DSH Plugin Store
Back to home

Andy8647

dsh-auto-approval

No description

Stars
2
Language
JavaScript
Created
Aug 8, 2026
Updated
Aug 13, 2026
Other
GitHub repo

Introduction

dsh-auto-approval

English | 中文

Automated tool-call approval for DeepSeek Harness: an auto tier for the approval policy that classifies every tool call as allow / deny (fully autonomous — no human in the loop, uncertain calls are denied).

A monorepo of two packages:

PackageRole
packages/dsh-auto-approvalhost half: pre-execute classifier (L0 rules + L1 LLM, two-state allow/deny)
packages/dsh-client-ui-auto-approvalclient half: AA status chip beside the composer access-mode selector, fed by the host via a Typert remote

Demo

auto-approval two-state decision demo

The chip next to the composer shows the run state (AA on / AA off); hover for cumulative stats, click for a dialog with the on/off switch, config summary and the recent-decisions table. The demo covers: file read/write and ls whitelisted and dispatched directly, a harmless command allowed by the L1 classifier, and dangerous commands rejected by deny rules / legacy-ask rules (now denying) / the self-kill guard.

Install

Install both packages into the same profile (published to npm, ships built artifacts — no build environment needed):

# host half (required: the approval decision logic)
dsh plugin --profile web add dsh-auto-approval
# client half (optional: the AA status chip in the composer)
dsh plugin --profile web add dsh-client-ui-auto-approval

For source-based installs (development / self-hosting), see the host package README.

Development

pnpm install          # export NPM_TOKEN=$(cat ~/.dsh/npm-token) if any @deepseek-ai/* dep is still private
pnpm -r run build     # build both packages
pnpm -r run test      # host unit tests

License

BSD-3-Clause