The Web UI of DeepSeek Harness (DSH) provides basic sandbox permission presets, but when handling complex tasks, more flexible intermediate states or automated approval mechanisms are sometimes required. The dsh-agent-approval plugin fills this gap by introducing a new permission mode: while maintaining the workspace-write safety baseline, it delegates all permission escalation requests to an independent approval agent for automated adjudication.

Core Features

The plugin primarily provides the following capabilities:

  • Permission Preset Extension: Adds an Agent Approval preset to the /permission menu. Selecting this preset turns the feature on; switching to another preset automatically turns it off.
  • Automated Adjudication Mechanism: When enabled, the sandbox baseline is fixed to workspace-write, and the approval policy is taken over by the plugin as ask. Each permission escalation request no longer triggers a popup; instead, it is adjudicated by a one-time spawn subagent. The subagent has an independent session, zero tool permissions, and can only read the context and make a judgment.
  • Risk Control: The approval agent determines whether an operation is destructive, irreversible, or out of scope. Only operations that are “safe, reversible, task-aligned, and honestly justified” are approved; otherwise, they are rejected outright.
  • Fail-Closed Policy: For safety, if the approval agent fails to start, times out, or returns an invalid result, the request is always treated as rejected; it is never silently allowed.
  • Configurability: The settings page allows selecting the approval model (Provider + Model) and timeout duration. If no model is selected, the Harness default model is used.
  • Audit and Records: An Approval tab appears at the top of the session window, displaying the session’s approval records (conclusion, risk level, model, duration, reason). Records are stored as separate files in the session directory. Approved entries can be one-click “whitelisted” and saved as allow rules.
  • State Restoration: When the plugin is disabled, it automatically restores the permission knob state that was in effect before it was enabled.

Installation

Install it using the official dsh plugin command. This plugin is a standard DSH bundle, mounted and menu-registered through dsh.bundle.patch and cordis.patch.yml.

dsh plugin --profile web add /path/to/dsh-agent-approval

After restarting DSH, an Agent Approval page appears in the settings panel, and a fourth Agent Approval item appears in the /permission menu.

If you need to add an icon to the menu item, you can run the following after installation:

npm run patch:glyph

Usage

  1. Enable Approval: Select Agent Approval in the /permission menu, or directly enter /agent-approval on.
  2. View and Whitelist: At the top of the session window, click the Approval tab to view audit records. For approved entries, you can one-click “whitelist” them and save them as allow rules.
  3. Configure Model: Go to the settings page and configure the approval model, timeout duration, and allow/reject rules.
  4. Disable Approval: Switch back to another preset, or enter /agent-approval off; the system will restore the sandbox mode and approval policy that were in use before it was enabled.

Notes

  • License: Follows the MIT License.
  • Record Storage: Approval records are stored as separate files in the session storage directory; deleting the session also deletes the records.
  • Execution Permissions: The plugin runs with the permissions of the current DSH process. It is recommended to review the source code before installation.

For more details and the repository link: DeepSeek Harness Agent Approval Permission Plugin