zjuhbh/dsh-full-with-approval

DSH profile plugin: full-access (GPU-capable) sandbox with per-operation approval for writes outside the workspace or to protected files.

Project Overview项目介绍

dsh-full-with-approval is a profile plugin built specifically for DeepSeek Harness (DSH), appending a fourth permission preset called full-with-approval alongside the stock read-only, workspace-write, and danger-full-access options. The preset switches the session sandbox to danger-full-access, granting unconfined compute (CUDA, devices, network, any binary), while a layer mounted via cordis.patch.yml listens on the official tools/pre-execute waterfall and returns { kind: "ask", reason } for writes/edits that target paths outside the workspace, protected globs (default .git/**, .env*, .env/**), or scratch roots. Approval is resolved through ctx.approval.request(...) and only allowed-once lets the registry dispatch the call; otherwise the tool fails closed with nothing written.

The plugin is intended for DSH users who need full GPU access yet want to keep sensitive files and out-of-workspace paths from being silently modified, and it integrates purely through existing DSH extension points — no core package is touched. Install it inside a DSH profile with dsh plugin --profile web add ./dsh-full-with-approval (pnpm file: form copies the package and installs declared dependencies, while link: requires a prior npm install in the checkout). Once added, the new row appears automatically in the GUI selector and the /permission slash command; the gate follows whichever preset is currently active.

Runtime dependencies are picomatch and the harness packages; tests run with npm ci, node --test, and the harness integration script test/pre-execute.harness.mjs. Documented limitations include a heuristic (not kernel-enforced) bash guard that errs toward asking yet can be evaded by dynamically built paths, the absence of the upstream risk-confirmation gate that stock danger-full-access shows (because the icon table lives inside the @deepseek-ai/dsh-client-ui-conversation bundle and cannot be overridden from a plugin), and the need to run node tools/patch-ui-glyph.mjs after each dsh upgrade to draw the 4th row's shield-check glyph. Path classification is canonicalize-then-compare, so on filesystems with odd symlink aliasing the workspace boundary is advisory; the real kernel fence remains workspace-write mode at the cost of GPU access. The package is MIT licensed and ships as a standard npm pack tarball, with pnpm supply-chain errors resolvable via --config.minimum-release-age=0.

dsh-full-with-approval 是一个面向 DeepSeek Harness(DSH)平台的 profile 插件,它在原有三种权限预设之外追加了第四种 "full-with-approval"。该预设把会话沙箱切到 danger-full-access,从而放开 GPU、设备、网络与任意二进制,但同时通过 DSH 的 tools/pre-execute 钩子对写入与 shell 命令做一次性的用户审批。安装方式是进入 DSH profile 后执行 dsh plugin --profile web add ./dsh-full-with-approval,由 dsh plugin add 调用 pnpm 把声明了 dsh.bundle 的包并入层叠栈。

典型用法是在 Web 权限选择器中挑选"Full With Approval",或直接执行 /permission full-with-approval;此后任何命中工作区外或 protectedPaths 的 write/edit、以及包含外部路径写标记的 bash/pwsh 命令都会弹出 ctx.approval 的 ask 提示,approved-once 通过则放行,被拒则整个调用失败。它面向需要 CUDA 全算力又不想牺牲关键文件安全的 DSH 终端用户与团队管理员。

依赖为 picomatch 与 harness 包;限制是 shell 守卫基于静态启发式,动态拼接路径仍可绕过,故应视为"可疑即问"层而非安全边界,且 4 行图标需用 tools/patch-ui-glyph.mjs 手动打补丁;首次运行需 npm ci 并重启 profile 生效,许可证为 MIT。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add dsh-full-with-approval

把 zjuhbh/dsh-full-with-approval 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-full-with-approval

A DeepSeek Harness (DSH) profile plugin that adds a fourth permission preset, full-with-approval:

  • Full compute access — the session sandbox mode is danger-full-access, so processes run unconfined: CUDA/GPU, devices, network and any binary your machine can run.

  • Approval-gated file edits — while this preset is active, every write/edit that would modify

    • a file outside the session workspace (except the platform temp areas and configured scratch roots), or
    • a protected file inside the workspace (default: .git/**, .env*),

    asks the user for one-shot approval before anything executes. Approval is resolved through the same interactive prompt the sandbox escalation retries use (ctx.approval, allowed-once). Rejected or cancelled ⇒ the tool fails and nothing is written. If no approval channel is available, the call fails closed.

  • Approval-gated shell modifications — a bash/pwsh command that shows evidence of modifying files outside the workspace (out-of-workspace path tokens plus a write marker: redirection, chmod, rm, python, curl -o, …) also asks first; visibly read-only invocations (cat, ls, grep, env, … without a write marker) and workspace-relative commands pass without prompting. The static heuristic errs on the side of asking: interpreters (python, node) and command substitutions that mention outside paths always ask. bashGuard: false disables this layer; extraBashTokens adds forced-ask substrings.

Everything else — writes inside the workspace to ordinary files, temp/scratch files, all reads and every command — proceeds untouched.

How it works

The plugin is a thin load-bearing layer over existing DSH extension points; no core package is modified.

  1. cordis.patch.yml patch entry full-with-approval mounts the host plugin.
  2. The same patch overrides the permission preset table (by id) to add the 4th preset full-with-approval = { sandbox: danger-full-access, approval: ask }. The GUI permission selector and /permission command read this table, so the new row appears automatically.
  3. The plugin listens on the tools registry's tools/pre-execute waterfall (the official allow / deny / ask before dispatch hook). When the session's effective preset is full-with-approval and the call is a write/edit whose target is outside the workspace or protected, it returns { kind: "ask", reason }. The registry resolves the ask through ctx.approval.request(...) and only dispatches on allowed-once.

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-tonghuashun 下一个 Next dsh-venv →