Introduction

DeepSeek Harness (DSH) adopts a plugin-based architecture, where everything is a plugin. When developing agents or building enterprise-level applications, security and compliance controls need to be added before tool invocation. The dsh-approval-flow-poc plugin implements a minimal enterprise approval policy layer on the official tools/pre-execute extension point. It is responsible for risk classification of tool invocations, deciding whether to allow, deny, or request manual approval based on preset policies, and generating masked audit logs.

Core Capabilities

This plugin evaluates the risk of tool invocations based on the tool name and a masked parameter summary. It supports classifying risk into four levels: low, medium, high, and critical. It implements three basic policies: allow (permit), deny (block), and requireApproval (request approval).

For auditing, the plugin only records the masked summary, policy decision, and final error status, without containing original parameters, in order to balance security and privacy. When a policy requires approval, the plugin uses DSH’s native approval channel, providing an injectable ApprovalTransport interface and a TTY transport for local debugging.

Installation and Enablement

Install the plugin into the Web profile using the npm package manager:

npx @deepseek-ai/dsh plugin --profile web add github:lasoloryan/dsh-approval-flow-poc

After installation, run a configuration check to confirm the plugin is active:

npx @deepseek-ai/dsh --profile web --dump-config

In the output, you should see the following configuration entry:

- id: approval-flow-policy
  name: dsh-approval-flow-poc

Configuration and Policies

The plugin provides three preset policies, each suitable for different scenarios. When switching presets, you must override the complete configuration in the profile’s cordis.patch.yml. Note that DSH patches replace the config for the same entry as a whole rather than deep-merging it, so all fields must be included in full when overriding.

Preset Policy Comparison Table:

Preset low medium high critical Use Case
developer Delegate/Allow Delegate/Allow Manual approval Deny Local development
production Delegate/Allow Manual approval Manual approval Deny Pre-production or controlled operation
strict Delegate/Allow Manual approval Deny Deny Highly sensitive demonstrations

Configuration Example:

- id: approval-flow-policy
  config:
    preset: production
    auditPath: .dsh-approval-flow/audit.jsonl
    approvalTimeoutMs: 45000
    localPrompt: false
    include: []
    exclude: []

Notes

This is an unofficial community experiment. It is not affiliated with or endorsed by DeepSeek AI and provides no security guarantees for production environments.

Functional Boundaries:
* Does not provide SSO (Single Sign-On), RBAC (Role-Based Access Control), multi-level co-signing, remote Webhooks, or other advanced features.
* Does not provide tamper-proof logs or compliance certification.
* DSH is currently in developer preview. After upgrading the DSH version, incompatible changes may occur, requiring configuration checks and tests to be re-run.

Summary

This plugin provides DSH developers with a practical approval policy prototype, suitable for scenarios requiring rapid implementation of basic tool invocation controls and auditing. For more details, refer to the project directory page or GitHub repository.