DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Auto Approver — DeepSeek Harness 插件(DSH Plugin)
← Plugins
A

dsh-auto-approver

Auto Approver

DeepSeek Harness 的可配置自动批准:拦截批准/请求,并根据策略(全部允许/允许列表/始终拒绝)回复“一次性允许”或“拒绝”,同时提供完整的审计日志——仅在策略要求时询问人工。

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add github:nicecx/dsh-auto-approver#4f7101fef23a4528dd32c07be7169cec87827d8a
README兼容性版本

兼容性与来源证明

Auto Approver 以 dsh-auto-approver 发布,当前版本为 0.1.0。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
any
发布来源
github
Registry 更新时间
2026/8/31

版本

0.1.0stable
2026/8/31

相关插件

正在加载相关插件…

最新版
0.1.0
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
未提供
文件数
未提供
Surface
any
许可证
MIT
发布源
github
GitHub
★ 0
周下载
0
最近提交
2026/8/31
查看源码 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录

相关插件

继续浏览 security-access 分类下经过校验的插件。

Doctor@linxin666/dsh-doctorDSH 配置档案的事务性救援模式,配备受监督的启动器、隔离的恢复容器、确定性修复、健康监控以及本地 Web 恢复控制台Pocketdsh-pocket把 DeepSeek Harness 装进你的口袋:一个包、一个设置页,手机扫码即同步访问电脑上的 DSH(局域网 + 公网,实时同屏)。DSCODE@toddzheng024/dscode-bundle完整的 DeepSeek 编码代理,支持持久化 shell、Ultra 协作和自动权限审查。Auto Reviewdsh-auto-review针对 DeepSeek Harness 审批请求的第二模型 AI 自动审查:只读审查子代理在审批应答链上决定允许或拒绝,并采用故障关闭回退机制和完整的会话日志审计。

README

dsh-auto-approver

Configurable auto-approval for DeepSeek Harness. Intercepts approval/request (and optionally ask_user_question) and answers by policy — rule layer, an optional Hermes Pro semantic verdict, or the human. Every decision is audit-logged.

Why

DeepSeek Harness asks for approval before privileged operations (file writes, command execution, danger-full-access, …). In a trusted, autonomous setup — or for a known-safe subset of tools — those prompts are pure noise. This host plugin intercepts every approval request before the relay/UI push and settles it, with a full audit log and an interactive reject loop (the agent is told why it was rejected and can retry).

It is the mirror image of dsh-reset-handoff: that plugin delegates restarts to an external ops agent; this one delegates approvals to a local policy and/or Hermes.

How it works

agent requests permission
   → 'approval/request' event (host emits)
   → dsh-auto-approver (prepend, before relay/UI)
        │
        ├─ denyAlways hit        → 'rejected' (never prompts; Hermes cannot override)
        ├─ mode=allow-all        → 'allowed-once' (never prompts)
        ├─ mode=allowlist        → hit → 'allowed-once'; miss → next() (human asked)
        ├─ mode=hermes           → allowlist hit → 'allowed-once'
        │                          else → Hermes Pro semantic verdict
        │                                  (deepseek-v4-pro, 90s timeout, fail-closed → human)
        └─ mode=off              → next() (all to human, plugin inert)
   → every decision is appended to the audit log
   → 'rejected' also follows up the reason to the requesting session

Registering with { prepend: true, global: true } makes the plugin answer before dsh-relay pushes the prompt to iMessage/Web — an auto-settled request never disturbs the human.

QnA takeover (optional)

With qnaMode: 'hermes', ask_user_question is also answered by Hermes Pro instead of interrupting the human. Hermes sees the question and its options (or free-form) and returns a choice per the relay answer format; if Hermes is unavailable it falls back to the human.

Install

dsh plugin --profile <profile> add github:nicecx/dsh-auto-approver

Configuration

Override in your profile patch (cordis.patch.yml):

- id: dsh-auto-approver
  name: 'dsh-auto-approver'
  config:
    mode: 'hermes'           # allow-all | allowlist | hermes | off (default: allow-all)
    allowlist: []            # tools auto-approved (rule layer; hermes mode: direct pass)
    denyAlways: []           # tools always rejected (highest priority, Hermes cannot override)
    denyReasons: {}          # tool → reject reason text fed back to the agent
    hermesModel: 'deepseek-v4-pro'   # verdict model (Pro = highest capability)
    hermesTimeoutSecs: 90    # verdict timeout; on failure → human (fail-closed)
    feedbackOnReject: true   # followup the reject reason to the requesting session
    qnaMode: 'off'           # 'hermes' = ask_user_question answered by Hermes Pro; 'off' = human
    userGranted: []          # endorsement signal (NOT a bypass card) — see below
    logPath: ''              # audit log path (default ~/.dsh/auto-approver.log)
modebehavior
allow-allauto-approve everything (incl. danger-full-access). Trusted environments only.
allowlistauto-approve only listed tools; everything else asks the human.
hermesrule layer (denyAlways / allowlist) + Hermes Pro semantic verdict for the rest.
offplugin inert; everything goes to the human.

userGranted — endorsement signal, not a bypass card

userGranted is a soft endorsement passed into the Hermes verdict prompt ("the user explicitly authorized this tool — lean toward approval when the operation is reasonable and carries no data-destruction / credential-exfiltration risk"). It is not a hard allow:

  • denyAlways still wins over everything.
  • Hermes still rejects dangerous operations (data destruction, credential exfiltration, irreversible deletes).
  • Keep it empty by default — adding broad tools (bash, write) conflicts with the least-privilege principle. Only list capabilities the user explicitly named.

Interactive reject loop

When the policy (or Hermes) rejects, the plugin follows the reason back into the requesting session, so the agent knows what was wrong and can retry with a corrected request (e.g. narrower permission, concrete path, specific command). Manual approval on iMessage/Web always wins.

Audit log

Every decision is appended (JSON lines) to ~/.dsh/auto-approver.log:

{"ts":"...","sessionId":"...","toolName":"bash","reason":"...","callId":"...","decision":"allowed-once"}

Hermes verdicts also carry the reason in note (e.g. hermes: ...).

Safety notes

  • allow-all auto-grants everything, including full-access commands. Prefer allowlist/hermes in anything less than a fully trusted single-user box.
  • hermes mode is fail-closed: if Hermes is unavailable or times out, the request goes to the human — never silently granted.
  • The relay/Web double-track is untouched: when the policy says ask, the human still decides on iMessage or the Web UI; manual approvals always win.
  • The audit log is the complete record of auto-decisions — keep it.

License

MIT