Jiao-XXX/dsh-auto-approve

Add an automatic approval permission file between Workspace Write and Full access for DeepSeek Harness. Dangerous or uncertain operations are still transferred to manual approval.

dsh-auto-approve adds an Auto permission tier to DeepSeek Harness for long-running tasks and dependency installs with fewer interruptions but a complete audit trail. For each approval/request in the auto preset it: (1) recovers the raw tool/call arguments from the in-memory session log and reads the newest genuine user message; (2) checks the justification and tool arguments against a deterministic danger list — a confusion circuit breaker sends destructive commands that use command or process substitution directly to a human; (3) sends the command, justification, target sandbox mode, workspace path, and latest user message to the configured classifier model; explicit authorization in the genuine user message can inform the decision, but command examples or quotations alone are not execution authorization; (4) returns allowed-once only for the exact verdict 'approve' — every other result delegates to the normal human approval flow. Its positioning: more convenient than Workspace Write, safer than Full access.

Agent Capabilities ★ 8 updated 2026-09-07 ✅ runtime-tested
View on GitHub ↗

Install

dsh plugin --profile web add github:Jiao-XXX/dsh-auto-approve

Install with dsh plugin --profile web add github:Jiao-XXX/dsh-auto-approve (or from a local checkout with dsh plugin --profile web add ./dsh-auto-approve); remove with dsh plugin --profile web remove dsh-auto-approve. The bundle restates the permission preset table into four tiers: read-only, workspace-write, auto (new), danger-full-access. MIT licensed.

Compatibility

DeepSeek Harness with approval/request handling. Adds the Auto permission tier between workspace-write and danger-full-access: same as workspace-write, but routine escalations are auto-approved while destructive-list matches, classifier uncertainty, or failures go to a human. Recovers raw tool/call arguments from the in-memory session log and reads only the newest genuine user message (source.kind === 'user'; plugin messages ignored; messages over 2,000 characters go straight to human review).

Details

Recent updates

The current README documents the four-tier permission table, the auto decision pipeline, the danger list and confusion circuit breaker, the 2,000-character user-message cutoff, the allowed-once-only return contract, and the MIT license.

FAQ

What does the Auto tier do?
Same as workspace-write, but routine sandbox escalations are auto-approved with allowed-once; destructive-list matches, classifier uncertainty, timeouts, malformed responses, or plugin errors go to a normal human approval popup.
Can a model authorize itself by quoting commands?
No — command examples or quotations alone are not execution authorization; only explicit authorization in a genuine user message can inform the decision.
What happens if the classifier fails?
Every result other than the exact verdict 'approve' delegates to the normal human approval flow — including timeouts and malformed responses.

Alternatives

suntianc/dsh-codex-auth · vlln/dsh-task-status · timeance/dsh-approve-for-me

More plugins in Agent Capabilities

Browse more in Agent Capabilities

Guides for Agent Capabilities plugins