MrWeiCodes/dsh-permgate 预览 preview

MrWeiCodes/dsh-permgate

Plugin插件 Native原生 ⭐ 10 MIT Approval & Security审批与安全

Fine-grained permission control plugin for DeepSeek Harness (DSH)

Project Overview项目介绍

dsh-permgate is a permission control plugin built natively for DeepSeek Harness (DSH), created to address the coarse granularity of DSH’s built-in three-level permission system. It adds a custom review permission gateway that checks every tool call AI makes across eight categories, including directory access, command execution, file editing, and subagent launches. It supports global and project-level configuration, whitelist/blacklist exceptions, custom rules, and default values for shortcut tools. Users can install the plugin through four methods: DSH plugin market, AI-assisted install, command line, or manual install, depending on their local setup.

After installation, users can enable custom review for the current session via the permission picker below DSH’s input box, or set it as the default permission for all new sessions in DSH settings. Every tool call is evaluated against user-defined rules: calls matching exceptions are automatically allowed or denied, and uncertain calls pop up an approval modal for manual review. The modal displays full operation details including diffs for file edits, letting users quickly approve, reject, or add the current operation as a new exception rule. Users can also add custom rejection messages to tell AI how to adjust its plan for the task.

dsh-permgate is designed to be non-intrusive: it only uses DSH’s public APIs and does not modify native DSH source code, so it can be cleanly removed after uninstallation with no leftover traces in the DSH codebase. Updates preserve existing user configuration automatically, so users do not need to reconfigure settings after installing a new version. The plugin is released under the open source MIT license, which allows for commercial and non-commercial use without any restriction. When uninstalling, users only need to manually delete the configuration directory if they want to fully remove all plugin-related data.

dsh-permgate 是专为 DeepSeek Harness(DSH)开发的细粒度权限控制原生插件,用于弥补 DSH 原生仅提供只读、工作区写入、完全访问三档权限、粒度较粗的不足。插件新增「自定义审查」权限网关,可对 AI 的工具调用按目录访问、命令执行等八大分类逐项审查,支持全局和项目双级配置、黑白名单例外、自定义规则等多种功能。

安装插件后,用户可在 DSH 输入框下方的权限选择器中选择「自定义审查」启用插件,也可在设置中将其设为新会话默认权限,之后 AI 的每一次工具调用都会按配置规则进行审查,需要人工审批的操作会弹出可视化审批窗口。用户可直接查看操作参数和改动diff,选择允许、拒绝或一键添加例外规则,拒绝时还可填写自定义意见让 AI 调整方案。

插件支持通过 DSH 插件市场、AI 助手、命令行或手动四种方式安装,更新时原有配置会自动保留无需重新设置,卸载后仅需手动删除配置目录即可清理残留。插件遵循零侵入设计,仅使用 DSH 公开接口,未修改原生 DSH 代码,卸载后从进程完全移除不留痕迹,采用 MIT 许可开源,无商业使用限制。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 note1 项提示
  • 10 stars - an early-stage project星标 10,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add @mrweicodes/dsh-permgate

把 MrWeiCodes/dsh-permgate 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-permgate — DSH 权限网关

为 DeepSeek Harness(DSH)提供的细粒度权限控制插件

🌏 中文 | English

dsh · dsh-plugin · plugin · permission control · approval · sandbox · security · AI agent · 权限控制 · 审批 · 沙箱 · 权限网关

简介

当前 DSH 仅有 [Read only]、[Workspace Write]、[Full access] 三档权限,权限粒度较粗。本插件新增 「自定义审查」(Custom Review) 权限网关,对工具调用进行逐项审查。

权限按分类(目录访问 / 执行命令 / 读取文件 / 读取图片 / 编辑文件 / 撤销操作 / 启动子代理 / 重复操作)逐项审查工具调用,支持全局/项目双级配置、例外(白/黑名单)、快捷工具默认值、自定义规则、兜底策略,以及中英文双语审批弹窗与沙箱升级流程。

功能特性

  • 八大权限分类:工作区外目录、执行命令、读取文件、读取图片、编辑文件、撤销操作、子代理、重复操作八类分开管控,每一类都能独立设置「询问 / 允许 / 拒绝」——敏感操作从严、日常操作从宽,按你的习惯划定 AI 的边界。
  • 全局 / 项目双级配置:一份全局规则管所有项目,再按项目单独微调;项目里没设置的项目自动跟随全局,不用重复配置。
  • 例外(白/黑名单):把「经常要放行」或「绝对不允许」的路径、命令加进例外,命中后直接放行或直接拒绝,不再每次弹窗打扰你。
  • 快捷工具:web_search、skill 等没法按文件或命令分类的工具,也能单独设定默认是询问、直接允许还是直接拒绝。
  • 自定义规则:按工具名、文件路径、参数内容任意组合出规则(例如「任何工具都不得执行 rm -rf」),比分类例外更灵活;优先级 规则 > 例外 > 默认值,用最少的规则管住最多的情况。
  • 审批弹窗:一次弹窗看全所有信息——AI 想做什么、为什么、具体参数;编辑/写入文件会直接展示改动前后的 diff(+N/-N 行),撤销操作会展示本次撤销将恢复的内容,不用再点开文件比对。觉得某类操作以后都不用问了,还能一键把它加进项目白/黑名单。
  • 自定义拒绝意见:拒绝时可以直接告诉 AI「为什么不行、应该怎么做」,AI 收到明确的理由后会立即调整方案,而不是对着一个冰冷的「用户拒绝」反复试错。
  • 底层沙箱升级:即使你放行了,文件操作仍被 DSH 底层沙箱拦下(比如写工作区外的文件)时,会再次弹窗询问是否临时放开——一次授权、执行完自动收回,多一层保险。
  • 中英文双语:界面跟随 DSH 语言自动切换,中英文用户都能顺畅使用。
  • 持久化:所有设置保存在用户目录,重启不丢失。

使用

  • 会话权限选择器:在输入框下方的权限选择器中选择「自定义审查」,即由权限网关按分类逐项审查工具调用。

    会话权限选择器

  • 新会话默认权限设置:在设置里把「自定义审查」设为新对话的默认权限,之后每次新建对话自动启用,不用手动重复选择。

    默认权限设置

  • 审批弹窗:编辑/写入类审批可以看到 diff 详情,快速判断改动是否合理;命令类审批展示命令与参数——命中例外直接放行、未命中则询问,并给出可一键添加的规则候选(如 git status *),常放行的命令顺手就加进例外。

    审批弹窗

    命令执行审批(Pwsh)

  • 自定义拒绝意见:拒绝时填写意见,AI 会收到「为什么不行、应该怎么做」的明确理由,立即调整方案。

    拒绝意见

  • 设置 → 权限网关:一站式管理所有权限——每个分类的默认行为、白/黑名单、快捷工具、自定义规则、底层沙箱,全局与项目分开配置,还能查看最近决策记录。无需再手动编辑配置文件,通过设置界面即可快速调整。

    权限网关设置页

安装

方式一:插件市场安装(dsh-market,推荐)

已安装 dsh-market(DSH 插件市场)的用户:打开 设置 → 插件市场(Plugin Market),搜索 dsh-permgate,点卡片上的「安装」并按提示确认来源(npm:@mrweicodes/dsh-permgate;若卡片显示 GitHub 源则为 github:MrWeiCodes/dsh-permgate)。安装完成后重启 dsh web。然后在会话的权限选择器(/permission)中选择 「自定义审查」。

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-plugin-whale-fenggu 下一个 Next dsh-code-ide →