DNAlec/dsh-auto-approve

Plugin插件 Native原生 ⭐ 3 MIT Approval & Security审批与安全

DeepSeek Harness 自动审批插件:关键词 + 审核模型审核表。

Project Overview项目介绍

This is a plugin built exclusively for DeepSeek Harness (DSH) that automatically approves or rejects tool calls based on user-configured keywords and a judge model. It supports customizing approval, rejection, and manual review actions for every combination of tool call category and risk level, and routes all uncertain calls to the original DSH manual approval flow. To install, users run the DSH CLI command dsh plugin --profile web add github:DNAlec/dsh-auto-approve to pull directly from GitHub, or install the published npm package after a tagged release, then restart the dsh web service for changes to take effect. After the first successful start, the plugin automatically adds the Auto-approve permission preset to the current profile's configuration file.

After installation, all configuration is done through the DSH settings panel's Auto-approve page, and no manual file editing is required for most common use cases. Users walk through a simple setup flow: select an auto-approve mode, sort keywords into reject, human, and allow buckets, map actions to category-risk level pairs, configure the judge model settings, and finally set the session permission to Auto-approve. This plugin is designed for DSH power users who want to reduce frequent manual approval interruptions during long agent sessions, and automate consistent handling of low-risk routine tool calls to keep sessions moving without constant user input.

The plugin is released under the permissive MIT open source license, and requires no extra third-party dependencies beyond a working DSH installation. There are a few important caveats for users to note: setting the judge model's max token output cap too low will cause reasoning failures, which add unnecessary latency and can lead to all calls falling back to manual review. When upgrading the plugin, if DSH has updated its base permission presets, users need to manually merge configuration changes, and uninstalling the plugin does not delete existing user configuration or audit log data to prevent permanent data loss.

这是专门为 DeepSeek Harness (DSH) 开发的原生插件,核心功能是基于自定义关键词和可配置的裁判模型,自动批准或拒绝工具调用。插件支持按调用类别和风险等级配置不同的处理动作,无法判定的调用会转交到原有的网页人工审批流程。用户可以通过 DSH 命令行工具安装,既可以直接从 GitHub 拉取安装,也可以在版本 tagged 后从 npm 进行安装,安装后需要重启 dsh web 服务生效。

插件安装完成后,用户可以在 DSH 设置面板的「自动审批」页面完成全部配置。配置流程包括选择自动审批模式、设置关键词分桶、配置不同分类对应不同风险等级的处理动作、选择裁判模型并调整相关参数,最后将会话权限设置为自动审批即可开始使用。该插件面向需要减少 DSH 运行中人工审批打断、希望批量处理低风险常规工具调用的深度 DSH 用户。

插件遵循 MIT 开源协议,没有额外的第三方依赖,使用时需要注意几个要点:第一,裁判模型的输出 token 上限需要合理设置,过小会导致推理失败,增加不必要的调用延迟;第二,插件升级时如果 DSH 基础预设发生变更,需要用户手动合并更新配置文件;第三,卸载插件不会删除用户的配置和审计日志目录,避免数据意外丢失。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 3 stars - very few users, little community feedback星标只有 3,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add @dnalec/dsh-auto-approve

把 DNAlec/dsh-auto-approve 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-auto-approve

English | 中文

A DeepSeek Harness plugin that auto-approves or rejects tool calls with keywords and a judge model that returns a category plus a risk level. Every category has three cells (low / medium / high), all yours to configure. Uncertainty goes to the original Web approval dialog.

Install

dsh plugin --profile web add github:DNAlec/dsh-auto-approve

Or from npm, after a tagged release:

dsh plugin --profile web add @dnalec/dsh-auto-approve

To pin a reproducible version, append #vX.Y.Z (the tag must match package.json, which the publish workflow checks).

Restart dsh web. The first start adds the Auto-approve permission preset to the current profile's cordis.patch.yml; if that write fails, the log line names the file and the reason.

Setup

Settings → Auto-approve. Each control on the page carries one line of hint; the rules live here:

  1. Auto-approve mode — in-workspace writes skip approval (workspace-write, recommended), or send them through the judge (read-only). Clicking a mode writes it; restart dsh web, then re-select Auto-approve or start a new session.
  2. Keywords — three buckets: reject / human / allow. They match the tool name, command, path, and working directory, plus the values of custom-tool (MCP and friends) arguments with unrecognized names; they never see written contents, code bodies, or numeric/boolean switches ({content:"rm -rf /"}, {recursive:true} are judged by the model only). Reject/human words also match the tool name; allow words match neither the tool name nor the session directory, so bash/write is never allowed as a class.
  3. Criteria table — a row is an English id + a description (state when to pick this id) + three cells (low/medium/high → action). The judge sees only the id and the description; the plugin runs the action in the (row, level) cell. other cannot be deleted, but its description and cells are editable. The id is what the approval history shows.
  4. Risk levels — all three descriptions go into the prompt. When the level is unreadable (default high) also decides which cell of that row runs, so it decides the outcome: a high fallback rejects such calls, medium asks a human, low allows them.
  5. Judge model — model, reasoning effort, judge timeout, the judge request limit, the output budget (tokens), and whether a call that is over the limit / hit the collection guard goes to a human or is rejected (arguments not captured are always rejected; not configurable — see “How it works”). The same card holds the judge prompt: {{criteria}} inserts the criteria table and {{levels}} the level descriptions; a missing placeholder appends that block. It is editable, and restoring writes the shipped template of the language you pick and switches the language to it. The output budget (judge.maxTokens, default 8192, range 256-32768) caps how much the judge may write on its first attempt (reasoning tokens share that cap with the answer). A small cap breaks judgments: the model thinks by default, and locally it spent 3.7k-8.3k characters (≈2-5k tokens) on reasoning per call, so the old 1024 cap was always eaten by reasoning → empty answer → the plugin retried with a bigger budget, i.e. every judgment paid a wasted model call (double latency, tighter against the 20s timeout); the 2026-09-14 “every judgment goes to a human” outage was this chain at its extreme (the retry then was only 2048 and got eaten too). maxTokens is a cap, not a reservation — a model that does not think stops when done, so a generous value costs no extra time and only removes that doomed first call. It applies to routes that may reason (no effort configured but the route reports reasoning still counts); routes without reasoning stay at 256. The scene is visible in Test judgment and in the audit log.
  6. Model-initiated human review (off by default) — when on, auto-rejections carry their reason and the model may escalate one operation to a human. The tool name is editable (restart to rename) and the notice language is Chinese or English. Enabling it turns the approval dialog into a channel the model can wake you through — including while it is being driven by untrusted content.
  7. Set the session permission to Auto-approve.

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev codegraph 下一个 Next dsh-skin-studio →