timeance/dsh-approve-for-me
DeepSeek Harness sandbox permission expansion approval: Shell/PowerShell literal command prefix rules, fixed high-risk checks, optional toolless LLM reviewer; only allowed-once is granted successfully, high-risk or uncertain requests return to native manual approval, supports Web/headless Profile
dsh-approve-for-me provides rule-gated automatic approval of Shell and PowerShell sandbox escalations in DeepSeek Harness: fixed high-risk checks, literal command-prefix rules, and an optional tool-free LLM reviewer. Rules define the boundary; the reviewer may narrow the auto-approval set but cannot bypass rules or fixed high-risk checks; everything uncertain returns to native human approval. Every successful decision grants one allowed-once — it never grants permanent access. Known package lifecycle actions, path-qualified executables, direct scripts, wrappers, and mutating PowerShell commands are handled conservatively. Configuration happens in the Web UI (Settings -> Plugins -> Plugin configuration -> Approve for me) with narrow, literal token prefixes (e.g. git status, git diff, Get-Location); a prefix is a parsed token prefix, not exact string equality, and every segment of a compound command must match independently.
Install
dsh plugin --profile web add dsh-approve-for-me@latestnpm install -g @deepseek-ai/dsh, dsh plugin --profile web add dsh-approve-for-me@latest, then dsh web --host 127.0.0.1 --port 3080. Then open Settings -> Plugins -> Plugin configuration -> Approve for me, add only command prefixes you are willing to review automatically, and select the 'Approve for me' Access preset for the target agent or session. commandPrefixes is empty by default — installing the plugin alone does not automatically approve any command. @latest is an npm dist-tag, not a fixed version; use @beta only when you explicitly want the beta channel, and @<version> for reproducible installs. Published on npm (0.2.2).
Compatibility
DeepSeek Harness 0.1.1-rc.1 (including rc1's keyed third-party settings-card slot and shared client settings schema service). Works with the Shell and PowerShell sandbox escalation approval boundary; integrates as an Access preset. Unofficial plugin — no independent security audit; the README warns to keep allowlists narrow.
Details
- Repo: timeance/dsh-approve-for-me
- Category: Coding & Development
- Stars: 12
- Version: npm dsh-approve-for-me 0.2.2 (adapted to DeepSeek Harness 0.1.1-rc.1); MIT
- Last push: 2026-09-12
- First seen: 2026-08-14
Recent updates
The current README documents the 0.2.2 adaptation to 0.1.1-rc.1, the quick start, why-use-it comparison (native approval vs Approve for me vs Full access), web configuration with example prefixes, and the allowed-once security model.
FAQ
- Does installing it auto-approve everything?
- No — commandPrefixes is empty by default; you must add prefixes and select the 'Approve for me' Access preset for the target agent or session.
- Can the LLM reviewer grant more than the rules allow?
- No — the reviewer may narrow the set but cannot bypass rules or fixed high-risk checks; uncertain requests return to native human approval.
- Does it grant permanent access?
- No — every successful decision grants one allowed-once; it never grants permanent access.
Alternatives
sjh9714/dsh-win32 · cc1252/deepseek-harness-desktop · dhicoc/dsh-reverse-skill