DSH’s default permission model is often extreme: either overly conservative, requiring frequent confirmations that block the workflow, or overly aggressive, allowing dangerous operations to run directly. dsh-perm-guard aims to act as an “intermediate layer” between the two by automatically approving common operations and blocking dangerous commands, balancing development efficiency with security.

Plugin Overview

dsh-perm-guard is a permission auto-approval plugin for DeepSeek Harness (DSH) Web, maintained by community developer a903067276-rgb.

The plugin intercepts permission requests from the DSH agent when it executes commands (such as bash, pwsh) or file operations (write/edit). Under the default configuration, routine operations such as file editing, Git commits, and build tests are approved automatically; destructive operations such as deleting files, privilege escalation, and downloading/execution over the network require forced manual confirmation.

Core Features

  • Dual-mode policy: Provides “Standard” and “Aggressive” modes.
    • Standard mode: Automatically approves operations only inside trusted directories; cross-directory or dangerous operations require confirmation.
    • Aggressive mode: Removes location restrictions and enforces confirmation only for destructive operations (such as deletion and privilege escalation).
  • Fine-grained control: Supports tri-state toggles for 11 categories (auto/ask/deny), allowing custom default behavior for each operation type.
  • Audit and persistence: Records a timestamp and command summary for every approval decision; configuration is saved in ~/.dsh/perm-guard.json and automatically loaded after restart.
  • Full entry-point coverage: Intercepts all DSH approval entry points, including bash, pwsh, and the write/edit file tools.

Installation and Enabling

Run the following command in a terminal to install the plugin, then restart dsh web.

dsh plugin --profile web add "github:a903067276-rgb/dsh-perm-guard#main"

After installation, refresh the DSH Web page in your browser to make it take effect.

Usage

  1. Global switch: Click the “Auto” button in the Composer toolbar (to the left of the input box). A green button indicates that auto-approval is enabled.
  2. Mode configuration: Go to the Settings page and find the “Auto Permissions” option. Here you can switch between Standard/Aggressive mode, adjust the toggles for the 11 categories, or edit the trusted directory list.
  3. Scope of effect: While the plugin is enabled, the rules apply to all sessions, including sub-agents.

Notes and Compatibility

  • Version compatibility:
    • DSH version 0.1.5 and above is incompatible with plugin version v0.2.8. Installing v0.2.8 causes the entire plugin tree to fail to load, so the Web app cannot start. Use the main branch or v0.2.9 or higher.
    • The DSH 0.1.0-rc.6 to 0.1.5 series has been tested for compatibility.
  • Security boundaries:
    • The DSH sandbox does not have OS-level network isolation. The plugin can only identify network download-and-execute behavior by detecting patterns such as curl|sh in command text; it cannot block other network traffic.
    • Terminal sessions, MCP tool calls, and model calls are currently not covered by this approval system.
  • Command fallback:
    • For unknown commands, the system always falls back to “ask” mode and does not approve them automatically.
  • Project nature:
    • This is an unofficial community project with its source code hosted on GitHub. Before installing, confirm that the source code and license meet your use requirements.

Summary

dsh-perm-guard addresses the conflict between frequent prompts and unchecked operation in DSH through persisted configuration and interception mechanisms. For scenarios that require automated execution of many routine commands while preventing accidental deletion or privilege escalation, the plugin provides a practical intermediate-layer safeguard.