moon09300731/dsh-approval-gate 预览 preview

moon09300731/dsh-approval-gate

Plugin插件 Native原生 ⭐ 81 MIT Approval & Security审批与安全

DeepSeek Harness 自动审批门控:Flash 预判不可回补操作,安全自动批准、危险转人工(fail-safe)

Project Overview项目介绍

This plugin is a native DSH security plugin built exclusively for DeepSeek Harness. It adds a configurable approval gate for sandbox operations, using a lightweight Flash model to assess risk on every cross-boundary sandbox action before it runs. You can install it directly via the DSH CLI with the single command dsh plugin --profile web add dsh-approval-gate, no manual downloading or unpacking required. After installation, you just need to enable it in the DSH session permission dropdown menu to start using it right away.

This plugin is designed for developers who use DeepSeek Harness for coding and system administration tasks. It follows a clear, fail-safe workflow: every sandbox operation is checked for risk first, hard risk operations like file deletion, credential access, and production environment access are automatically routed to you for manual confirmation. Operations you have already approved are stored as learned rules, so future identical operations are automatically approved without additional manual input. Semantic matching is used to recognize operations with different wording but the same intent, so you don’t have to approve the same task multiple times.

This plugin is released under the permissive MIT open source license, so you can modify, redistribute, or use it for any purpose, commercial or non-commercial, without any legal restriction. It only requires a working DeepSeek Harness installation to run, no other external dependencies or extra third-party tools are needed. It supports hot configuration updates, so any changes you make to the allowlist.json file take effect immediately without needing to restart DSH. After first installation, you only need to restart DSH once to complete the configuration and fully activate the plugin.

这是一个专为 DeepSeek Harness (DSH) 开发的原生安全审批插件,核心功能是对沙箱越界操作进行风险预判,实现常规操作自动放行,高风险操作强制转人工确认的fail-safe安全机制,它符合DSH插件打包规范,可通过DSH CLI命令直接安装,安装后就能在DSH的会话权限下拉菜单中选择启用。

对于开发人员使用DSH进行编码、系统配置操作等场景,该插件会在每次沙箱越界时调用Flash模型判定操作风险,五类硬风险操作(删除文件、凭据访问、远程生产环境操作等)会直接拦截并要求人工确认,已经人工确认过的同类操作会被学习沉淀,后续遇到相同操作会自动放行。

该插件采用MIT开源许可证,允许自由使用、修改和分发,它依赖DSH的运行环境,支持配置热更新,修改allowlist.json后无需重启DSH即可生效,还提供了可视化审批界面、文件改动对比和一键撤销功能,首次安装后只需重启一次DSH即可完成配置并启用。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 no risk signal found未发现风险信号
  • This site's static screen found no obvious risk signal (stars, license, activity, manifest)本站静态筛查没发现明显风险信号(星标、许可证、更新活跃度、清单完整度)
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add dsh-approval-gate

把 moon09300731/dsh-approval-gate 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

简体中文 | English

dsh-approval-gate

DeepSeek Harness 自动审批门控 —— 最小人工介入,安全自动放行、危险转人工(fail-safe)。

Flash 模型预判每次沙箱越界:常规操作自动放行,硬风险操作(删除 / 凭据 / 远程 / 系统 / 批量)永远转人工确认;学习沉淀只针对你确认过的操作,并提供界面化人工审查入口。

✨ 特性

  • ⚡ Flash 风险预判:每次沙箱越界由 Flash 模型判定(SAFE / RISKY:<类别>),可回补操作自动放行
  • 🛡️ 硬风险永远人工:删除、凭据、远程/生产、系统路径、批量不可回补五类操作直接转人工,不计数、不学习
  • 🎯 确认制学习:同一操作确认 N-1 次后自动放行;沉淀规则携带操作指纹,只放行你确认过的操作
  • 🧠 语义同类验证:措辞变化但意图相同的操作,由 Flash 对照你的确认样本语义判断,不再依赖关键词
  • 🔧 配置热更新:allowlist.json 修改即时生效,无需重启
  • ✅ 人工审查 UI:自动放行时输入框上方出现绿色提示;「审批」视图(轨迹右侧)展示当前会话完整放行时间线
  • 📄 文件改动对比与撤销(v0.5.0+):审批涉及的文件可点击查看 unified diff——变动行带上下 5 行上下文、多处修改按 hunk 分区并以「N unmodified lines」分隔条折叠、绿加红删灰上下文、双行号;一键「撤销此改动」投递指令让 AI 按快照恢复文件
  • 🗂️ 会话级快照管理(v0.5.0+):快照按事件归属会话,审批视图按当前会话统计;清理支持「仅清本会话」与「清空全部」两档,避免误删其他会话未查看的 diff 记录

📸 界面速览

① 审批视图

审批视图

「审批」标签页(轨迹右侧)按时间倒序展示当前会话的自动放行与人工审批记录:每条记录含工具名(bash / edit)、判定标签(「自动放行 · Flash 判定安全」「人工通过」等)、时间与操作说明。顶部统计栏显示本会话的 diff 快照占用(2.9 KB · 3 条),并提供两个清理入口:「仅清本会话」(只删除当前会话的快照,不影响其他会话未查看的 diff)与 「清空全部」(二次确认后清空所有会话,防止误删)。

② 文件改动对比(diff)

diff 对话框

点击审批记录中的文件即可打开对比面板:以 unified diff 展示改动前后差异——新增行绿底(+)、删除行红底(-)、上下文行灰底;左侧显示原/新双行号;多处修改按 hunk 分区,块间以灰色「6 unmodified lines」分隔条折叠未变更区间。顶部统计 +2 / -2 行变更 · 20 行未变。底部 「撤销此改动」 一键向对话投递撤销指令,AI 将按审批前的快照恢复文件。

③ 设置 · 自动审批

设置-自动审批

设置页「自动审批」分区提供完整配置:初始化权限预设(一键写入 cordis.patch.yml 的 auto-approve 预设)、当前判定管道总览(DENY → 白名单 → denyRules → Flash → 学习)、危险词黑名单(预置条目 + 自定义添加)、以及热更新说明(修改即时生效,无需重启)。

🚀 快速开始

dsh plugin --profile web add dsh-approval-gate
  1. 配置权限预设:在 ~/.dsh/profiles/web/cordis.patch.yml 添加 auto-approve 预设(详见指南)
  2. 重启 dsh web
  3. 选择预设:会话权限下拉选中「自动审批(Flash)」

📖 文档

📄 License

MIT

← 上一个 Prev dsh-ecosystem-spec 下一个 Next sealos-skills →