Introduction

When agents in DeepSeek Harness (DSH) lack sufficient permissions and need to escalate privileges (for example, sandbox privilege escalation or retrying with higher permissions), this usually requires manual confirmation by the user in a popup. Frequent popups can interrupt the workflow. The dsh-approve-for-me plugin configures a Reviewer model to automatically handle these privilege escalation requests in the background: low-risk requests are automatically approved, while high-risk requests are routed to manual approval or automatically rejected based on the preset mode.

Core Features

The plugin is located in the workflow category of the DeepSeek Harness ecosystem and is maintained by user watericetangcw (MIT License).
Main capabilities include:
* The Reviewer model automatically approves low-risk privilege escalation requests.
* High-risk requests can be automatically rejected or routed to manual approval.
* Supports both Accept Only and Accept & Refuse modes.

Installation and Enablement

Installation is completed via a script, which automatically modifies profiles/web/package.json and runs the installation command.

  1. Run the following command to install:
    curl -fsSL https://raw.githubusercontent.com/watericetangcw/dsh-approve-for-me/main/scripts/install.sh | bash
  1. After installation, you must restart the dsh web service and refresh the browser page before the configuration takes effect.

For manual installation, add the dependency in <DSH_HOME>/profiles/web/package.json:

{
  "dependencies": {
    "dsh-approve-for-me": "file:../path/to/dsh-approve-for-me"
  },
  "dsh": {
    "profile": {
      "bundles": [
        "@deepseek-ai/dsh-base",
        "dsh-approve-for-me",
        "@deepseek-ai/dsh-web-app"
      ]
    }
  }
}

Run npm install in the profiles/web directory and restart.

Usage Flow

  1. Configure the Reviewer model
    In Settings, select the Approve For Me page, and specify the model provider, the specific model, and the reasoning strength. Higher reasoning strength makes the evaluation more rigorous but may take longer.

  2. Switch modes
    In the mode selector on the chat interface, switch from normal mode to Approve For Me (Accept Only) or Approve For Me (Accept & Refuse).

  3. Observe the results

    • Low-risk requests: They are automatically approved by the Reviewer, and a green “Approved” decision line appears in the chat flow.
    • High-risk requests:
      • In Accept Only mode, the request is returned for manual approval, and a warning panel appears for the user to decide whether to allow it.
      • In Accept & Refuse mode, the request is automatically rejected, and a red “Rejected” decision line appears in the chat flow.

Notes

  • Bundle order: dsh-approve-for-me must be placed after @deepseek-ai/dsh-base and before @deepseek-ai/dsh-web-app; otherwise, the plugin will silently fail.
  • Model not configured: If the Reviewer model is not configured, both modes fall back to manual approval.