Foreword¶
The core design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” When building agent workflows, it is common to encounter situations where the “research phase” and the “execution phase” have different permission requirements. The native Read-Only preset in DSH provides basic security guarantees, but it is not semantically intuitive and cannot enforce blocking permission escalation requests.
This plugin aims to map the read-only permission preset in the DSH Web UI into an OpenCode-style Plan mode at the configuration layer. It does not change the underlying logic; instead, through the Cordis Patch mechanism, it unifies the permission presentation and approval policy of the workflow.
What Is This¶
This is a DSH plugin named dsh-plan-preset.
- Core feature: Maps the
read-onlypermission preset in the DSH Web UI to an OpenCode-stylePlanmode. - Maintainer: 23aisfvb
- Category: admin-security
- License: MIT
It solves the following problem: how to maintain the existing DSH architecture while achieving semantic isolation between “read-only research” and “plan mode” through simple configuration changes, and prevents unauthorized permission escalation.
Core Features¶
After the plugin is enabled, the permission preset will change as follows:
- Display name: The access mode control in the Web UI will be displayed as “Plan” (the icon remains in shield style, and the original name “Read Only” is overridden).
- File operations: Read-only. It allows reading files, but denies writing, deleting, or modifying files.
- Web search: Available. File sandbox restrictions are decoupled from the web search feature, so the Agent can still use web search even in read-only mode.
- Permission requests: Denied. The approval policy is set to
never. This means any permission escalation request is automatically denied, and the denial is final.
Install and Enable¶
The installation process involves local dependency configuration and dependency installation. Execute the following steps in order.
-
Modify
profiles/web/package.json:- Add the following to the
dependenciesfield:"dsh-plan-preset": "file:E:/agent/deepseek_harness/Plugins/dsh-plan-preset" - Add the following to the
dsh.profile.bundlesfield:"dsh-plan-preset"
- Add the following to the
-
Enter the plugin directory and install dependencies:
cd profiles/web && pnpm install
- Restart the DSH Web service:
dsh web
Typical Usage¶
After installing the plugin and restarting the service, you can verify the configuration or use this mode in the following ways.
Verify the configuration:
Run the following command to inspect the configuration output and confirm that the permission line has been overridden:
dsh --profile web --dump-config
In the output, you should see the permission line contains read-only.name=Plan and approval=never.
Workflow practice:
1. Start the Agent; it is in Plan mode by default.
2. The Agent performs Q&A and file research, uses web search to assist analysis, but cannot modify any files.
3. After the Agent produces the final plan or research conclusion, the user manually switches the permission mode (for example, switch to Full Access).
4. The Agent obtains full permissions and begins executing specific file-writing operations.
Applicable Scenarios and Notes¶
- Implementation principle: This is a pure composition patch and contains no runtime code. It overrides the
permissionline configuration indsh-basethroughcordis.patch.yml. Other presets (such asworkspace-write) are not affected. - Upgrade compatibility: The Cordis Patch mechanism uses whole-line overriding. If an upgrade of the DSH main program causes the default
permissionline preset to change (for example, new presets are added or fields are adjusted), this plugin’s configuration may be shadowed by the new default configuration. After upgrading DSH, make sure to rundsh --profile web --dump-configto verify.
Summary¶
dsh-plan-preset is a lightweight configuration patch plugin. It does not rely on complex runtime code; by modifying configuration mappings only, it helps teams establish a clearer workflow permission system in DSH. For agent development scenarios that require strict separation between “research/plan” and “execution” phases, this plugin provides a standardized solution.