timeance/dsh-approve-for-me

DeepSeek Harness sandbox permission expansion approval: Shell/PowerShell literal command prefix rules, fixed high-risk checks, optional toolless LLM reviewer; only allowed-once is granted successfully, high-risk or uncertain requests return to native manual approval, supports Web/headless Profile

dsh-approve-for-me provides rule-gated automatic approval of Shell and PowerShell sandbox escalations in DeepSeek Harness: fixed high-risk checks, literal command-prefix rules, and an optional tool-free LLM reviewer. Rules define the boundary; the reviewer may narrow the auto-approval set but cannot bypass rules or fixed high-risk checks; everything uncertain returns to native human approval. Every successful decision grants one allowed-once — it never grants permanent access. Known package lifecycle actions, path-qualified executables, direct scripts, wrappers, and mutating PowerShell commands are handled conservatively. Configuration happens in the Web UI (Settings -> Plugins -> Plugin configuration -> Approve for me) with narrow, literal token prefixes (e.g. git status, git diff, Get-Location); a prefix is a parsed token prefix, not exact string equality, and every segment of a compound command must match independently.

Coding & Development ★ 12 updated 2026-09-12 — untested
View on GitHub ↗

Install

dsh plugin --profile web add dsh-approve-for-me@latest

npm install -g @deepseek-ai/dsh, dsh plugin --profile web add dsh-approve-for-me@latest, then dsh web --host 127.0.0.1 --port 3080. Then open Settings -> Plugins -> Plugin configuration -> Approve for me, add only command prefixes you are willing to review automatically, and select the 'Approve for me' Access preset for the target agent or session. commandPrefixes is empty by default — installing the plugin alone does not automatically approve any command. @latest is an npm dist-tag, not a fixed version; use @beta only when you explicitly want the beta channel, and @<version> for reproducible installs. Published on npm (0.2.2).

Compatibility

DeepSeek Harness 0.1.1-rc.1 (including rc1's keyed third-party settings-card slot and shared client settings schema service). Works with the Shell and PowerShell sandbox escalation approval boundary; integrates as an Access preset. Unofficial plugin — no independent security audit; the README warns to keep allowlists narrow.

Details

Recent updates

The current README documents the 0.2.2 adaptation to 0.1.1-rc.1, the quick start, why-use-it comparison (native approval vs Approve for me vs Full access), web configuration with example prefixes, and the allowed-once security model.

FAQ

Does installing it auto-approve everything?
No — commandPrefixes is empty by default; you must add prefixes and select the 'Approve for me' Access preset for the target agent or session.
Can the LLM reviewer grant more than the rules allow?
No — the reviewer may narrow the set but cannot bypass rules or fixed high-risk checks; uncertain requests return to native human approval.
Does it grant permanent access?
No — every successful decision grants one allowed-once; it never grants permanent access.

Alternatives

sjh9714/dsh-win32 · cc1252/deepseek-harness-desktop · dhicoc/dsh-reverse-skill

More plugins in Coding & Development

Browse more in Coding & Development

Guides for Coding & Development plugins