Andy8647/dsh-auto-approval

Automated tool-call approval for DeepSeek Harness: an auto tier for the approval policy that classifies every tool call as allow or deny — fully autonomous, no human in the loop, and uncertain calls are denied. The host half is a pre-execute classifier with L0 rules plus an L1 LLM; the optional client half shows an AA status chip beside the composer access-mode selector (AA on/off, hover for cumulative stats, click for a dialog with the switch, config summary, and a recent-decisions table).

Agent Capabilities ★ 4 updated 2026-09-20 ⚠️ needs adapt
View on GitHub ↗

Install

dsh plugin --profile web add dsh-auto-approval

npm package dsh-auto-approval 0.1.0 (registry-verified 2026-08-25). Install both packages into the same profile (published to npm, ships built artifacts — no build environment needed): the host half dsh plugin --profile web add dsh-auto-approval (required: the approval decision logic) and the optional client half dsh plugin --profile web add dsh-client-ui-auto-approval (the AA status chip in the composer). BSD-3-Clause license.

Compatibility

DeepSeek Harness Web profile. Host half (pre-execute classifier) + optional client chip. Classifies every tool call as allow/deny with a two-state policy.

Details

Recent updates

v0.1.0: two-state allow/deny classifier (L0 rules + L1 LLM); whitelisted file read/write and ls dispatch directly; dangerous commands rejected by deny rules / legacy-ask rules / self-kill guard.

FAQ

What does the auto tier do?
It classifies every tool call as allow or deny with no human in the loop. Fully autonomous operation — uncertain calls are denied by design.
Do I need both packages?
Only the host half (dsh-auto-approval) is required for the decision logic. The client half (dsh-client-ui-auto-approval) adds the AA status chip beside the composer's access-mode selector.
How do dangerous commands behave?
They are rejected by deny rules, legacy-ask rules (which now deny), and the self-kill guard. The demo covers whitelisted file operations and a harmless command allowed by the L1 classifier.

Alternatives

Jiao-XXX/dsh-auto-approve · timeance/dsh-approve-for-me · Hanihahaha/dsh-auto-approve

More plugins in Agent Capabilities

Browse more in Agent Capabilities

Guides for Agent Capabilities plugins