dsh-auto-approve
Adds an `auto` permission preset between workspace-write and danger-full-access: a classifier grants routine sandbox escalations once, while dangerous or uncertain requests still go to a human.
在 workspace-write 与 danger-full-access 之间增加 `auto` 权限档:分类器一次性放行例行沙箱升级,危险或不确定的操作仍转人工审批。
How to install
dsh plugin add dsh-auto-approve About
中文 | English dsh-auto-approve 为 DeepSeek Harness 增加 Auto 权限档。在该档位下,分类模型可以对例行的沙箱升级做一次性批准;命中确定性危险规则、模型拿不准、超时、响应格式错误或插件内部异常时,审批仍会交给正常的人工弹窗。 该 bundle 会把权限预设表重述为四个档位,顺序为 read-only、workspace-write、auto、danger-full-access——即在 dsh 原生三档中间插入 auto 档,原有档位全部保留。不在 auto 档时,插件会原样放行所有审批请求给后续应答者。 定位 auto 是 workspace-write 之上的低打扰安全层:保留同一沙箱边界,把例行升级交给分类器;命中危险清单、分类器拿不准或分类失败时,才回到人工审批。 直观地说,它类似 Claude Code 的 **auto mode** 与 Codex 的 **Auto-review mode**:把例行审批交给安全评审,危险或拿不准时再交还人工。 | 权限档 | 沙箱范围 | 什么时候弹窗 | 适合场景 | | --- | --- | --- | --- | | read-only | 只读工作区,不能修改项目文件 | 需要写入、联网或执行其他越界操作时 | 代码审阅、探索和敏感仓库 | | workspace-write …
Recommendation signals
Meta
- License
- MIT
- Language
- JavaScript
- GitHub stars
- 15
- mo. downloads
- 1.8K
- Last push
- 2026-09-07
- Created
- 2026-08-14
Basic safety check
- Findings
- None
- Sources
- curated:awesome-dsh-plugin.com, curated:awesome-dsh-plugin/awesome-dsh-plugin
- Topics
- dsh-plugin
Related plugins
dsh-auto-mode
NanmiCoder/dsh-auto-mode
Adds an Auto permission preset between Workspace Write and Full access: routine work stays in the official workspace-write sandbox while the current session model reviews escalation and destructive calls, granting one exact wider access once, asking when the intent is ambiguous, and denying critical paths.
dsh-passwords
slywalker2006/dsh-passwords
Turns DeepSeek Harness into a server-grade multi-tenant platform: remote access + auto HTTPS, subuser permissions & token/daily quotas, sandbox enforcement, encrypted auth & audit log.
sofagent
KongFangXun/sofagent/tree/main/engine/dsh-plugins/cordis-plugin-sofagent-audit
Commit-time audit harness for AI coding agents: 24 git-diff rules (secrets, out-of-scope edits, prompt injection), HMAC-signed audit trail, snapshot rollback, and an MCP server with 84 tools. Installable via dsh plugin add.
dsh-vault
Ox0400/dsh-vault
Encrypted local credentials vault for the Harness: a web settings page and vault_* tools to store, search and copy passwords, API keys, TOTP secrets and card data, with health audits, expiry rotation, imports/exports and read-only/ask access modes.