Preface

DeepSeek Harness (DSH) default mechanisms ensure safety through invocation approvals and sandbox restrictions. When developers need to process tasks for long periods without supervision, frequent manual intervention and approval workflows become obstacles. DSH itself provides the danger-full-access permission preset, but lacks a clear, fast, and human-only trigger switch. The yolo-mode plugin is designed for this scenario: it lets users activate full-access execution with a single command and automatically falls back after task completion or timeout.

What It Is

yolo-mode is a no-approval full-access (yolo) mode plugin for DeepSeek Harness, maintained by CanGeng. Its core purpose is to provide a human-exclusive trigger switch. When activated, it elevates DSH permissions to danger-full-access while using several mechanisms to limit risk and keep the state traceable.

Core Features

  1. Human-Only Switch: Activated through the /yolo command-line interface; the model side cannot obtain activation authority by itself.
  2. Full-Access Activation: After activation, the model runs under the current user’s UID and has full filesystem access, equivalent to local execution by the user.
  3. Automatic Expiration and Fallback: Supports setting a time limit (e.g., 4 hours). After expiration, it automatically falls back to the permission snapshot taken before activation.
  4. Disaster Command Interception: Intercepts dangerous operations such as fork bombs, disks formatting, and forced shutdowns.
  5. Path Protection: Prevents write/edit tools from modifying sensitive paths such as ~/.ssh, ~/.gnupg, ~/.aws, ~/.config/gcloud, and ~/.kube.
  6. Notification Mechanism: Supports sending notifications when activation, deactivation, interception, or agent idle events occur, via desktop commands, Webhooks, or SMTP email.

Installation and Enablement

According to the source-code notes, the installation steps are as follows:

# 1. Clone anywhere and link it into your profile's
...(源文本在此处截断)

Specifically, you need to clone the repository locally, link it into your DSH configuration profile, and then reload the plugin.

Typical Usage

The plugin provides a set of commands to control the mode and inspect status:

Command Effect
/yolo on Activates the mode with no default expiration time
/yolo on 4h / /yolo on 90m / /yolo on 2d Activates the mode and sets an expiration time (hours, minutes, days supported)
/yolo off Manually disables the mode and restores permissions
/yolo status Shows whether it is currently active, remaining time, fallback target, interception count, and notification channels

Applicable Scenarios and Notes

  1. Permission Scope: After activation, the model runs with the current user’s UID and has full filesystem read/write permissions. The write and edit tools can operate on arbitrary paths.
  2. Limitations of the Interception Mechanism: The interceptor is a regex-based, best-effort defense intended to prevent accidental operations, not a security boundary. It can be bypassed through deliberate obfuscation (e.g., base64 encoding).
  3. Residual Background Processes: Background processes started while active retain their permissions from activation time after expiration and are not forcibly terminated.
  4. Expiration Delay: Expiration checking has a delay of about 30 seconds plus one tool-call interval. Long-running generation tasks already in progress are not interrupted.
  5. Log Dependencies: To read session logs containing yolo events, the plugin must be loaded. If the plugin is uninstalled, session logs containing yolo events cannot be parsed normally by DSH.
  6. Source Review: Because the plugin runs in the user’s local environment, carefully review the source code and license before installation.

Conclusion

yolo-mode provides a compromise between safety and efficiency in DeepSeek Harness, suitable for developers to run long-duration autonomous tasks when they have absolute control. Its core value lies in delegating the use of “full access” to humans and supplementing it with automatic fallback and log auditing mechanisms. For more technical details, please refer to the GitHub repository or community directory page.