 → 熔断」,全程保留人工与审计兜底。宿主 >= 0.1.6 的 auto 归上游 @deepseek-ai/dsh-experimental-auto-review(Auto review / EXP),本插件只接管 auto-approval 档、上游只接管 auto 档(按 derived preset 判档),两者作用于不同档位、可同时启用。


特性

  1. 静态规则 + LLM 分类器 —— 只读/会话/工作区常规操作直接放行;危险、外部写、凭据外泄、受保护路径直接拒绝;模糊操作交 LLM 预分类。
  2. 写向量完整性加固 —— 含真实文件写重定向的命令段脱离只读快径;POSIX tee / dd of= / sed -i / truncate / install 以操作数目标参与按目标闸门;直写插件运行态文件无条件硬拒。
  3. 12 分类三态开关 + 信任目录双模式 —— 每类可配 auto / ask / deny,默认全部 inherit(HARD_LOCKED 的 delete / disk 除外——未配置也恒被接管为 ask 倒计时);delete / disk / privilege / protected 四类保持锁定,trustedDirs 与 categoryMode 控制「常规位置」范围(分层细节见 docs/17)。→ docs/17
  4. 双通道模型来源 —— 快速判断与深度评审各可独立选择:跟随会话模型(默认)/ DSH 已配置模型 / 自定义端点。端点密钥存 DSH 凭据存储,前端只显示「已配置」、永不回显。
  5. 分级倒计时 + 超时兜底 + LLM 接管 —— 低/中/高三档倒计时(默认 5 / 8 / 10 秒);超时按 timeoutAction(拒绝 / 通过 / 低风险自动同意)结算;中风险下 LLM 在窗口内给出明确结论即接管。关浏览器也不悬挂(host 计时器独裁)。
  6. 熔断与循环防护 —— 连续/累计被 LLM 拒绝达阈值则转人工(/approval-reset 重置);循环防护(默认关)把「被自动放行面连续放行的同一调用」转为钉死拒绝倒计时。
  7. 声明式规则 rulesText —— 工具(正则) | allow|deny|human [| 字段],支持 [agent:…] / [workspace:…] 维度限定;解析出错时整段失效(设置卡有警示)。
  8. 确认制学习(默认关)—— 同一签名被人工反复确认达阈值后自动放行,每次放行前仍过一次标准在线评审;条目可查看与吊销。→ docs/18
  9. 可审计、可观测 —— history.jsonl + append-only audit.jsonl;LLM 评审真实耗时统计;瞬时网关故障自动重试一次(认证类错误不重发凭据)。

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-craft-your-textbook 下一个 Next dsh-opencode-go-usage →