Fourth permission preset for dsh: unconfined, GPU-capable sessions (danger-full-access) with per-operation user approval for writes outside the workspace or to protected paths (.git/**, .env*); implemented purely as a bundle over the official tools/pre-execute ask hook, no core edits.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:zjuhbh/dsh-full-with-approval
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
[!WARNING] ⚠️ This project is no longer maintained (停止维护). No further updates, bug fixes, or security patches will be provided. Issues and pull requests are not monitored. The code is provided as-is under the MIT License; feel free to fork it if you want to continue development. Use at your own risk.
本项目已停止维护。 不再提供任何更新、修复或安全补丁,Issue / PR 不再受理。 代码按 MIT License 原样提供,如需继续开发请自行 fork,使用风险自负。
A DeepSeek Harness (DSH) profile plugin that adds a fourth permission preset, full-with-approval:
Full compute access — the session sandbox mode is
danger-full-access, so processes run unconfined: CUDA/GPU, devices, network and any binary your machine can run.Approval-gated file edits — while this preset is active, every
write/editthat would modify- a file outside the session workspace (except the platform temp areas and configured scratch roots), or
- a protected file inside the workspace (default:
.git/**,.env*),
asks the user for one-shot approval before anything executes. Approval is resolved through the same interactive prompt the sandbox escalation retries use (
ctx.approval,allowed-once). Rejected or cancelled ⇒ the tool fails and nothing is written. If no approval channel is available, the call fails closed.Approval-gated shell modifications — a
bash/pwshcommand that shows evidence of modifying files outside the workspace (out-of-workspace path tokens plus a write marker: redirection,chmod,rm,python,curl -o, …) also asks first; visibly read-only invocations (cat,ls,grep,env, … without a write marker) and workspace-relative commands pass without prompting. The static heuristic errs on the side of asking: interpreters (python,node) and command substitutions that mention outside paths always ask.bashGuard: falsedisables this layer;extraBashTokensadds forced-ask substrings.
Everything else — writes inside the workspace to ordinary files, temp/scratch files, all reads and every command — proceeds untouched.
How it works
The plugin is a thin load-bearing layer over existing DSH extension points; no core package is modified.
cordis.patch.ymlpatch entryfull-with-approvalmounts the host plugin.- The same patch overrides the
permissionpreset table (by id) to add the 4th presetfull-with-approval = { sandbox: danger-full-access, approval: ask }. The GUI permission selector and/permissioncommand read this table, so the new row appears automatically. - The plugin listens on the tools registry's
tools/pre-executewaterfall (the official allow / deny / ask before dispatch hook). When the session's effective preset isfull-with-approvaland the call is awrite/editwhose target is outside the workspace or protected, it returns{ kind: "ask", reason }. The registry resolves the ask throughctx.approval.request(...)and only dispatches onallowed-once.
Install
# from the parent directory of a git checkout (pnpm `file:` install: copies the
# package and installs its declared dependencies)
dsh plugin --profile web add ./dsh-full-with-approval
# or from a local folder by absolute path (the `link:` form does not manage the
# plugin's own dependencies; keep `npm install` in the checkout)
dsh plugin --profile web add /path/to/dsh-full-with-approval
# once published as an npm package
dsh plugin --profile web add dsh-full-with-approval
dsh plugin add runs pnpm and reconciles the profile's bundle list: a package declaring dsh.bundle joins the layer stack automatically. The change applies on the next boot of the dsh profile (restart the app / refresh after HMR).
If pnpm aborts with
ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION(a supply-chain policy on the profile's lockfile, unrelated to this plugin), relax it for the install:dsh plugin --profile web add ./dsh-full-with-approval --config.minimum-release-age=0
Usage
- In the web UI open the permission selector and pick Full With Approval (4th option), or run:
/permission full-with-approval - While the preset is active, protected writes raise the approval prompt; approve to let that one write through.
- Switch back to
workspace-write/danger-full-access/read-onlyat any time; the gate follows the preset.
Configuration
The plugin entry config (patch cordis.patch.yml in the profile or override via cordis.patch.yml of your profile):
- id: full-with-approval
config:
# Globs matched against the POSIX path relative to the session workspace.
# An absolute pattern matches the absolute target path.
protectedPaths:
- ".git/**"
- ".env*"
- ".env/**"
# Absolute scratch roots that never prompt (besides the platform temp dir).
extraWritableRoots: []
# Shell guard layer (default true): ask for bash/pwsh commands that show
# evidence of modifying files outside the workspace.
bashGuard: true
# Extra substrings that force an ask when a shell command mentions them.
extraBashTokens: []
Changing protectedPaths takes effect on reload/restart.
What is intentionally NOT gated
- Reads are always allowed (every sandbox mode permits reading), including reads of outside files by obviously read-only commands (
cat,ls,grep,env, … without a write marker). - Temp areas (
/tmp,os.tmpdir()) andextraWritableRootsnever prompt. - Shell writes are gated by heuristic, not by kernel — a command can still evade the static check (paths built dynamically,
cdfollowed by relative writes, opaque interpreters hiding file access). The heuristic errs toward asking; treat it as a prompt-on-suspicion layer, not a security boundary. The kernel-level boundary remainsworkspace-writemode at the cost of GPU access.
Known caveats
- Selector icon — the core Web UI draws permission icons from a value-keyed table inside the
@deepseek-ai/dsh-client-ui-conversationclient bundle; plugin-added presets get none (the flat client module graph cannot override that table from a plugin bundle). Until supported upstream, draw the 4th row's shield-check glyph with one command (idempotent, backs up the bundle file, live-served — refresh the page after re-running on each dsh upgrade):node tools/patch-ui-glyph.mjs - The 4th option does not show the extra risk-confirmation gate the stock
danger-full-accessrow shows (that gate is keyed on the preset value in the core UI client); the row's own one-shot approvals still guard every protected write. run_code/code-mode executions are not inspected for file effects; nativewrite/editcalls andbash/pwshcommands are gated.- Path classification is canonicalize-then-compare against the session workspace; on filesystems with odd symlink aliasing (Windows 8.3, case-insensitive paths) treat the workspace boundary as advisory — the sandbox fence itself is the kernel-level authority where modes confine.
Development
npm ci # picomatch + harness deps
node --test # classifier unit tests
DSH_AI_NODE_MODULES=/path/to/node_modules/@deepseek-ai \
node test/pre-execute.harness.mjs # full ask→approval→dispatch chain
See also examples/cordis.patch.yml for the explicit knob values, and
SECURITY.md / CONTRIBUTING.md for the trust model and change rules.
Release
npm pack # build the tarball
License
MIT
Links
More in this category
toby-bridges/api-relay-audit★ 872
Runs local security audits of AI API relays and LLM proxies from DeepSeek Harness, producing Markdown reports for prompt injection, model substitution signals, tool-call rewriting, error leakage, stream integrity, and profile-gated Web3 risks.
SeaOf0/dsh-redteam-model★ 671
Authorized-security DSH collection: nine work modes (redteam coordinator, pentest, code audit, binary analysis, attack-defense, AV evasion, incident response, cloud security, CTF solving) and fifteen runtime plugins, managed from a settings page with one-click deploy, install, update and uninstall.
howmp/dsh-pentest★ 603
Authorized pentest mode for DeepSeek Harness — exploration chain, assets and findings with a Web view.
PerryLink/dsh-auto-review★ 234
Second-model auto-review on the approval answerer chain: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default.
NanmiCoder/dsh-auto-mode★ 164
Adds an Auto permission preset between Workspace Write and Full access: routine work stays in the official workspace-write sandbox while the current session model reviews escalation and destructive calls, granting one exact wider access once, asking when the intent is ambiguous, and denying critical paths.
PerryLink/dsh-permission-rules★ 120
Claude Code-style declarative permission rules: ordered allow/deny/ask YAML rules matching tool names, arguments, workspace paths, and agent identity on the tools/pre-execute waterfall, with full session-log audit, dry-run mode, and hot reload.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.