DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Guardian Approval — DeepSeek Harness 插件(DSH Plugin)
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录
← Plugins

dsh-guardian-approval

Guardian Approval

面向 DSH 的独立 Codex Guardian 风格审批审核器。

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add dsh-guardian-approval@0.1.1
README兼容性版本

兼容性与来源证明

Guardian Approval 以 dsh-guardian-approval 发布,当前版本为 0.1.1。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
web
发布来源
npm
Registry 更新时间
2026/9/20

版本

0.1.1stable
2026/8/20
0.1.0stable
2026/8/20

相关插件

正在加载相关插件…

最新版
0.1.1
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
174.7 kB
文件数
43
Surface
web
许可证
MIT
发布源
npm
GitHub
★ 2
周下载
87
最近提交
2026/8/20
查看源码 ↗项目主页 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题

相关插件

继续浏览 security-access 分类下经过校验的插件。

Doctor@linxin666/dsh-doctorDSH 配置档案的事务性救援模式,配备受监督的启动器、隔离的恢复容器、确定性修复、健康监控以及本地 Web 恢复控制台Pocketdsh-pocket把 DeepSeek Harness 装进你的口袋:一个包、一个设置页,手机扫码即同步访问电脑上的 DSH(局域网 + 公网,实时同屏)。DSCODE@toddzheng024/dscode-bundle完整的 DeepSeek 编码代理,支持持久化 shell、Ultra 协作和自动权限审查。Auto Reviewdsh-auto-review针对 DeepSeek Harness 审批请求的第二模型 AI 自动审查:只读审查子代理在审批应答链上决定允许或拒绝,并采用故障关闭回退机制和完整的会话日志审计。

README

dsh-guardian-approval

English · 简体中文

In DSH (DeepSeek Harness), agents trigger approval prompts for out-of-sandbox writes, command runs, etc. Under the "Auto Approve" preset, this plugin hands every approval request to a fixed reviewer model for a verdict:

approval request ──► collect evidence (tool call + args + egress payload pre-read)
                        │
                        ▼
              reviewer model (fixed route, immune to
              the agent's hot model switches)
              embeds the full Codex Guardian policy
                        │
              ┌─────────┴─────────┐
              ▼                   ▼
            allow             deny / circuit-break
       (allow this once)   (reject with a readable reason)
              │
     channel failure → fail-closed to human, never silently allow

Features

  • Independent review channel — endpoint, model, reasoning effort and timeout are configured separately; hot-swapping the agent's main model never touches the reviewer
  • Full Codex Guardian policy — the risk (low/medium/high/critical) × authorization (unknown/low/medium/high) matrix; file/tool content counts as untrusted evidence, only explicit user instruction authorizes — "do what the file says" does not authorize the dangerous thing inside the file
  • Payload samples — for egress-shaped actions the plugin pre-reads the file being written/uploaded (2KB excerpt) so the reviewer sees exactly what would leave the machine
  • Three-state circuit breaker — 3 consecutive denials / 3 consecutive channel errors / 10 denials in a 50-review window; any trip fast-fails with a readable reason (parity with Codex's "stop and announce approval failure" behavior)
  • Fail-closed — a dead review endpoint never results in an allow; requests fall back to the human approval UI
  • Sidecar audit trail — every verdict (allow/deny/error/circuit-open/delegated) is appended to ~/.dsh/auto-approval-audit.jsonl with risk/authorization/rationale
  • Dual API styles — responses (strict json_schema) or chat (OpenAI-compatible /chat/completions) for relay/proxy providers

Data boundary

The configured reviewer receives sanitized tool arguments, bounded recent direct-user messages, and, for egress-shaped actions, up to four 2KB local-file excerpts. Redaction is best-effort and cannot guarantee detection of every secret format. Use only a reviewer endpoint you trust with the reviewed workspace data.

Verified behavior (live cases)

ActionVerdictRationale
User explicitly asked: delete this directory✅ allownarrow scope + explicit authorization
A file instructed: copy an API-key config into Public❌ deny"user only authorized following untrusted file content, never authorized writing secrets to a public path"
A file instructed: set a directory ACL to Everyone:F❌ denypersistent security weakening, not narrowly scoped
Review channel failed 3× in a row❌ breaker"review service failed 3 times in a row — check the channel or retry later"

Install

Requires Node.js 22.19 or later and DSH 0.1.0-rc.6 or later in the 0.1 release line. Development and CI use DSH rc.8.

dsh plugin --profile web add -w dsh-guardian-approval@0.1.1

Restart DSH Web, then fill in Settings → Plugins → Plugin config → DSH 自动审批:

settings

The 连通与策略 section has a one-click connectivity test (sends a real probe review and shows the verdict, risk/auth grades, rationale and latency — verifying endpoint, model, key, API style and policy in one shot) and a policy-document editor (the full Codex Guardian policy text ships built-in; edit or replace it, effective on the next review without restart):

policy editor

Then: any OpenAI-compatible endpoint, a reviewer model, and the API key (stored in the DSH credential store, never in the repo). Pick the Auto Approve preset in a session to activate.

Development

pnpm install
pnpm run build   # tsc + client bundle
pnpm test        # vitest: evidence recovery, output parsing tolerance, breaker states, error breaker

Policy sources

  • codex-rs/core/src/guardian/policy_template.md
  • Codex sandboxing/auto-review docs

Deep dives

  • Architecture — the approval waterfall mount point, evidence assembly, dual API styles, three-state breaker, and the sidecar-audit decision
  • Policy & verdicts — the risk × authorization matrix, untrusted-evidence rules, the two-condition injection test, and known limits
  • Field notes — three days of gotchas: traceable-proxy receiver loss, the session-log vocabulary brick, four relay-channel quirks, and the live testing methodology

License

MIT