Introduction¶
DeepSeek Harness (DSH) is a plugin-based agent development framework. shifan3/dsh-approve-for-me is a DSH host plugin that adds an approve-for-me approval mode to DSH. This mode uses an LLM security reviewer to automatically judge and execute approval requests based on conversation summaries, while intercepting high-risk destructive commands.
Feature Overview¶
The plugin provides the following capabilities:
* Automatic approval mode: Under the ask approval policy, it uses an LLM to judge approval requests and responds with ALLOW or REJECT.
* High-risk interception: For destructive commands such as rm -rf and drop table, the plugin skips LLM judgment and directly asks the user for confirmation.
* Context summary: It reads the recent conversation summary (about 12k characters) as the basis for LLM judgment.
* Audit log: It records approval/asked and approval/decided events.
Installation¶
Static installation (recommended) keeps the plugin active after restart.
dsh plugin --profile web add ./dsh-approve-for-me
Restart dsh web after installation to activate the plugin.
If you do not want to write to the ~/.dsh directory, you can use dynamic installation. Dynamic installation only runs in the current session and becomes invalid after restart. In the Web UI, you can create a new plugin in the Cordis panel and paste the contents of host-code.js.
Configuration¶
Configure the plugin behavior through cordis.patch.yml. All configuration options are optional:
- id: approve-for-me
config:
enabled: true # 启用/禁用插件
provider: deepseek-official # LLM 提供商
model: deepseek-v4-flash # 模型名称
maxTokens: 512 # 输出最大 Token 数
summaryMaxChars: 12000 # 摘要最大字符数
timeoutMs: 60000 # 超时时间(毫秒)
High-Risk Command Interception¶
The following commands trigger user confirmation (skipping LLM judgment):
* rm -r, rm -rf, rm -fr, rm -R, rm -rfv, and similar commands
* rm ... / (delete root directory)
* drop table, drop database, drop schema
* truncate table ...
* delete from ...
* mkfs, mkfs.ext4
* dd if=
* shred, wipefs
* git push -f / git push --force
* git reset --hard
* chmod -R 777, chown -R
* :(){ :|:& };: (fork bomb)
Important Notes¶
- Policy enum: The plugin does not add a new policy enum; it operates inside the existing
askapproval policy. Enabling the plugin switches to theapprove-for-memode. - Sandbox limitations: Dynamic installation mode runs in the DSH dynamic host VM sandbox, does not support
setTimeoutorAbortController, and timeouts depend on the LLM adapter configuration. - Single-instance limitation: Only one
approve-for-meresponder can be active in the same DSH instance. A later-loaded responder overwrites an earlier-loaded one.
Conclusion¶
This plugin is suitable for developers who want to balance automated approval with manual security review. By using an LLM to automatically handle routine requests while retaining manual control over destructive operations, it can improve operational efficiency and safety in DSH applications.
Repository: https://github.com/shifan3/dsh-approve-for-me