moon09300731/dsh-approval-gate
Automatic approval gate control: Flash predicts whether the write/command is irreversible, automatically approves safe operations, and transfers dangerous operations to manual work (fail-safe)
dsh-approval-gate is an automatic approval gate for DeepSeek Harness: every sandbox-escaping action is pre-classified by a Flash model (SAFE / RISKY), recoverable operations auto-pass, and hard-risk operations — delete, credentials, remote/production, system paths, and unrecoverable batch actions — always escalate to human approval without counting or learning. Confirmation-based learning auto-approves an operation after you confirm it N-1 times, with operation fingerprints so only operations you confirmed get released; semantic-similarity validation resists wording changes. A UI review surface shows what was learned.
Install
dsh plugin --profile web add dsh-approval-gatenpm dsh-approval-gate 0.5.0 verified 2026-09-01 (maintainer moon0930; README has EN edition README.en.md, repo moon09300731/dsh-approval-gate). Automatic approval gating: a Flash model predicts each sandbox-escaping action as SAFE or RISKY, auto-approves recoverable operations, and always routes hard-risk operations (delete / credentials / remote / system / batch) to a human, fail-safe. Learning only applies to operations you confirmed.
Compatibility
DSH web profile; Flash classifier model required; fail-safe design.
Details
- Repo: moon09300731/dsh-approval-gate
- Category: Agent Capabilities
- Stars: 2
- Version: npm dsh-approval-gate 0.5.0
- Last push: 2026-08-20
- First seen: 2026-08-14
Recent updates
Flash risk pre-classification; hard-risk always human; confirmation-based learning with operation fingerprints; fail-safe; review UI.
FAQ
- Which operations always go to a human?
- Delete, credentials, remote/production, system paths, and unrecoverable batch actions — they are never auto-approved and never learned.
- How does auto-approval learning work?
- After you confirm the same operation N-1 times, it auto-approves; each learned rule carries an operation fingerprint so only confirmed operations are released.
- How do I install it?
- dsh plugin --profile web add dsh-approval-gate (npm 0.5.0).
Alternatives
cdxiaodong/dsh-guardian · arrow949/dsh-turn-approval · moon09300731/dsh-approval-gate