Automated approval review: auto-approve read-only tools, auto-deny dangerous commands, fail-closed policy engine.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:DamonKoy/dsh-plugins#path:/packages/dsh-approve-for-me
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
Automated approval review for DeepSeek Harness. Inspired by Codex 0.147's
--approve-for-me (Guardian auto-review).
English | 中文
What it does
approval/requesthook: inreviewmode, read-only tools (read,grep,glob,ssh_list, inspection tools, ...) are auto-approved; inautomode every request is approved — except dangerous commands, which are always denied (fail-closed security floor).tools/pre-executehook: dangerous shell commands (rm -rf /,mkfs,dd of=/dev/sdX, fork bombs,chmod -R 777 /,curl|sh,shutdown, ...) are hard-blocked before dispatch, so they never reach the approval prompt.approval_policy_statustool: report the current mode and activity.- RPC (
approve-for-me/status,approve-for-me/set-mode) for client halves and other plugins.
Modes
| Mode | Read-only tools | Other tools | Dangerous commands |
|---|---|---|---|
off |
ask human | ask human | ask human |
review (default) |
auto-approve | ask human | auto-deny |
auto |
auto-approve | auto-approve | auto-deny |
Install
dsh plugin --profile web add github:DamonKoy/dsh-plugins#path:/packages/dsh-approve-for-me
Restart dsh web. Default mode is review.
Config
~/.dsh/dsh-approve-for-me.json:
{ "mode": "auto" }
Valid modes: off | review | auto. You can also switch at runtime via the
approve-for-me/set-mode RPC (memory-only, resets on restart).
Security notes
- Auto-approval never bypasses the dangerous-command denylist.
- Denials are fail-closed: a throwing listener falls through to the human answerer, never to silent approval.
- The policy engine (
lib/policy.js) is unit-tested; runnode --test test/to verify.
License
MIT
Links
More in this category
toby-bridges/api-relay-audit★ 867
Runs local security audits of AI API relays and LLM proxies from DeepSeek Harness, producing Markdown reports for prompt injection, model substitution signals, tool-call rewriting, error leakage, stream integrity, and profile-gated Web3 risks.
SeaOf0/dsh-redteam-model★ 659
Authorized-security DSH collection: nine work modes (redteam coordinator, pentest, code audit, binary analysis, attack-defense, AV evasion, incident response, cloud security, CTF solving) and fifteen runtime plugins, managed from a settings page with one-click deploy, install, update and uninstall.
howmp/dsh-pentest★ 578
Authorized pentest mode for DeepSeek Harness — exploration chain, assets and findings with a Web view.
PerryLink/dsh-auto-review★ 223
Second-model auto-review on the approval answerer chain: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default.
NanmiCoder/dsh-auto-mode★ 163
Adds an Auto permission preset between Workspace Write and Full access: routine work stays in the official workspace-write sandbox while the current session model reviews escalation and destructive calls, granting one exact wider access once, asking when the intent is ambiguous, and denying critical paths.
PerryLink/dsh-permission-rules★ 116
Claude Code-style declarative permission rules: ordered allow/deny/ask YAML rules matching tool names, arguments, workspace paths, and agent identity on the tools/pre-execute waterfall, with full session-log audit, dry-run mode, and hot reload.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.