DeepSeek Harness Plugin Hub

Publish and manage complete Harness Profiles. Discover Plugins for your next setup.

Explore

PluginsPresetsDocsNews

Community

Publish a pluginContactReport an issue

Resources

Plugin Hub on GitHubDeepSeek HarnessSystem statusPrivacy notice
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

Independent and unofficial. Not affiliated with, authorized by, or endorsed by DeepSeek.

Auto Approver — DSH Plugin for DeepSeek Harness
← Plugins
A

dsh-auto-approver

Auto Approver

Configurable auto-approval for DeepSeek Harness: intercepts approval/request and answers allowed-once/rejected by policy (allow-all / allowlist / deny-always), with a full audit log — so the human is only asked when the policy says so.

The plugin will be installed here. Keep web if you are unsure.

npx -y @deepseek-ai/dsh plugin --profile web add github:nicecx/dsh-auto-approver#4f7101fef23a4528dd32c07be7169cec87827d8a
READMECompatibilityVersions

Compatibility and provenance

Auto Approver is published as dsh-auto-approver and currently resolves to version 0.1.0. The Hub verifies its manifest and preserves the exact installation source for reproducible installs.

DSH compatibility
*
Runtime surfaces
any
Release source
github
Registry updated
8/31/2026

Versions

0.1.0stable
8/31/2026

Related plugins

Loading related plugins…

Latest
0.1.0
DSH
*
HMR
Process restart
Tree shaking
Safe tree shaking not declared
Unpacked size
Unavailable
Files
Unavailable
Surface
any
License
MIT
Source
github
GitHub
★ 0
Weekly downloads
0
Last push
8/31/2026
View source ↗
README badge

Click the badge to copy Markdown for your README.

Do you maintain this Plugin?Claim benefit · Priority security scan

Verify the GitHub repository declared in package.json to manage this listing. After you claim it, Hub will prioritize a security scan of the current version and publish the result when it passes.

Claim this Plugin →
Report an issue
DeepSeek Harness Plugin Hub
ProfilesPluginsCategoriesNewsDocsSign inManage Profiles
ProfilesPluginsCategoriesNewsDocsSign in

Related plugins

More verified plugins in security-access.

Doctor@linxin666/dsh-doctorTransactional rescue mode for DSH profiles with a supervised launcher, isolated recovery capsule, deterministic repairs, health monitoring, and a local Web recovery consolePocketdsh-pocketPut DeepSeek Harness in your pocket: one package, one settings page, and scan a QR code on your phone to access DSH on your computer in sync (LAN + public network, real-time screen mirroring).DSCODE@toddzheng024/dscode-bundleA complete DeepSeek coding agent with persistent shell, Ultra collaboration and automatic permission review.Auto Reviewdsh-auto-reviewSecond-model AI auto-review for DeepSeek Harness approval requests: a read-only reviewer subagent decides allow/deny on the approval answerer chain, with fail-closed fallback and full session-log audit.

README

dsh-auto-approver

Configurable auto-approval for DeepSeek Harness. Intercepts approval/request (and optionally ask_user_question) and answers by policy — rule layer, an optional Hermes Pro semantic verdict, or the human. Every decision is audit-logged.

Why

DeepSeek Harness asks for approval before privileged operations (file writes, command execution, danger-full-access, …). In a trusted, autonomous setup — or for a known-safe subset of tools — those prompts are pure noise. This host plugin intercepts every approval request before the relay/UI push and settles it, with a full audit log and an interactive reject loop (the agent is told why it was rejected and can retry).

It is the mirror image of dsh-reset-handoff: that plugin delegates restarts to an external ops agent; this one delegates approvals to a local policy and/or Hermes.

How it works

agent requests permission
   → 'approval/request' event (host emits)
   → dsh-auto-approver (prepend, before relay/UI)
        │
        ├─ denyAlways hit        → 'rejected' (never prompts; Hermes cannot override)
        ├─ mode=allow-all        → 'allowed-once' (never prompts)
        ├─ mode=allowlist        → hit → 'allowed-once'; miss → next() (human asked)
        ├─ mode=hermes           → allowlist hit → 'allowed-once'
        │                          else → Hermes Pro semantic verdict
        │                                  (deepseek-v4-pro, 90s timeout, fail-closed → human)
        └─ mode=off              → next() (all to human, plugin inert)
   → every decision is appended to the audit log
   → 'rejected' also follows up the reason to the requesting session

Registering with { prepend: true, global: true } makes the plugin answer before dsh-relay pushes the prompt to iMessage/Web — an auto-settled request never disturbs the human.

QnA takeover (optional)

With qnaMode: 'hermes', ask_user_question is also answered by Hermes Pro instead of interrupting the human. Hermes sees the question and its options (or free-form) and returns a choice per the relay answer format; if Hermes is unavailable it falls back to the human.

Install

dsh plugin --profile <profile> add github:nicecx/dsh-auto-approver

Configuration

Override in your profile patch (cordis.patch.yml):

- id: dsh-auto-approver
  name: 'dsh-auto-approver'
  config:
    mode: 'hermes'           # allow-all | allowlist | hermes | off (default: allow-all)
    allowlist: []            # tools auto-approved (rule layer; hermes mode: direct pass)
    denyAlways: []           # tools always rejected (highest priority, Hermes cannot override)
    denyReasons: {}          # tool → reject reason text fed back to the agent
    hermesModel: 'deepseek-v4-pro'   # verdict model (Pro = highest capability)
    hermesTimeoutSecs: 90    # verdict timeout; on failure → human (fail-closed)
    feedbackOnReject: true   # followup the reject reason to the requesting session
    qnaMode: 'off'           # 'hermes' = ask_user_question answered by Hermes Pro; 'off' = human
    userGranted: []          # endorsement signal (NOT a bypass card) — see below
    logPath: ''              # audit log path (default ~/.dsh/auto-approver.log)
modebehavior
allow-allauto-approve everything (incl. danger-full-access). Trusted environments only.
allowlistauto-approve only listed tools; everything else asks the human.
hermesrule layer (denyAlways / allowlist) + Hermes Pro semantic verdict for the rest.
offplugin inert; everything goes to the human.

userGranted — endorsement signal, not a bypass card

userGranted is a soft endorsement passed into the Hermes verdict prompt ("the user explicitly authorized this tool — lean toward approval when the operation is reasonable and carries no data-destruction / credential-exfiltration risk"). It is not a hard allow:

  • denyAlways still wins over everything.
  • Hermes still rejects dangerous operations (data destruction, credential exfiltration, irreversible deletes).
  • Keep it empty by default — adding broad tools (bash, write) conflicts with the least-privilege principle. Only list capabilities the user explicitly named.

Interactive reject loop

When the policy (or Hermes) rejects, the plugin follows the reason back into the requesting session, so the agent knows what was wrong and can retry with a corrected request (e.g. narrower permission, concrete path, specific command). Manual approval on iMessage/Web always wins.

Audit log

Every decision is appended (JSON lines) to ~/.dsh/auto-approver.log:

{"ts":"...","sessionId":"...","toolName":"bash","reason":"...","callId":"...","decision":"allowed-once"}

Hermes verdicts also carry the reason in note (e.g. hermes: ...).

Safety notes

  • allow-all auto-grants everything, including full-access commands. Prefer allowlist/hermes in anything less than a fully trusted single-user box.
  • hermes mode is fail-closed: if Hermes is unavailable or times out, the request goes to the human — never silently granted.
  • The relay/Web double-track is untouched: when the policy says ask, the human still decides on iMessage or the Web UI; manual approvals always win.
  • The audit log is the complete record of auto-decisions — keep it.

License

MIT