PAKIKNOWLEDGE/dsh-auto-classifier
Autonomous permission classifier for the auto preset: tool-scoped allow/deny rules, an LLM semantic judge, and git checkpointing for unattended sessions.
dsh-auto-classifier adds a fourth permission preset — auto (Autonomous) — beside read-only / workspace-write / danger-full-access, in the style of Claude Code auto mode. On tools/pre-execute every tool call sees its name plus full arguments and dangerous commands (system-directory deletion, formatting, registry writes, git reset --hard / force push, credential access) are denied before anything executes; on approval/request, sandbox escalations are auto-allowed/auto-rejected by the classifier without a browser prompt. Before an allowed high-risk escalation the workspace is checkpointed with a throttled git add -A && git commit (auto_snapshot snapshots manually anytime). A systemPrompt section injects autonomous-mode discipline (risk tiers, git rescue, no infinite retry loops, email-and-stop when a human decision is needed). A bilingual (EN · 中文) web control page — Settings → Plugins → Auto Classifier — provides live phone-style toggles (LLM judge, write-content scan, strict default, judge stages, default decision), judge-model configuration (provider / base URL / API key / model; credentials saved and the judge calls that provider directly over HTTPS with a Test button; the API key is never returned, only masked), session stats and the recently-denied list. A Claude Code style tool-scoped rule engine supports Tool(pattern) rules with case-insensitive regexes and field projection to avoid false positives.
Install
dsh plugin --profile web add dsh-auto-classifiernpm dsh-auto-classifier 0.1.14 verified 2026-09-03 (repository field → github.com/PAKIKNOWLEDGE/dsh-auto-classifier; README EN primary with zh edition). The README's recommended route is pack-and-add for Windows workspaces (workspace-write sandbox blocks npm's default cache dir): npm pack --cache <workspace-path> in the repo, then in ~/.dsh/profiles/web pnpm add "dsh-auto-classifier@file:...tgz" --force with the bundle row appended, then dsh --profile web --dump-config and restart. Its cordis.patch.yml injects rows as a bundle patch — never manually insert the same row ids in profile/home layers (duplicate loader entry kills web startup). The classifier is active only in sessions whose permission preset is auto; all other sessions keep stock behavior.
Compatibility
DSH web profile; active only under the auto (Autonomous) permission preset; judge-model direct HTTPS mode supports OpenAI-compatible and Anthropic endpoints; web control page requires the host webServer service.
Details
- Repo: PAKIKNOWLEDGE/dsh-auto-classifier
- Category: Development & Runtime
- Stars: 0
- Version: npm dsh-auto-classifier 0.1.14
- Last push: 2026-08-16
- First seen: 2026-08-15
Recent updates
auto permission preset; pre-execute danger classifier + sandbox auto-approval; git checkpoint before high-risk escalation; system-prompt discipline section; bilingual control page with direct-connect judge-model config (v0.1.14).
FAQ
- When is the classifier active?
- Only in sessions whose permission preset is auto. Every other session keeps the stock interactive behavior — handlers simply call next().
- How are dangerous commands handled?
- On the tools/pre-execute waterfall each call is checked by name plus full arguments; patterns like system-directory deletion, git reset --hard or credential access are denied before anything executes.
- Where is the judge API key stored?
- In the model configuration endpoint, persisted server-side; the web page never returns it — only a mask — and a Test button pings the exact credentials typed.
Alternatives
940842546/dsh-permissions · tappass/dsh-governance · 863683348/dsh-gov