Adds an approval-mode toggle next to the permission selector: default approval keeps per-call confirmation, bypass approval auto-approves every tool call while staying in Workspace Write.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:NEVSTOP-LAB/dsh-approval-mode
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
An approval mode plugin for DSH. Adds an "approval mode" button next to the permission selector (Read Only / Workspace Write / Full Access) in the DSH window. Keep the permission at Workspace Write and pick "Bypass, escalations excepted" — tool calls are auto-approved, while file operations stay sandboxed to the workspace, safer and more convenient than Full Access.
[!IMPORTANT] Both bypass modes auto-approve tool calls; ordinary operations show no confirmation prompt.
- Bypass, escalations excepted: ordinary tool calls pass through; writing outside the workspace, or any command that needs a wider sandbox, still prompts and the one-shot grant is yours to give.
- Bypass approval: escalations are auto-approved too, so the sandbox boundary opens with everything else (high risk).
Use them only when you fully trust the current task, and switch back to "default approval" when done. When the session permission is Full Access, DSH never issues approval requests, so these modes have no effect.
Features
- The button sits in the composer toolbar next to the permission selector, styled like the permission control
- Default approval: identical to stock DSH — tool calls require a click to approve
- Bypass, escalations excepted: tool calls are auto-approved; widening the sandbox to write outside the workspace still prompts you
- Bypass approval: every tool call is auto-approved, escalations included, with no prompt at all (high risk)
- Changes apply immediately and persist per session
- The button turns orange in either bypass mode: a hollow shield for escalations-excepted, a bolt for full bypass
- With Full Access permission, the button is greyed out and shows "绕过审批": DSH never issues approval requests, so the mode cannot be switched
- Switching mode notifies the agent of that session
- Settings → Plugins carries this plugin's default approval mode (rendered by the host from the plugin Config on DSH 0.1.7+, a standalone card under Plugin configuration on older hosts)
Configuration
The approval mode is two values, each with its own entry point:
| Entry point | Where | Scope |
|---|---|---|
| Approval-mode button | Composer toolbar, next to the permission selector | The current session: no other session is affected |
| Default approval mode | Settings → Plugins (0.1.7+) / the plugin-configuration card (0.1.6 and older) | The default: sessions without a mode of their own follow it, running ones included; a session already given its own mode on the button is unaffected |
The toolbar button never rewrites the default, and the default only moves the sessions that have no mode of their own: change the default in Settings, wave one session through with the button.
Where they live: the default is this plugin's own config field (stored by the host in the profile patch on DSH 0.1.7+); each session's own mode is kept in $DSH_HOME/approval-mode/sessions.json (a plugin-owned directory, written atomically).
Both apply immediately and persist.
[!IMPORTANT] Upgrading from DSH 0.1.6 or older to 0.1.7+: 0.1.7 replaced the old settings store (it renames
settings.yamltosettings.yaml.imported), so a default mode written by an older version can no longer be read on the new host — pick it once under Settings → Plugins → dsh-approval-mode. Per-session modes are migrated by the plugin on its first start, so nothing there needs doing by hand.
Install
Requires the dsh CLI (lower bound 0.1.1-rc.2, verified on 0.1.5-rc.2, 0.1.7-rc.1 and 0.2.0-rc.1 — see the version note below).
Install from the GitHub repository:
dsh plugin --profile web add github:NEVSTOP-LAB/dsh-approval-mode
[!NOTE]
--profile webis the default profile. Use--profile desktopfor DSH Desktop; replacewebwith the name of any other profile.
[!NOTE] Version requirement: DSH
0.1.1-rc.2or newer (no upper bound); verified on DSH0.1.5-rc.2(DSH Desktop 2.0.11),0.1.7-rc.1(DSH Desktop 2.0.14) and0.2.0-rc.1(DSH Desktop 2.0.16). An older host is reported by dsh-market as "below declared minimum", so upgrade DSH first. 0.1.7 replaced the settings service contract (plugin Config instead of namespaces); this plugin supports both, and the default mode has to be set once after that upgrade — see Configuration above. From 0.2.0 on, no@deepseek-ai/dsh-*peer is declared: the plugin imports no versioned host package (the notification message is built in-tree), so a 0.2 host can no longer report it as incompatible. Development, the reasoning behind the declared ranges and the compatibility checklist live in CONTRIBUTING.md.
Pinning a commit is recommended so later pushes cannot silently change what runs:
dsh plugin --profile web add github:NEVSTOP-LAB/dsh-approval-mode#<commit-sha>
Or download the tarball from Releases and install it:
dsh plugin --profile web add ./dsh-approval-mode-0.2.0.tgz
Verify the composed config contains the plugin layer:
dsh --profile web --dump-config
After boot, the "默认审批" button appears next to the permission selector in the composer toolbar.
Uninstall:
dsh plugin --profile web remove dsh-approval-mode
License
MIT
Links
More in this category
toby-bridges/api-relay-audit★ 868
Runs local security audits of AI API relays and LLM proxies from DeepSeek Harness, producing Markdown reports for prompt injection, model substitution signals, tool-call rewriting, error leakage, stream integrity, and profile-gated Web3 risks.
SeaOf0/dsh-redteam-model★ 666
Authorized-security DSH collection: nine work modes (redteam coordinator, pentest, code audit, binary analysis, attack-defense, AV evasion, incident response, cloud security, CTF solving) and fifteen runtime plugins, managed from a settings page with one-click deploy, install, update and uninstall.
howmp/dsh-pentest★ 595
Authorized pentest mode for DeepSeek Harness — exploration chain, assets and findings with a Web view.
PerryLink/dsh-auto-review★ 233
Second-model auto-review on the approval answerer chain: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default.
NanmiCoder/dsh-auto-mode★ 164
Adds an Auto permission preset between Workspace Write and Full access: routine work stays in the official workspace-write sandbox while the current session model reviews escalation and destructive calls, granting one exact wider access once, asking when the intent is ambiguous, and denying critical paths.
PerryLink/dsh-permission-rules★ 119
Claude Code-style declarative permission rules: ordered allow/deny/ask YAML rules matching tool names, arguments, workspace paths, and agent identity on the tools/pre-execute waterfall, with full session-log audit, dry-run mode, and hot reload.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.