wangxing-git/dsh-autogate 预览 preview

wangxing-git/dsh-autogate

DeepSeek Harness 自动审批插件:在 workspace-write 沙箱之上叠加确定性规则 + LLM 安全审批,自动模式不放宽沙箱、fail-closed。 为 DeepSeek Harness 提供安全自动审批——确定性规则 + LLM 审查,基于 workspace-write 沙箱,自动模式绝不授予完全访问权限。

Project Overview项目介绍

This is a native auto-approval plugin built exclusively for DeepSeek Harness (DSH), layered on top of DSH's built-in workspace-write sandbox. To install the plugin, you can run the command dsh plugin --profile web add github:wangxing-git/dsh-autogate from your terminal, or use npx @deepseek-ai/dsh if DSH is not in your system PATH. After installation completes, you just need to restart your DSH instance to activate the plugin. It implements a three-tier decision architecture that never relaxes the original workspace-write sandbox boundary for most calls, only allowing temporary wider sandbox access for explicitly approved escalation requests.

The plugin offers two preconfigured permission modes that share the same L0 deterministic rule set and L1 LLM classifier, differing only in whether L2 manual fallback is enabled. The default semi-automatic auto-ask mode sends any LLM rejected or ambiguous requests to a manual approval popup. The fully automatic auto mode treats LLM rulings as final, rejecting requests that do not pass instead of popping up for manual input. A floating approval trail panel is added to the bottom-right of the DSH web UI, showing recent approval records filtered by the current active session.

The plugin is released under the open-source MIT license, and includes several documented known limitations users should be aware of. The L1 LLM classifier is heuristic and can make misjudgments, either allowing dangerous operations or rejecting safe ones, so fail-closed logic is implemented to reduce misallowance. Injected prompt defenses are soft, only raising the barrier for attacks rather than eliminating risk entirely, and residual TOCTOU race windows for symlinks are still covered by the base workspace-write sandbox. Full auto mode should only be used in trusted environments, as it disables manual popups for all LLM decisions.

这是一个专为 DeepSeek Harness 开发的原生自动审批插件,基于 DSH 原生的 workspace-write 沙箱实现分层权限决策体系。它分为三层安全判断:L0 确定性规则快速拦截或放行,L1 由 LLM 做语义安全审查,L2 人工审批作为兜底。它始终保留原工作区沙箱边界,不放宽权限到 full-access,提供半自动(auto-ask 默认)和全自动(auto)两种运行模式。

本插件适合希望减少 DSH 日常开发中人工审批弹窗次数,同时又不想过度放宽安全边界的用户。子代理创建时会自动继承父会话的权限模式,插件还在 DSH 网页端右下角提供了审批轨迹悬浮面板,按当前会话隔离显示最近 50 条审批记录,每条记录标注决策结果、层级和工具信息,还支持点击定位到对应工具调用位置。

安装可通过 DSH 内置的插件命令,执行 dsh plugin add github:wangxing-git/dsh-autogate 后重启 DSH 即可。配置可通过 DSH 设置界面或直接修改 $DSH_HOME/settings.yaml,项目采用 MIT 许可开源。需要注意 LLM 分类器是启发式的,仍有误判可能,全自动模式仅建议在可信环境中使用。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 3 stars - very few users, little community feedback星标只有 3,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:wangxing-git/dsh-autogate

把 wangxing-git/dsh-autogate 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

语言: 简体中文(本页) · English

dsh-autogate

dsh-autogate — 在 workspace-write 沙箱之上的分层自动审批插件

DeepSeek Harness 自动审批插件:在 workspace-write 沙箱之上 增加「半自动(auto-ask)+ 全自动(auto)」两档权限,采用「确定性规则 + LLM 安全审批 +(半自动下)被拒绝方主动人工审批」分层决策。保留工作区沙箱边界,不放宽为 full-access。

分层设计

层 决策 说明
L0 确定性规则 allow / deny 零成本、零 LLM:只读、会话状态、工作区内编辑与删除、build/test、run_code 容器直接放行;工作区外普通路径读直接放行;工作区外的写/删除(敏感 shell/凭据配置文件写除外)放行交由 workspace-write 沙箱拦截 + escalation 弹窗;工作区外敏感配置文件写交 LLM 审查;空命令、动态命令名、参数缺失等兜底放行交由沙箱;提权、系统级自毁(关机/重启/格式化;进程杀手 killall/pkill/taskkill/Stop-Process 降级 L1)、凭据外传、文件系统根与系统/凭据关键路径(/usr/local 除外)的变更/删除、家目录根删除硬拒绝;家目录根变更、DSH_HOME 与 /usr/local 的变更/删除走工作区外通用路径(沙箱 + escalation)
L1 LLM 安全审批 allow / deny 沙箱不拦截但语义危险的操作(未识别工具、模糊 shell、敏感路径读、动态目标、块设备、持久终端、git 状态变更、网络/数据库操作、进程管理(killall/pkill/taskkill/Stop-Process)、工作区内受保护路径写)交 LLM 两态裁决:用户明确授权的操作放行,减少人工批准。分类器输入先脱敏再标签隔离(<untrusted> 数据 vs <user-authority> 授权),并内置注入防御;用户用短指代(如「A」)回应 AI 方案列表时,AI 提议作为 <proposal-context> 仅用于消解指代、不作授权;agent 指令文件(AGENTS.md / CLAUDE.md / .dsh 等)按常规配置归类,用户明确授权即可编辑
L2 人工审批 ask 审批弹窗前先过 LLM 预审:合理则直接批准不弹窗,危险/不确定才人工兜底。覆盖三类审批请求:① AI 用 ask_user_question 问用户确认操作合法,确认后重新执行再过 LLM;② AI 用 sandbox_permissions + justification 重试走 DSH 沙箱提权(escalation);③ 工具/插件自身声明需要审批(pre-execute 返回 ask)的调用

分层决策架构:L0 确定性规则 → L1 LLM 安全审批 → L2 人工兜底,workspace-write 沙箱始终兜底

两种模式

预设键 模式 escalation 提权审批兜底
auto-ask 半自动(默认) LLM 拒绝/异常 → 委派人工弹窗(L2 兜底)
auto-full 全自动 LLM 拒绝/异常 → 直接拒绝,不人工弹窗(LLM 裁决为最终决定)

两种模式共享同一套 L0 确定性规则与 L1 LLM 分类器,唯一区别是 L2 人工兜底:半自动保留人工弹窗,全自动把 LLM 裁决作为最终决定。硬 deny(L0 guard)与 preflight 开关在两种模式下行为一致。

子代理继承

子代理(subagent)创建时继承父会话的托管档:父会话处于 auto-ask 或 auto-full 时,子代理会话的权限档与父一致(DSH 默认给子代理 pin approval=never 且不写权限档事件,本插件补写继承标记并放开为 ask)。

  • 权限档投影:子代理会话补写 permission/preset 继承标记(source: autogate),UI 显示与父会话相同的 Auto 档,而非「工作区读写」;该标记只影响显示,不作为授权依据。
  • 授权依据锚定顶层:子代理触发的一切 L0/L1/L2 审批,其授权依据(最近的直接人类消息与问答授权)始终取沿 parentSession 链向上找到的顶层 Auto 会话,避免无直接人类消息的子代理会话被误当作授权来源。
  • 子代理审批无人工兜底:子代理的提权 / 工具 ask 请求由 LLM 终审,拒绝即拒绝、不转人工弹窗(子代理无可靠弹窗通道)。

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-continue 下一个 Next DSH-plugin-android-apk →