DeepSeek Harness adopts an “everything is a plugin” architecture. During daily use, when an agent session requests elevated approval, users often miss this critical operation if they are not at the terminal. Existing logging methods are not intuitive enough. The dsh-approval-notify plugin solves this problem using Windows-native mechanisms, ensuring that approval requests can be noticed even when the user is not in front of the terminal.
Plugin Overview¶
This is a client-side plugin that displays Windows-native Toast notifications and plays a system sound when a session requests elevated approval. It is maintained by Uknown-wang and is licensed under the MIT license.
Core Features¶
- Windows-native Toast notifications: Displays system-level notifications to avoid being blocked by the terminal window.
- System sound: Plays a sound to alert the user.
- Displays session details: The notification includes the session name, ID (first 8 characters), working directory path, tools used, and the reason for elevated approval.
- Web UI jump: Supports clicking the notification to open the Web UI directly for approval.
- Fallback handling: In non-interactive sessions or when Toast is unavailable, it degrades to playing only the alert sound.
- Event monitoring: Monitors the
approval/askedevent stream to ensure no approval request is missed.
Installation¶
Use the official CLI command to install the plugin. The plugin declares dsh.bundle.patch; dsh plugin add automatically merges it into the profile’s bundle layer stack.
dsh plugin --profile <profile> add dsh-approval-notify
After installation, restart the dsh process to activate the plugin.
Configuration¶
After installation, add or modify the following fields in the profile configuration file. Note that DSH composite patches replace the entire config block line by line; when overriding configuration, the complete fields must be rewritten.
| Item | Default | Description |
|---|---|---|
dedupeMs |
1500 |
Deduplication window for the same session (milliseconds). |
sound |
ms-winsoundevent:Notification.Default |
Windows notification sound event name. Set to null to mute (Toast is still shown). |
launchUrl |
Environment variable DSH_WEB_URL |
URL opened when the notification is clicked. Set to null to disable navigation. |
titlePrefix |
Elevation approval required |
Prefix for the notification title. |
disabled |
false |
Set to true to temporarily disable the plugin. |
appId / powershell |
Classic PowerShell toast AppId | Advanced options; usually no changes are needed. |
How It Works¶
The plugin monitors the approval/asked audit event in the post-submission session/event event stream. It deliberately does not attach to the approval/request waterfall; instead, it uses firehose mode. This means that regardless of listener registration order, notification failures will never affect the approval pipeline itself. Notifications are emitted by powershell.exe through WinRT ToastNotificationManager, without requiring additional modules.
Use Cases and Requirements¶
- Platform limitation: Supports only Windows 10/11. On non-Windows platforms, the plugin is automatically disabled.
- Environment dependency: Requires the official DSH profile to provide the
approvalandsessionTitleservices. - Permission note: The plugin runs with the permissions of the current DSH process. Before installation, review the source code and license (MIT).
Conclusion¶
This plugin provides immediate visual feedback for DeepSeek Harness’s elevated approval flow and is suitable for developers who need to respond quickly to approval requests. The related directory and source code can be found in the community plugin marketplace.