moon09300731/dsh-approval-gate
DeepSeek Harness 自动审批门控:Flash 预判不可回补操作,安全自动批准、危险转人工(fail-safe)
Project Overview项目介绍
This plugin is a native DSH security plugin built exclusively for DeepSeek Harness. It adds a configurable approval gate for sandbox operations, using a lightweight Flash model to assess risk on every cross-boundary sandbox action before it runs. You can install it directly via the DSH CLI with the single command dsh plugin --profile web add dsh-approval-gate, no manual downloading or unpacking required. After installation, you just need to enable it in the DSH session permission dropdown menu to start using it right away.
This plugin is designed for developers who use DeepSeek Harness for coding and system administration tasks. It follows a clear, fail-safe workflow: every sandbox operation is checked for risk first, hard risk operations like file deletion, credential access, and production environment access are automatically routed to you for manual confirmation. Operations you have already approved are stored as learned rules, so future identical operations are automatically approved without additional manual input. Semantic matching is used to recognize operations with different wording but the same intent, so you don’t have to approve the same task multiple times.
This plugin is released under the permissive MIT open source license, so you can modify, redistribute, or use it for any purpose, commercial or non-commercial, without any legal restriction. It only requires a working DeepSeek Harness installation to run, no other external dependencies or extra third-party tools are needed. It supports hot configuration updates, so any changes you make to the allowlist.json file take effect immediately without needing to restart DSH. After first installation, you only need to restart DSH once to complete the configuration and fully activate the plugin.
这是一个专为 DeepSeek Harness (DSH) 开发的原生安全审批插件,核心功能是对沙箱越界操作进行风险预判,实现常规操作自动放行,高风险操作强制转人工确认的fail-safe安全机制,它符合DSH插件打包规范,可通过DSH CLI命令直接安装,安装后就能在DSH的会话权限下拉菜单中选择启用。
对于开发人员使用DSH进行编码、系统配置操作等场景,该插件会在每次沙箱越界时调用Flash模型判定操作风险,五类硬风险操作(删除文件、凭据访问、远程生产环境操作等)会直接拦截并要求人工确认,已经人工确认过的同类操作会被学习沉淀,后续遇到相同操作会自动放行。
该插件采用MIT开源许可证,允许自由使用、修改和分发,它依赖DSH的运行环境,支持配置热更新,修改allowlist.json后无需重启DSH即可生效,还提供了可视化审批界面、文件改动对比和一键撤销功能,首次安装后只需重启一次DSH即可完成配置并启用。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-approval-gate(moon09300731/dsh-approval-gate)
仓库:https://github.com/moon09300731/dsh-approval-gate
本站详情页:https://www.yhbd.top/plugins/moon09300731-dsh-approval-gate/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 81 · 最近提交 2026-08-20 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- This site's static screen found no obvious risk signal (stars, license, activity, manifest)本站静态筛查没发现明显风险信号(星标、许可证、更新活跃度、清单完整度)
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add dsh-approval-gate
把 moon09300731/dsh-approval-gate 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
简体中文 | English
dsh-approval-gate
DeepSeek Harness 自动审批门控 —— 最小人工介入,安全自动放行、危险转人工(fail-safe)。
Flash 模型预判每次沙箱越界:常规操作自动放行,硬风险操作(删除 / 凭据 / 远程 / 系统 / 批量)永远转人工确认;学习沉淀只针对你确认过的操作,并提供界面化人工审查入口。
✨ 特性
- ⚡ Flash 风险预判:每次沙箱越界由 Flash 模型判定(
SAFE/RISKY:<类别>),可回补操作自动放行 - 🛡️ 硬风险永远人工:删除、凭据、远程/生产、系统路径、批量不可回补五类操作直接转人工,不计数、不学习
- 🎯 确认制学习:同一操作确认 N-1 次后自动放行;沉淀规则携带操作指纹,只放行你确认过的操作
- 🧠 语义同类验证:措辞变化但意图相同的操作,由 Flash 对照你的确认样本语义判断,不再依赖关键词
- 🔧 配置热更新:
allowlist.json修改即时生效,无需重启 - ✅ 人工审查 UI:自动放行时输入框上方出现绿色提示;「审批」视图(轨迹右侧)展示当前会话完整放行时间线
- 📄 文件改动对比与撤销(v0.5.0+):审批涉及的文件可点击查看 unified diff——变动行带上下 5 行上下文、多处修改按 hunk 分区并以「N unmodified lines」分隔条折叠、绿加红删灰上下文、双行号;一键「撤销此改动」投递指令让 AI 按快照恢复文件
- 🗂️ 会话级快照管理(v0.5.0+):快照按事件归属会话,审批视图按当前会话统计;清理支持「仅清本会话」与「清空全部」两档,避免误删其他会话未查看的 diff 记录
📸 界面速览
① 审批视图

「审批」标签页(轨迹右侧)按时间倒序展示当前会话的自动放行与人工审批记录:每条记录含工具名(bash / edit)、判定标签(「自动放行 · Flash 判定安全」「人工通过」等)、时间与操作说明。顶部统计栏显示本会话的 diff 快照占用(2.9 KB · 3 条),并提供两个清理入口:「仅清本会话」(只删除当前会话的快照,不影响其他会话未查看的 diff)与 「清空全部」(二次确认后清空所有会话,防止误删)。
② 文件改动对比(diff)

点击审批记录中的文件即可打开对比面板:以 unified diff 展示改动前后差异——新增行绿底(+)、删除行红底(-)、上下文行灰底;左侧显示原/新双行号;多处修改按 hunk 分区,块间以灰色「6 unmodified lines」分隔条折叠未变更区间。顶部统计 +2 / -2 行变更 · 20 行未变。底部 「撤销此改动」 一键向对话投递撤销指令,AI 将按审批前的快照恢复文件。
③ 设置 · 自动审批

设置页「自动审批」分区提供完整配置:初始化权限预设(一键写入 cordis.patch.yml 的 auto-approve 预设)、当前判定管道总览(DENY → 白名单 → denyRules → Flash → 学习)、危险词黑名单(预置条目 + 自定义添加)、以及热更新说明(修改即时生效,无需重启)。
🚀 快速开始
dsh plugin --profile web add dsh-approval-gate
- 配置权限预设:在
~/.dsh/profiles/web/cordis.patch.yml添加auto-approve预设(详见指南) - 重启
dsh web - 选择预设:会话权限下拉选中「自动审批(Flash)」
📖 文档
📄 License
MIT
Minglink/dsh-infinite-gen-4
kenryu42/cc-safety-net
hyhmrright/brooks-lint
toby-bridges/api-relay-audit
hashgraph-online/hol-guard
SeaOf0/dsh-redteam-model
howmp/dsh-pentest
saya-ch/dsh-mobile