Permission control in DeepSeek Harness (DSH) typically relies on native Permission Presets. The default configuration often struggles to balance security and flexibility, and modifying the Harness core code to adapt to specific scenarios can be costly. The dsh-access-mode plugin provides three access modes—Default / No Edit / Auto—replaces the native selector on the left side of the Web composer, and lets users exercise fine-grained control over AI tool-call permissions, Sandbox policy, and Approval policy at the session level without modifying the Harness core code.
Plugin Overview¶
dsh-access-mode is maintained by developer ddll8023 and belongs to the admin-security category. It extends DSH permission management as a plugin and supports the following core features:
- Three access modes: Provides a Default / No Edit / Auto drop-down selector in the Web interface.
- Non-invasive integration: Does not modify the Harness core code, Agent loop, tool implementations, or model invocation flow.
- Session persistence: Modes are persisted per Agent session, and the Sandbox and Approval policies take effect immediately after switching.
- Service reuse: Reuses native Harness Approval, Sandbox, Tool Execution, Session, and Remote Command services.
Installation and Enablement¶
Ensure DeepSeek Harness is installed and is version 0.1.0-rc.6 or higher. The dsh plugin command depends on pnpm; if it is not installed, enable it with corepack enable pnpm.
Use the officially recommended command to install directly from GitHub:
dsh plugin --profile web add github:ddll8023/dsh-access-mode
After installation, restart dsh web to load the plugin. The three access mode options—Default, No Edit, and Auto—should appear on the left side of the Web composer. New sessions default to No Edit.
To verify successful enablement, run:
dsh --profile web --dump-config | grep -A2 access-mode
Expected output includes id: access-mode and name: dsh-access-mode.
Usage¶
The plugin switches modes using the /access-mode command. The mode is written to the current Agent session and persists permission/preset, sandbox/mode, and approval/policy in native session events, thereby controlling subsequent execution.
Mode Details¶
| Mode | Sandbox policy | Approval policy | Behavior description |
|---|---|---|---|
| Default | workspace-write |
ask |
Automatically allows read-only tools (such as read, grep, web_search, etc.) and conservative read-only Bash commands. Editing, writing, and unknown operations require approval. |
| No Edit | danger-full-access |
ask |
Only edit and write require approval; other tools are allowed directly, and Bash arguments are not checked. Suitable for scenarios that need access to files outside the workspace but want to avoid accidental writes. |
| Auto | danger-full-access |
never |
Allows all tool calls. Suitable for fully trusted sessions; do not enable it for untrusted prompts or projects. |
Switching Modes¶
Use the drop-down selector in the Web composer, or enter the following command directly in the session:
/access-mode default # 切换到 Default
/access-mode no-edit # 切换到 No Edit
/access-mode auto # 切换到 Auto
For older sessions that do not have plugin mode events, the plugin initializes based on the existing Approval state: a never state is treated as Auto, and any other state is treated as No Edit.
Security Notes¶
- Version compatibility: Supports only DSH
>= 0.1.0-rc.6. - danger-full-access risk: No Edit and Auto modes use
danger-full-access, which removes path restrictions from the DSH file Sandbox. Use these modes only in trusted sessions to prevent AI actions from damaging the system or sensitive data. - Operating system permissions:
danger-full-accessonly removes DSH file-system Sandbox restrictions; it does not bypass operating system permissions, container permissions, or remote execution environment restrictions. - Default boundary: Default mode still retains the
workspace-writeboundary. If access to files outside the workspace is required, switch to No Edit and approve the relevant operations.
Summary¶
dsh-access-mode provides flexible session-level permission control for DSH through the plugin mechanism. It does not require modifying core code and allows switching among Default, No Edit, and Auto through simple commands and interface actions, adapting to different workflow needs from conservative development to full automation.
- Catalog page: dsh-access-mode
- Source code: ddll8023/dsh-access-mode