Permission control in DeepSeek Harness (DSH) typically relies on native Permission Presets. The default configuration often struggles to balance security and flexibility, and modifying the Harness core code to adapt to specific scenarios can be costly. The dsh-access-mode plugin provides three access modes—Default / No Edit / Auto—replaces the native selector on the left side of the Web composer, and lets users exercise fine-grained control over AI tool-call permissions, Sandbox policy, and Approval policy at the session level without modifying the Harness core code.

Plugin Overview

dsh-access-mode is maintained by developer ddll8023 and belongs to the admin-security category. It extends DSH permission management as a plugin and supports the following core features:

  • Three access modes: Provides a Default / No Edit / Auto drop-down selector in the Web interface.
  • Non-invasive integration: Does not modify the Harness core code, Agent loop, tool implementations, or model invocation flow.
  • Session persistence: Modes are persisted per Agent session, and the Sandbox and Approval policies take effect immediately after switching.
  • Service reuse: Reuses native Harness Approval, Sandbox, Tool Execution, Session, and Remote Command services.

Installation and Enablement

Ensure DeepSeek Harness is installed and is version 0.1.0-rc.6 or higher. The dsh plugin command depends on pnpm; if it is not installed, enable it with corepack enable pnpm.

Use the officially recommended command to install directly from GitHub:

dsh plugin --profile web add github:ddll8023/dsh-access-mode

After installation, restart dsh web to load the plugin. The three access mode options—Default, No Edit, and Auto—should appear on the left side of the Web composer. New sessions default to No Edit.

To verify successful enablement, run:

dsh --profile web --dump-config | grep -A2 access-mode

Expected output includes id: access-mode and name: dsh-access-mode.

Usage

The plugin switches modes using the /access-mode command. The mode is written to the current Agent session and persists permission/preset, sandbox/mode, and approval/policy in native session events, thereby controlling subsequent execution.

Mode Details

Mode Sandbox policy Approval policy Behavior description
Default workspace-write ask Automatically allows read-only tools (such as read, grep, web_search, etc.) and conservative read-only Bash commands. Editing, writing, and unknown operations require approval.
No Edit danger-full-access ask Only edit and write require approval; other tools are allowed directly, and Bash arguments are not checked. Suitable for scenarios that need access to files outside the workspace but want to avoid accidental writes.
Auto danger-full-access never Allows all tool calls. Suitable for fully trusted sessions; do not enable it for untrusted prompts or projects.

Switching Modes

Use the drop-down selector in the Web composer, or enter the following command directly in the session:

/access-mode default  # 切换到 Default
/access-mode no-edit  # 切换到 No Edit
/access-mode auto     # 切换到 Auto

For older sessions that do not have plugin mode events, the plugin initializes based on the existing Approval state: a never state is treated as Auto, and any other state is treated as No Edit.

Security Notes

  1. Version compatibility: Supports only DSH >= 0.1.0-rc.6.
  2. danger-full-access risk: No Edit and Auto modes use danger-full-access, which removes path restrictions from the DSH file Sandbox. Use these modes only in trusted sessions to prevent AI actions from damaging the system or sensitive data.
  3. Operating system permissions: danger-full-access only removes DSH file-system Sandbox restrictions; it does not bypass operating system permissions, container permissions, or remote execution environment restrictions.
  4. Default boundary: Default mode still retains the workspace-write boundary. If access to files outside the workspace is required, switch to No Edit and approve the relevant operations.

Summary

dsh-access-mode provides flexible session-level permission control for DSH through the plugin mechanism. It does not require modifying core code and allows switching among Default, No Edit, and Auto through simple commands and interface actions, adapting to different workflow needs from conservative development to full automation.