dsh-approve-prefix
Automates DeepSeek Harness sandbox escalation approvals for single-command prefixes while routing complex commands to manual review.
Install
$ dsh plugin --profile web add azazo1/dsh-approve-prefixPlugin Overview & Capabilities
AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.
Key Capabilities
- Deterministic AST parsing for bash and PowerShell commands to guarantee single simple command structure
- Configurable prefix matching across static config, persistent settings, and per-session temporary GUI tabs
- Session-scoped night mode to auto-reject unapproved escalations and interactive tools instead of hanging on confirmation prompts
- Zero learning from approvals to prevent single manual approvals from expanding automatic privileges
- Injects system prompt instructions explaining active approved prefixes and escalation rules to the agent
Useful For
- Allowing routine read-only CLI commands (e.g., gh api, git status) to escalate sandbox privileges automatically without popup prompts
- Running unattended tasks overnight or during absence by turning on night mode
- Enforcing strict security posture where any piped or chained shell execution requires explicit human authorization
Who It Fits
- DeepSeek Harness users running terminal-heavy autonomous agents
- Developers seeking tighter control over automated shell privilege escalation
- Users running long unattended automation sessions in DSH
Documented Limitations
- pwsh command parsing requires a local pwsh executable available on the host system
- Only evaluates command syntax and prefix match, not the runtime side effects of the executed binary
- Pending command queue has a capacity limit (default 128) which may evict stale entries in very long workflows
- GUI session tab configuration is not available in headless or TUI environments (though /night command is supported)
DSH Compatibility
Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.
Security Signals
Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.
package.json declares 2 runtime, 3 development, 1 peer, and 0 optional dependencies.
package.json declares DSH bundle metadata.
GitHub reports the repository license as MIT.
A root package.json was captured and can be inspected by the registry.
Public GitHub source metadata is available for this registry snapshot.
Source & Registry Notes
Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.
- Source repository
- azazo1/dsh-approve-prefix
- Registry source
- GitHub · dsh-plugin topic
- Registry classification
- Plugin
- Source checked
- a10122a · 2026-09-27
This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.
Repository Activity
- GitHub stars
- 1GitHub stars
- Forks
- 0
- Open issues
- 0
- Last commit
- 2026-09-27
- Last release
- No release detected
Related DSH Plugins
Ranked by overlapping capabilities, use cases, plugin type, categories, and DSH profile.
Sandbox-first automatic permission policy and intelligent risk classification for DeepSeek Harness.
View plugin →Second-model AI auto-review for DeepSeek Harness approval requests with fail-closed safety and session audit.
View plugin →Persistent multi-model Agent teams and bounded DAG workflows with GUI controls for DeepSeek Harness.
View plugin →Native SQLite-backed local project taskboard plugin and UI for DeepSeek Harness with Agent claim and review flows.
View plugin →