simon300000/dsh-auto

Adds an Auto Approve permission preset to the Web UI, using a fresh restricted Reviewer Agent to allow or deny each approval request.

dsh-auto adds an Auto Approve permission preset to the DeepSeek Harness Web UI: each action that requires approval is reviewed by a fresh, restricted DSH child Agent before the plugin allows or denies it. The plugin handles approval/request only when the session selects Auto Approve — other presets continue through DSH's existing approval chain. Each approval spawns one Reviewer session; DSH's own agent loop handles bounded read/glob/grep investigation. The child runs in a read-only sandbox with approval/policy = never, an execution guard that denies every tool except read/glob/grep plus a scoped structured-output tool, no further subagents, and at most four investigation steps plus the final response. Only the outcome is required in the structured result (a compact {"outcome":"allow"} defaults the rest); direct user messages, human answers, assembled system instructions and workspace instructions can establish authorization, while assistant content and other tool results remain untrusted evidence.

Workflow & Automation ★ 0 updated 2026-09-10
View on GitHub ↗

Install

dsh plugin --profile web add github:simon300000/dsh-auto

GitHub install per README (EN primary with 中文): dsh plugin --profile web add github:simon300000/dsh-auto. npm 404 verified 2026-09-04. Restart the Web UI, then select the Auto Approve permission preset in the session Permissions selector (or set it as the default in General Settings). Bundled defaults review each action with deepseek-official/deepseek-v4-flash at high reasoning; reviewerProvider/reviewerModel must be set together — if both are omitted the Reviewer uses the parent session's current provider and model.

Compatibility

DeepSeek Harness Web UI (current release supports Web only); adds an Auto Approve permission preset; reviewer defaults deepseek-official/deepseek-v4-flash (high reasoning); read-only sandbox child with approval/policy = never.

Details

Recent updates

No npm release (404 verified 2026-09-04); README documents current Web-UI-only release.

FAQ

Does it auto-approve everything?
No — it reviews every approval request with a fresh restricted Reviewer subagent; the Reviewer runs read-only with approval/policy = never and may only investigate with read/glob/grep before allowing or denying.
Which model reviews actions?
By default deepseek-official/deepseek-v4-flash at high reasoning; configure reviewerProvider/reviewerModel together, or omit both to have the Reviewer use the parent session's provider/model.
Does it affect other permission presets?
No — it only handles approval/request when the session selects Auto Approve; all other presets continue through DSH's existing approval chain.

Alternatives

moon09300731/dsh-approval-gate · timeance/dsh-approve-for-me

More plugins in Workflow & Automation

Browse more in Workflow & Automation

Guides for Workflow & Automation plugins