dsh-auto-approve
其他 活跃维护

dsh-auto-approve

Hanihahaha/dsh-auto-approve

作为权限管理类插件,可自动批准符合沙箱规则判断的权限申请请求,基于启发式沙箱原因匹配逻辑运行,无需人工逐条审核,简化权限审批流程,降低日常操作成本。

0
Stars 标星
0
Forks 分支
0
Watchers 关注
0
Open Issues
JavaScript
主要语言
None
开源协议
8 KB
仓库大小
1 个月前
最后推送
一键安装扩展 / 插件指令
dsh plugin --profile web add github:Hanihahaha/dsh-auto-approve
git clone https://github.com/Hanihahaha/dsh-auto-approve.git
git clone git@github.com:Hanihahaha/dsh-auto-approve.git
README.md main

dsh-auto-approve

中文

A DeepSeek Harness plugin that adds an auto-approve permission mode and can automatically grant requests matching its sandbox-reason heuristic or all approval requests.

Features

  • Adds an Auto approve permission preset that preserves the workspace-write boundary.
  • Provides /auto-approve all|sandbox|off|status.
  • Adds a session-header control that cycles between off, sandbox-matched, and all approvals.
  • Intercepts the approval/request waterfall and returns allowed-once for the selected mode.

Install

# Install from the repository root.
dsh plugin --profile web add ".\dsh-auto-approve"

# Or, after publishing
dsh plugin --profile web add dsh-auto-approve

Restart dsh web after installation. The permission selector then exposes the Auto approve preset and the command and header control become available.

How It Works

Layer Behavior
Permission preset Extends @deepseek-ai/dsh-permission-presets with auto-approve using workspace-write plus ask.
Approval handling Intercepts approval/request; the preset grants all requests, while manual sandbox mode grants requests whose reason text contains sandbox, all grants every request, and off grants none.

DSH has ask and never policies but no native auto-approve policy. This plugin implements auto-approval by short-circuiting the waterfall. never means reject, not auto-approve.

Security

  • all grants every approval request and is only suitable for trusted tasks.
  • Manual mode is process-local and returns to the default sandbox mode after restart.
  • The Auto approve preset remains constrained to workspace-write; requests outside the workspace still use escalation, although this plugin grants the resulting approval.