Letter2025/dsh-approval-llm
Model-based permission approval (approve-for-me) for DeepSeek Harness: an approval/request answerer backed by
dsh-approval-llm adds a model-approval (approve-for-me) permission mode to DeepSeek Harness: in that mode, approval/request asks are answered by a separate reviewer model instead of a human — the reviewer decides ALLOW / DENY / ESCALATE, and the request only reaches a human when the reviewer cannot decide or fails. It is the DSH equivalent of Codex's approvals_reviewer=auto_review (--approve-for-me). Deterministic routing (denyList, allowlist, humanOnlyList) happens before any model call; the reviewer holds an isolated security-policy prompt the main agent never sees; tool arguments are recovered from the session log so the reviewer judges the real call, not the agent's claim. A circuit breaker hands the session to a human after consecutive denials, and model failures (timeout, parse error, provider error) escalate to a human rather than fabricating a rejection. Every ALLOW/DENY appends a user-visible decision message to the session. The package ships a bundled configure-approval-llm skill that walks an AI-proposes / user-confirms configuration flow. Warning from the README: an AI reviewer is a policy choice, not a security guarantee — prefer it for low-risk workflows and keep humanOnlyList, denyList, and the breaker tight.
Install
dsh plugin --profile web add dsh-approval-llmnpm package dsh-approval-llm 0.1.4 (registry-verified 2026-08-24). Recommended bundle install: dsh plugin --profile web add dsh-approval-llm — the package declares dsh.bundle.patch, so installing activates a config layer that inserts the plugin row AND adds the model-approval ('帮我批准') preset to the permission table. Then restart dsh web and pick 帮我批准 in the permission selector (Access chip in the input bar) to switch that session's reviewer to the model. The preset table is process-level, so changing presets requires a dsh restart. Local checkout alternative: pnpm run build, then dsh plugin --profile web add ./dsh-approval-llm from the parent directory. The package also ships a bundled configure-approval-llm skill (AI-proposes / user-confirms config flow). Requires a dsh version with the approval waterfall seam (developer preview, breaking changes).
Compatibility
DeepSeek Harness web profile with the approval waterfall seam. Model-approval mode answers approval/request asks with a separate reviewer model (ALLOW / DENY / ESCALATE); every other permission mode delegates to the human channel unchanged. Deterministic routing (denyList / allowlist / humanOnlyList) runs before any model call. Circuit breaker: maxConsecutiveDenials (default 3) consecutive DENY hands the rest of the session's asks to a human. Fail-to-human on TIMEOUT / parse error / provider error — never a fabricated denial. Reviewer prompt is isolated from the main agent; tool arguments are recovered from the session log. Requires the dsh approval chain to have one terminal answerer (compose a human UI answerer behind this plugin for human override).
Details
- Repo: Letter2025/dsh-approval-llm
- Category: Agent Capabilities
- Stars: 7
- Version: npm package dsh-approval-llm 0.1.4 (registry-verified 2026-08-24)
- Last push: 2026-09-08
- First seen: 2026-08-14
Recent updates
The current English README documents: the model-approval permission mode and design mapping to Codex auto_review and AGENTSCOPE-PLAN-058/062/063, the decision waterfall (mode gate → routing policy → circuit breaker → reviewer model), ALLOW/DENY/ESCALATE mapping to dsh outcomes, full configuration reference (enabled, modePreset, provider/model, timeoutMs, maxOutputTokens, systemPrompt, allowlist, denyList, humanOnlyList, maxConsecutiveDenials, maxArgsChars, includeArgs, notifyUser), bundle install with the auto-added model-approval preset, bundled configure skill, source-overlay dev mode, security model, and known limitations.
FAQ
- Does the reviewer replace human approval everywhere?
- No — mode gating keeps human approval unchanged. The plugin only answers asks from sessions whose effective permission preset equals modePreset (default model-approval / 帮我批准); every other session delegates to the human channel exactly as before the plugin existed.
- What happens if the reviewer model fails or times out?
- TIMEOUT, parse errors, and provider errors produce ESCALATE (delegate to the next answerer — the human UI), never a fabricated denial, and are not counted in the circuit breaker. A deployment with no human answerer resolves unavailable, which callers treat as denial (fail-closed by composition).
- How does the reviewer decide without seeing the main agent's prompt?
- Prompt isolation: the reviewer prompt is assembled by this plugin from its own config and the main agent never sees the security policy. Tool descriptions come from the live registry and arguments from the durable session log, so the reviewer judges the real call.
Alternatives
timeance/dsh-approve-for-me · Jiao-XXX/dsh-auto-approve · suntianc/dsh-codex-auth