DSH’s default permission model is often extreme: either overly conservative, requiring frequent confirmations that block the workflow, or overly aggressive, allowing dangerous operations to run directly. dsh-perm-guard aims to act as an “intermediate layer” between the two by automatically approving common operations and blocking dangerous commands, balancing development efficiency with security.
Plugin Overview¶
dsh-perm-guard is a permission auto-approval plugin for DeepSeek Harness (DSH) Web, maintained by community developer a903067276-rgb.
The plugin intercepts permission requests from the DSH agent when it executes commands (such as bash, pwsh) or file operations (write/edit). Under the default configuration, routine operations such as file editing, Git commits, and build tests are approved automatically; destructive operations such as deleting files, privilege escalation, and downloading/execution over the network require forced manual confirmation.
Core Features¶
- Dual-mode policy: Provides “Standard” and “Aggressive” modes.
- Standard mode: Automatically approves operations only inside trusted directories; cross-directory or dangerous operations require confirmation.
- Aggressive mode: Removes location restrictions and enforces confirmation only for destructive operations (such as deletion and privilege escalation).
- Fine-grained control: Supports tri-state toggles for 11 categories (auto/ask/deny), allowing custom default behavior for each operation type.
- Audit and persistence: Records a timestamp and command summary for every approval decision; configuration is saved in
~/.dsh/perm-guard.jsonand automatically loaded after restart. - Full entry-point coverage: Intercepts all DSH approval entry points, including
bash,pwsh, and thewrite/editfile tools.
Installation and Enabling¶
Run the following command in a terminal to install the plugin, then restart dsh web.
dsh plugin --profile web add "github:a903067276-rgb/dsh-perm-guard#main"
After installation, refresh the DSH Web page in your browser to make it take effect.
Usage¶
- Global switch: Click the “Auto” button in the Composer toolbar (to the left of the input box). A green button indicates that auto-approval is enabled.
- Mode configuration: Go to the Settings page and find the “Auto Permissions” option. Here you can switch between Standard/Aggressive mode, adjust the toggles for the 11 categories, or edit the trusted directory list.
- Scope of effect: While the plugin is enabled, the rules apply to all sessions, including sub-agents.
Notes and Compatibility¶
- Version compatibility:
- DSH version
0.1.5and above is incompatible with plugin versionv0.2.8. Installingv0.2.8causes the entire plugin tree to fail to load, so the Web app cannot start. Use themainbranch orv0.2.9or higher. - The DSH
0.1.0-rc.6to0.1.5series has been tested for compatibility.
- DSH version
- Security boundaries:
- The DSH sandbox does not have OS-level network isolation. The plugin can only identify network download-and-execute behavior by detecting patterns such as
curl|shin command text; it cannot block other network traffic. - Terminal sessions, MCP tool calls, and model calls are currently not covered by this approval system.
- The DSH sandbox does not have OS-level network isolation. The plugin can only identify network download-and-execute behavior by detecting patterns such as
- Command fallback:
- For unknown commands, the system always falls back to “ask” mode and does not approve them automatically.
- Project nature:
- This is an unofficial community project with its source code hosted on GitHub. Before installing, confirm that the source code and license meet your use requirements.
Summary¶
dsh-perm-guard addresses the conflict between frequent prompts and unchecked operation in DSH through persisted configuration and interception mechanisms. For scenarios that require automated execution of many routine commands while preventing accidental deletion or privilege escalation, the plugin provides a practical intermediate-layer safeguard.