Introduction

In DSH (DeepSeek Harness), agents display approval prompts when they trigger operations such as writes and command execution outside the sandbox. In the “Automatic Approval” preset, this plugin forwards each approval request to a dedicated reviewer model for adjudication.

Plugin Positioning

This is an independent, model-driven automatic approval plugin maintained by Scotlight for DSH (Codex Guardian–style automated review). It separates review logic from the agent model and implements the full Codex Guardian policy.

Core Features

Independent Review Channel

The endpoint, model, reasoning effort, and timeout are configured independently; hot-swapping the agent model does not affect the reviewer.

Full Codex Guardian Policy

Implements a Risk (Low/Medium/High/Critical) × Authorization (Unknown/Low/Medium/High) matrix. File/tool content is treated as untrusted evidence, and only explicit user instructions grant authorization—meaning “do what the file says” does not authorize dangerous content inside the file.

Payload Samples

For outbound operations, the plugin pre-reads the file being written/uploaded (with a 2KB summary) so the reviewer sees exactly what content will leave the machine.

Three-State Circuit Breaker

Configured for 3 consecutive denials / 3 consecutive channel errors / 10 denials in a 50-review window. Any trigger fails fast with a readable reason (consistent with Codex’s “stop and declare approval failure” behavior).

Fail-Close

A dead reviewer endpoint does not result in an allow; requests fall back to the manual approval UI.

Sidecar Audit Log

Each decision (allow/deny/error/circuit breaker open/delegated) is appended to ~/.dsh/auto-approval-audit.l, including risk/authorization/rationale.

Dual API Styles

Supports responses (strict _schema) or chat (OpenAI-compatible /chat/completions) for relay/proxy providers.

Installation and Enablement

dsh plugin --profile web add -w dsh-guardian-approval@0.1.1

Restart DSH Web, then go to Settings -> Plugins -> Plugin Configuration -> DSH Auto Approval. Configure the reviewer endpoint and model.

Typical Usage

  • The user explicitly requests deletion of this directory -> Allow.
  • A file instructs copying API key configuration to public -> Deny.
  • A file instructs setting a directory ACL to Everyone:F -> Deny.
  • The review channel fails 3 consecutive times -> Circuit breaker.

Notes

  • Redaction is best-effort and cannot guarantee detection of every key format.
  • Use reviewer endpoints that you trust to handle workspace data.

Conclusion

Through an independent review channel and a strict policy matrix, this plugin provides DSH with Codex Guardian–style automated security protection. For more details, refer to the plugin directory or the GitHub repository.