dsh-approval-first
Approval-first file edit and write shadow tools for DeepSeek Harness sandboxes.
Install
$ pnpm dsh plugin --profile web add /path/to/dsh-approval-firstPlugin Overview & Capabilities
AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.
Key Capabilities
- Presents approval diff cards on the first out-of-policy edit or write tool call
- Preserves silent execution for in-policy workspace and /tmp writes
- Applies directory-scoped permission grants upon user approval rather than full access
- Adapts dynamically to standing sandbox modes across session changes
- Enforces a boot-time drift tripwire that prevents activation if upstream tool definitions change
Useful For
- Reviewing model-generated code diffs directly without waiting for permission escalation retries
- Confining DeepSeek Harness agent file write permissions outside active workspaces
- Streamlining single-turn interactive file modifications in locked-down environments
Who It Fits
- DeepSeek Harness developers working with sandboxed execution environments
- Security-focused engineers reviewing automated file modifications
- Agent workflow developers seeking faster interactive permission approvals
Documented Limitations
- Only shadows edit and write tools, leaving bash escalation paths unchanged
- Interim shim design intended to be deprecated once native single-turn escalation lands in DeepSeek Harness
- Skips agents if another plugin already shadows edit or write tools
DSH Compatibility
Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.
Security Signals
Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.
package.json declares 0 runtime, 0 development, 0 peer, and 0 optional dependencies.
package.json declares DSH bundle metadata.
GitHub reports the repository license as MIT.
A root package.json was captured and can be inspected by the registry.
Public GitHub source metadata is available for this registry snapshot.
Source & Registry Notes
Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.
- Source repository
- joao-paulo-santos/dsh-approval-first
- Registry source
- GitHub · dsh-plugin topic
- Registry classification
- Plugin
- Source checked
- 3297a1c · 2026-08-31
This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.
Repository Activity
- GitHub stars
- 0GitHub stars
- Forks
- 0
- Open issues
- 0
- Last commit
- 2026-08-31
- Last release
- No release detected
Related DSH Plugins
Ranked by overlapping capabilities, use cases, plugin type, categories, and DSH profile.
Sandbox-first automatic permission policy and intelligent risk classification for DeepSeek Harness.
View plugin →Second-model AI auto-review for DeepSeek Harness approval requests with fail-closed safety and session audit.
View plugin →Import and resume chat histories from 18+ AI coding agents into DeepSeek Harness with reverse export and sync.
View plugin →Local-first AI agent runtime and DSH plugin bundle providing sandboxed sessions, MCP tools, audit logs, and session replay.
View plugin →