Introduction

DeepSeek Harness (DSH) supports plugin-based extensions. dsh-llm-approver is a plugin for the DeepSeek Harness Web GUI that performs LLM pre-review for sandbox escalation requests (sandbox_permissions) under a conversation permission preset. It uses an LLM call in an isolated context to assess operation safety, reducing the need for manual confirmation.

Core Features

The plugin engages when the conversation is in a specific permission preset, providing the following capabilities:

  1. LLM Pre-Review: The LLM performs a safety assessment before sandbox escalation requests reach the user interface.
  2. Isolated Context: The pre-review call does not include conversation history; it contains only the command to be executed and its rationale.
  3. Intelligent Routing: For operations that are clearly safe (such as creating files, reading, or listing directories), it allows and executes them directly. For ambiguous or dangerous operations, it falls back to the original UI approval prompt.
  4. Fail-Closed: The gating logic is designed as “allow only, never deny.” Any timeout, error, or parsing failure falls back to user UI approval.
  5. Universal Fit: Supports any DSH profile (including Web GUI, cc-tui, headless, etc.).

Installation

Before installing, make sure DSH and its profiles are installed and pnpm is available.

Use the official script to install into the default Web Profile:

./scripts/install.sh

To install into another Profile, specify the parameter:

./scripts/install.sh --profile tui

Usage

After enabling the plugin, switch the conversation permission preset to activate pre-review:

  1. Select a conversation in the DeepSeek Harness Web GUI.
  2. In the permission selector, switch the preset to Workspace Write · LLM Review.
  3. Proceed with normal conversation operations. When the agent triggers a sandbox denial and retries sandbox_permissions, the pre-review logic intervenes.

Typical Example

Run the following command to test whether pre-review is working. This command should execute directly without triggering an approval dialog:

请用 bash 工具创建文件 ~/llm-review-verify.txt,内容为 'review-ok'。该路径在会话工作区之外,若被拒绝请按提示用 sandbox_permissions 重试。直接执行,不要询问我。

Then try deleting that file. At this point, an approval dialog should appear.

Configuration

The plugin configuration lives in the cordis.patch.yml file in the DSH Profile. Add the llm-approver line:

Key Default Meaning
preset workspace-write-llm The permission preset name that activates pre-review
timeoutMs 60000 LLM pre-review timeout; falls back to UI on timeout
maxTokens 256 Token limit for LLM pre-review
maxInstructionChars 16384 Maximum truncation length for tool parameters
includeUserInstruction true Whether to include a snippet of the latest user instruction

On DeepSeek family routes, pre-review calls automatically disable thinking (reasoningEffort: "off") to fit the Token budget.

Notes

  1. Runtime Environment: The plugin runs with host process privileges. Check the source code and license before installing.
  2. Hot Reload Limitation: The Web Profile does not support HMR. After modifying configuration or installing, you must restart the dsh web process for changes to take effect.
  3. Audit Trail: Regardless of whether LLM pre-review is used, approval/asked and approval/decided events are recorded by the approval service. The LLM decision result is logged in host logs (llm-approver), not in the conversation event vocabulary.