dsh-auto-approval-plugin
Adds an auto-approval middle permission tier for DeepSeek Harness to automate safe commands and trusted-area operations.
Install
$ dsh plugin --profile <profile> add dsh-auto-approval-pluginPlugin Overview & Capabilities
AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.
Key Capabilities
- Adds an auto-approval preset to DeepSeek Harness general permission settings and the /permission picker
- Intercepts approval requests to auto-approve harmless introspection commands lacking shell metacharacters
- Auto-approves read/write filesystem and simple command operations inside configured trusted directory areas
- Evaluates canonical filesystem paths using realpath resolution to prevent symlink traversal
- Defers dangerous system commands, privilege escalations, and metacharacter chains to human confirmation without denying
- Provides a live web UI settings card for modifying rules, trusted areas, and viewing recent decisions
Useful For
- Reducing repetitive approval prompts for routine directory writes and read-only inspection commands across developer workflows
- Allowing DSH sessions safe write access to dedicated project repositories or data directories outside the primary workspace
- Automating multi-step read-only repository status queries and git inspections without enabling full dangerous system access
Who It Fits
- DeepSeek Harness developers seeking reduced manual friction during agent coding tasks
- Engineers managing automated agent workflows with specific external trusted project directories
- Security-conscious users who want structured policy-based permission escalation instead of granting full machine access
Documented Limitations
- Commands with shell metacharacters like pipes, redirects, chaining, or substitutions are never auto-approved
- Dangerous system patterns such as privilege escalation, ACL changes, and registry modifications always defer to the user
- Trusted area auto-approvals remain disabled until absolute paths are explicitly configured in settings
DSH Compatibility
Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.
Security Signals
Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.
package.json declares 0 runtime, 3 development, 3 peer, and 0 optional dependencies.
package.json declares DSH bundle metadata.
GitHub reports the repository license as MIT.
A root package.json was captured and can be inspected by the registry.
Public GitHub source metadata is available for this registry snapshot.
Source & Registry Notes
Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.
- Source repository
- StyxNether/dsh-auto-approval-plugin
- Registry source
- GitHub · dsh-plugin topic
- Registry classification
- Plugin
- Source checked
- 2702b6b · 2026-09-25
This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.
Repository Activity
- GitHub stars
- 3GitHub stars
- Forks
- 2
- Open issues
- 0
- Last commit
- 2026-09-06
- Last release
- No release detected
Related DSH Plugins
Ranked by overlapping capabilities, use cases, plugin type, categories, and DSH profile.
Sandbox-first automatic permission policy and intelligent risk classification for DeepSeek Harness.
View plugin →Second-model AI auto-review for DeepSeek Harness approval requests with fail-closed safety and session audit.
View plugin →Native SQLite-backed local project taskboard plugin and UI for DeepSeek Harness with Agent claim and review flows.
View plugin →Agent skill for generating interactive, verifiable architecture and workflow diagrams as self-contained HTML.
View plugin →