wangxing-git/dsh-autogate
Safe auto-approval for DeepSeek Harness — deterministic rules + LLM review on top of the workspace-write sandbox. Auto mode without ever granting full-access.
dsh-autogate is a DeepSeek Harness auto-approval plugin that adds two permission presets on top of the workspace-write sandbox using layered decisions: L0 deterministic rules (zero-cost allow/deny for read-only ops, in-workspace edits/deletes, build/test, run_code, plus hard denies for privilege escalation, self-destruction, credential exfiltration and filesystem-root/system-path mutation), L1 LLM safety approval (a two-state allow/deny classifier with sanitized, tag-separated inputs and injection defence), and L2 human approval (approval popups pass the LLM first). It keeps the sandbox boundary and never relaxes to full-access by default; subagents inherit the parent's preset with authority anchored at the top-level session. A floating 'Approval trail' overlay shows the most recent 50 decisions per session with layer badges and a Locate button.
Install
dsh plugin --profile web add github:wangxing-git/dsh-autogateThe compiled lib/ is committed. The README also gives the no-PATH form npx @deepseek-ai/dsh plugin --profile web add github:wangxing-git/dsh-autogate. Restart dsh after installing. Configuration is wired through the DSH settings service: write an autogate: section in $DSH_HOME/settings.yaml (hot-reloads immediately) or fall back to the entry config: {} in cordis.patch.yml; since dsh 0.1.6-alpha.2 plugin configuration moved to the Plugins page. No registry package is claimed.
Compatibility
DeepSeek Harness with the workspace-write sandbox. Adds two permission presets -- semi-auto (auto-ask, default) and full-auto (auto) -- on top of the workspace-write sandbox. The README warns this is a decision layer that reduces manual approvals, NOT a security boundary: the real enforcement boundary remains DSH's workspace-write sandbox and its escalation approval, and the L1 LLM classifier is heuristic (fail-closed on errors/timeouts).
Details
- Repo: wangxing-git/dsh-autogate
- Category: uncategorized
- Stars: 1
- Version: source install from GitHub (no npm registry package claimed); MIT
- Last push: 2026-08-17
- First seen: 2026-08-15
Recent updates
The README documents the autogate: settings block (preflight, showTrail, presetName, fullAutoPresetName, classifier timeout/token/retry, optional classifier prompt/provider/model/endpoint/apiKeyEnv, workspaceRoot, tempRoots), the key difference from similar plugins (ordinary calls stay workspace-write; unknown tools go to LLM classification rather than being allowed; fail-closed), and a substantial security disclaimer covering the one-shot L2 escalation widening, the classifier's heuristic nature, and the TOCTOU window on static path checks.
FAQ
- How do I install dsh-autogate?
- Run dsh plugin --profile web add github:wangxing-git/dsh-autogate (or the npx form), then restart dsh. The compiled lib/ is committed, so no build step is needed.
- Does it weaken the sandbox?
- Per the README ordinary calls stay under the workspace-write sandbox and L0/L1 never widen it; the exception is the L2 escalation channel, where an approved escalation runs that single call with the requested wider sandbox -- the README stresses this is a real one-time elevation.
- What is the difference between the two modes?
- Both share the same L0 rules and L1 classifier; the only difference is the L2 fallback -- semi-auto (auto-ask) shows a human popup after an LLM deny/error, while full-auto (auto) treats the LLM decision as final with no human popup.
Alternatives
moon09300731/dsh-approval-gate · TecFancy/dsh-auth-gate · MrWeiCodes/dsh-permgate