DeepSeek Harness adopts an “everything is a plugin” architecture. During daily use, when an agent session requests elevated approval, users often miss this critical operation if they are not at the terminal. Existing logging methods are not intuitive enough. The dsh-approval-notify plugin solves this problem using Windows-native mechanisms, ensuring that approval requests can be noticed even when the user is not in front of the terminal.

Plugin Overview

This is a client-side plugin that displays Windows-native Toast notifications and plays a system sound when a session requests elevated approval. It is maintained by Uknown-wang and is licensed under the MIT license.

Core Features

  1. Windows-native Toast notifications: Displays system-level notifications to avoid being blocked by the terminal window.
  2. System sound: Plays a sound to alert the user.
  3. Displays session details: The notification includes the session name, ID (first 8 characters), working directory path, tools used, and the reason for elevated approval.
  4. Web UI jump: Supports clicking the notification to open the Web UI directly for approval.
  5. Fallback handling: In non-interactive sessions or when Toast is unavailable, it degrades to playing only the alert sound.
  6. Event monitoring: Monitors the approval/asked event stream to ensure no approval request is missed.

Installation

Use the official CLI command to install the plugin. The plugin declares dsh.bundle.patch; dsh plugin add automatically merges it into the profile’s bundle layer stack.

dsh plugin --profile <profile> add dsh-approval-notify

After installation, restart the dsh process to activate the plugin.

Configuration

After installation, add or modify the following fields in the profile configuration file. Note that DSH composite patches replace the entire config block line by line; when overriding configuration, the complete fields must be rewritten.

Item Default Description
dedupeMs 1500 Deduplication window for the same session (milliseconds).
sound ms-winsoundevent:Notification.Default Windows notification sound event name. Set to null to mute (Toast is still shown).
launchUrl Environment variable DSH_WEB_URL URL opened when the notification is clicked. Set to null to disable navigation.
titlePrefix Elevation approval required Prefix for the notification title.
disabled false Set to true to temporarily disable the plugin.
appId / powershell Classic PowerShell toast AppId Advanced options; usually no changes are needed.

How It Works

The plugin monitors the approval/asked audit event in the post-submission session/event event stream. It deliberately does not attach to the approval/request waterfall; instead, it uses firehose mode. This means that regardless of listener registration order, notification failures will never affect the approval pipeline itself. Notifications are emitted by powershell.exe through WinRT ToastNotificationManager, without requiring additional modules.

Use Cases and Requirements

  • Platform limitation: Supports only Windows 10/11. On non-Windows platforms, the plugin is automatically disabled.
  • Environment dependency: Requires the official DSH profile to provide the approval and sessionTitle services.
  • Permission note: The plugin runs with the permissions of the current DSH process. Before installation, review the source code and license (MIT).

Conclusion

This plugin provides immediate visual feedback for DeepSeek Harness’s elevated approval flow and is suitable for developers who need to respond quickly to approval requests. The related directory and source code can be found in the community plugin marketplace.