DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Automode — DeepSeek Harness 插件(DSH Plugin)
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录
← Plugins
A

dsh-automode

Automode

DeepSeek Harness 的 CC 风格自动模式:确定性的拒绝/允许规则 + 执行前门控 + 与模型无关的两阶段分类器。采用 TypeScript 重写,合并 dsh-auto-mode v0.4.1 与 Nuo-cl/dsh-auto-mode 原生集成。

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add github:log-li/dsh-automode#ab4961b4379a75e605188fac132bab90859e5ad5
README兼容性版本

兼容性与来源证明

Automode 以 dsh-automode 发布,当前版本为 0.5.0。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
any
发布来源
github
Registry 更新时间
2026/8/22

版本

0.5.0stable
2026/8/22

相关插件

正在加载相关插件…

最新版
0.5.0
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
未提供
文件数
未提供
Surface
any
许可证
MIT
发布源
github
GitHub
★ 4
周下载
0
最近提交
2026/9/16
查看源码 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题

相关插件

继续浏览 security-access 分类下经过校验的插件。

Doctor@linxin666/dsh-doctorDSH 配置档案的事务性救援模式,配备受监督的启动器、隔离的恢复容器、确定性修复、健康监控以及本地 Web 恢复控制台Pocketdsh-pocket把 DeepSeek Harness 装进你的口袋:一个包、一个设置页,手机扫码即同步访问电脑上的 DSH(局域网 + 公网,实时同屏)。DSCODE@toddzheng024/dscode-bundle完整的 DeepSeek 编码代理,支持持久化 shell、Ultra 协作和自动权限审查。Auto Reviewdsh-auto-review针对 DeepSeek Harness 审批请求的第二模型 AI 自动审查:只读审查子代理在审批应答链上决定允许或拒绝,并采用故障关闭回退机制和完整的会话日志审计。

README

dsh-automode

CC-style auto-approval for DeepSeek Harness. Deterministic deny/allow rules handle the obvious cases; a model-agnostic two-stage classifier decides everything else — with circuit breaker, fail-closed semantics, persistent JSONL logging, and native permission preset integration.

Install

dsh plugin add dsh-automode

How it works

Tool call arrives
  │
  ├─ [pre-execute gate]  (all tools; deny reason reaches the model verbatim)
  │    ① Read-only tools → allow (unless deny matched)
  │    ② Deny rules (regex) → hard reject
  │    ③ Allow rules (prefix glob) → approve
  │    ④ allowInsideWorkingDirectory → in-tree file ops approve
  │    ⑤ Escalation intent → classifier pre-screen
  │    ⑥ Everything else → pass through
  │
  └─ [approval waterfall]
       ① Soft deny rules (prose) → reject
       ② Soft allow rules (prose) → approve
       ③ Read-only allowlist → approve
       ④ Verdict cache hit → reuse
       ⑤ Classifier (two-stage: one-token filter → structured review)
       ⑥ Failure → failClosed

Rules

Two-layer rule system:

Hard boundary (deterministic, never goes to classifier):

  • deny — regex patterns that hard-reject (exfiltration, secrets, sensitive targets)
  • allow — prefix-glob patterns that zero-LLM approve (routine commands, curated paths)

Classifier guidance (prose, fed to the LLM):

  • rules.deny — soft-deny descriptions (force push, curl|bash, production deploys)
  • rules.allow — soft-allow exceptions (local dev, dependency install, standard git)
  • rules.environment — context facts (trusted repos, infrastructure)

All rule arrays support $defaults: ["$defaults", "my custom rule"] keeps the built-in rules while adding yours.

Configuration

# In cordis.patch.yml
- id: auto-mode
  name: dsh-automode
  config:
    deny: [...]                    # Regex hard-reject patterns
    allow: [...]                   # Prefix-glob allow patterns
    readOnlyTools: [read, glob, grep, list, search]
    allowPaths: ['~/Documents/']   # Curated full-trust directories
    allowInsideWorkingDirectory: true
    failClosed: true
    preExecuteGate: true
    timeoutMs: 45000
    breakerConsecutive: 3
    breakerTotal: 20
    classifier:
      provider: ''                 # Empty = follow session model
      model: ''
      maxTokens: 2048
      askFallback: false           # true = three-state (allow/ask/reject)
    rules:
      deny: ['$defaults']
      allow: ['$defaults']
      environment: ['$defaults']

Commands

  • /auto — Switch to auto mode
  • /auto-status — Show diagnostics

Logging

All decisions are logged to ~/.dsh/auto-mode/decisions.jsonl (JSONL format, append-only).

Architecture

src/
  index.ts         Main entry: preset management, approval answerer, commands
  config.ts        Config schema + $defaults mechanism + built-in rule lists
  bands.ts         Deterministic band engine (deny regex + allow glob)
  pre-execute.ts   Pre-execute gate (first defense for all tools)
  classifier.ts    Two-stage classifier (one-token filter + structured review)
  rules.ts         Prose rule matching for the classifier
  prompt.ts        Classifier prompt construction
  cache.ts         Verdict cache (shared across enforcement points)
  breaker.ts       Circuit breaker (3 consecutive / 20 total)

License

MIT