DeepSeek Harness Plugin Hub

Publish and manage complete Harness Profiles. Discover Plugins for your next setup.

Explore

PluginsPresetsDocsNews

Community

Publish a pluginContactReport an issue

Resources

Plugin Hub on GitHubDeepSeek HarnessSystem statusPrivacy notice
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

Independent and unofficial. Not affiliated with, authorized by, or endorsed by DeepSeek.

Perm Guard — DSH Plugin for DeepSeek Harness
DeepSeek Harness Plugin Hub
ProfilesPluginsCategoriesNewsDocsSign inManage Profiles
ProfilesPluginsCategoriesNewsDocsSign in
← Plugins
P

dsh-perm-guard

Perm Guard

Auto automatic approval plugin: DSH medium-tier permissions—automatically allow actions within trusted directories, manually confirm dangerous operations (adjustable category toggles)

The plugin will be installed here. Keep web if you are unsure.

npx -y @deepseek-ai/dsh plugin --profile web add github:a903067276-rgb/dsh-perm-guard#a738506ce2b41f912b634dd8258d134bc8387fc8
READMECompatibilityVersions
Auto button in the composer tool rowAuto Permissions settings page

Compatibility and provenance

Perm Guard is published as dsh-perm-guard and currently resolves to version 0.2.10. The Hub verifies its manifest and preserves the exact installation source for reproducible installs.

DSH compatibility
*
Runtime surfaces
web
Release source
github
Registry updated
9/10/2026

Versions

0.2.10stable
9/10/2026
0.2.8stable
8/22/2026
0.2.7stable
8/21/2026
Show 1 more versionCollapse versions
0.2.5stable
8/20/2026

Related plugins

Loading related plugins…

Latest
0.2.10
DSH
*
HMR
Process restart
Tree shaking
Safe tree shaking not declared
Unpacked size
Unavailable
Files
Unavailable
Surface
web
License
MIT
Source
github
GitHub
★ 2
Weekly downloads
0
Last push
9/15/2026
View source ↗
README badge

Click the badge to copy Markdown for your README.

Do you maintain this Plugin?Claim benefit · Priority security scan

Verify the GitHub repository declared in package.json to manage this listing. After you claim it, Hub will prioritize a security scan of the current version and publish the result when it passes.

Claim this Plugin →
Report an issue

Related plugins

More verified plugins in security-access.

Pocketdsh-pocketPut DeepSeek Harness in your pocket: one package, one settings page, and scan a QR code on your phone to access DSH on your computer in sync (LAN + public network, real-time screen mirroring).DSCODE@toddzheng024/dscode-bundleA complete DeepSeek coding agent with persistent shell, Ultra collaboration and automatic permission review.Auto Reviewdsh-auto-reviewSecond-model AI auto-review for DeepSeek Harness approval requests: a read-only reviewer subagent decides allow/deny on the approval answerer chain, with fail-closed fallback and full session-log audit.Codex Subscriptiondsh-codex-subscriptionUse ChatGPT and Codex subscriptions in DeepSeek Harness with OAuth, quota, safe resets, web search, images, and Fast mode

README

dsh-perm-guard 🛡️

English | 简体中文

Auto-approval permission guard for DeepSeek Harness (dsh) web — the "middle tier" between workspace-write (asks too often) and danger-full-access (too open). Common operations like cross-directory edits, git commit/merge and builds run without approval prompts; destructive operations (deletes, disk ops, privilege escalation, curl|sh) always ask for human confirmation.

Unofficial project: independently developed and maintained by a community member, not an official DeepSeek product.

Screenshot

Auto button in the composer tool row

Auto Permissions settings page

Features

  • Two modes (switchable in the settings page, persisted):
    • Standard — auto-approve inside the trust directories (workspace, sibling directories, custom list); outside + risky operations prompt.
    • Aggressive — location-unrestricted: only destructive operations still prompt.
  • 11 per-category tri-state switches (auto / ask / deny) with your personal defaults.
  • Audit trail — every decision is recorded (approved / forwarded to human / rejected) with timestamp and command summary.
  • Persistent config — ~/.dsh/perm-guard.json, survives restarts. Zero host dependencies.

Install

dsh plugin --profile web add "github:a903067276-rgb/dsh-perm-guard#main"

Then restart dsh web. Update: dsh plugin --profile web update dsh-perm-guard, restart.

Manual install fallback: see docs/install.md.

Usage

  • Auto button — in the composer tool row (left of the input box). Click to toggle auto-approval on/off (green = on). Off restores the host's default approval behavior completely.
  • Settings → "Auto 权限" (Auto Permissions) — total switch, mode selection (Standard / Aggressive), 11 category switches, trust directory editor, and the recent-decision audit list.
  • Rules apply to all sessions (including subagents) while enabled.

Mode defaults

CategoryStandardAggressive
File edit (write/edit/cp/mv/mkdir)auto (in trust dirs)auto
Git local (commit/merge/rebase/checkout)autoauto
Build / test / installautoauto
Read-only queries (ls/cat/grep/git status)autoauto
Delete (rm, reset --hard, clean -fd)askask
Protected paths (.ssh/.aws/secrets/.env/system dirs)askask
Privilege (sudo, services, global installs)askask
Network download-execute (curl|sh)askask
Git pushaskauto
Publish / deployaskauto
Disk / partition / deviceaskask

Switching modes resets the category switches to that mode's defaults (adjustable afterwards).

Never auto-approved (all modes)

  • Deletion: rm, rm -rf / or ~ (circuit breaker, even with $(...) variants), git reset --hard, git clean -fd, Remove-Item
  • Disk: dd writing devices, mkfs/fdisk/wipefs/diskutil erase, writes to /dev/
  • Privilege: sudo/su, service management (launchctl/systemctl), recursive chmod/chown on / or ~
  • Network download-execute: curl|sh, wget|sh
  • Force push: git push --force / -f (rewrites history)
  • Writes to protected paths

Platform support

PlatformStatus
macOS✅ development environment
Linux⚠️ expected to work
Windows✅ adapted & field-tested (win32 path handling + PowerShell vocabulary, 2026-08-24)

Windows notes

  • Trusted dirs accept three absolute-path styles — C:\…, C:/…, /c/… (MSYS/Git-Bash) — normalized to C:/… on save; invalid entries are reported back by the UI instead of being silently dropped.
  • Classifier covers common PowerShell cmdlets: pipeline/formatting (Select-Object etc.) count as read-only; Invoke-RestMethod/iwr map to network; Stop-Process, reg add, schtasks /create etc. map to privilege (always human-confirmed); vssadmin delete shadows, bcdedit, diskpart are hard red lines.
  • gh CLI read-only subcommands (view/list/status…) auto-approve; write operations fall back to human confirmation.
  • Escalated retries (sandbox_permissions) raise exactly one confirmation card instead of two.

Requirements

  • DSH web >= 0.1.0-rc.6 (the approval system this plugin guards)
  • Version compatibility (best effort — the settings card uses dual-field key+id registration to satisfy both rc.6 (id) and rc.7+ (key); verified locally on rc.6/rc.8/0.1.1-rc.2/0.1.5-rc.1, not guaranteed on every DSH version):
    • DSH 0.1.0-rc.6 and newer (incl. the 0.1.1 / 0.1.2 / 0.1.5 lines): try main (default) or v0.2.9 and newer.
    • Conservative fallbacks (the last pre-0.1.1 build): DSH 0.1.0-rc.7/rc.8 → v0.2.7 (dsh plugin add github:a903067276-rgb/dsh-perm-guard#v0.2.7); DSH 0.1.0-rc.6 → frozen rc6-compat tag (no maintenance).
    • ⚠️ On DSH 0.1.5+ do not install v0.2.8: it imports the removed settingsNamespace export and makes the whole plugin tree fail to load (the web app will not boot). Use main / v0.2.9+ instead.
  • pnpm in PATH — dsh plugin is a pnpm forwarder (needed for install/update)
  • Maintenance policy: this plugin keeps evolving with the latest DSH releases; compatibility with older DSH versions is best-effort only and not guaranteed going forward.

How it works

  • Interception before the host prompt — every approval request is intercepted before the host prompt; the actual command/target is classified, and safe operations are auto-answered allowed-once (~13ms, no popup), risky ones are forwarded to the human prompt.
  • Call lookup — an approval request carries no tool arguments, so the plugin resolves the real arguments from the session log by callId; DSH 0.1.5 removed Session.events, so it now reads the public snapshotEvents() (older hosts keep the events path). When neither is available it always falls back to the human prompt (safe default, never auto-allow).
  • Command-level firewall (tools/pre-execute) — dangerous categories are intercepted before the sandbox even rejects them.
  • Classification pipeline — the two modes set per-category defaults (Standard: trust directories; Aggressive: location-unrestricted), and the 11 tri-state switches (auto / ask / deny) fine-tune each category.
  • Audit + persistence — every decision is recorded with timestamp and command summary; approval decisions are always persisted via the host's approval/asked + approval/decided event pair.

Notes

  • DSH's sandbox has no OS-level network fence (unlike Codex): the plugin can only detect download-execute patterns (curl|sh) in command text, not block other network traffic.
  • Terminal sessions, subagent creation, model calls and MCP tools are outside the approval system entirely.
  • Commands whose text contains danger words (e.g. echoing "Remove-Item", or scripts embedding rule sources) are conservatively intercepted — expected, rare in practice.
  • The audit list is in-memory (60 entries) and resets on restart; approval decisions themselves are always persisted via the host's approval/asked + approval/decided event pair.

Coverage

  • All approval entry points in DSH are covered: bash, pwsh (PowerShell), and the write/edit file tools. MCP tools and other read-only tools have no approval mechanism and are unaffected.
  • Compound commands (a && rm -rf x): pure-word chains are split and evaluated per subcommand, taking the strictest result; chains containing variables/redirection/wildcards are treated conservatively as one unit.
  • Unknown commands always fall back to "ask" regardless of mode (safe default) — the classifier never auto-allows what it cannot parse.

How it compares to Claude Code / Codex

Claude CodeCodexdsh-perm-guard
Read-only command setbuilt-in, not configurablesandboxbuilt-in + configurable
rm -rf / ~ breakeralways promptssandbox blocksalways prompts (all modes)
Protected pathsyes.git/.agents/.codex.ssh/.aws/secrets/system dirs/.git
Network isolationtool-levelOS-level (default off)not available (DSH has no OS network fence; only curl|sh pattern detection)
Approval categories3 tool classes5 granular switches11 explicit switches + 2 modes
Auditingprompts onlylogsin-plugin audit + host approval/asked/decided events

Configuration file

~/.dsh/perm-guard.json (created on first change):

{
  "enabled": true,
  "mode": "standard",
  "categories": { "fileEdit": "auto", "...": "..." },
  "trustedDirs": []
}
  • trustedDirs: extra absolute paths auto-approved in Standard mode (default: workspace + its sibling directories).
  • Trust directories are ignored in Aggressive mode (location-unrestricted).

Development

# hot-plug testing (no restart)
# 1. define a dynamic Cordis plugin with the same decision logic
# 2. cordis_run → verify → cordis_stop

# static bundle (this repo layout)
# symlink to ~/.dsh/profiles/web/node_modules/dsh-perm-guard
# add "dsh-perm-guard" to ~/.dsh/profiles/web/package.json dsh.profile.bundles
# restart dsh web

Verification matrix: docs/verify-checklist.md

License

MIT