Introduction¶
DeepSeek Harness (DSH) provides the ability to build agent workflows, where permission control is a core component. Beyond relying entirely on manual approval, developers often need a middle-ground solution for low-risk tool call requests. The dsh-approval-llm plugin introduces an independent review model to automatically handle approval/request requests in a specific mode, enabling an automated “approve-for-me” approval flow.
Plugin Overview¶
This plugin is maintained by developer Letter2025 and is a community plugin for DeepSeek Harness that adds a model-based permission approval mode. It allows a review model to decide tool call permissions on behalf of a human under the “Help Me Approve” preset. The review model outputs ALLOW, DENY, or ESCALATE, and only returns the request to the manual channel when it cannot make a decision or when a failure occurs.
Core Features¶
The plugin mainly includes the following features:
- Model approval mode: Provides model-based permission approval (“approve-for-me”) capability, automatically answering approval requests in a specific mode.
- Three-way decision mechanism: The review model decides
ALLOW(allow),DENY(deny), orESCALATE(escalate/forward). - Circuit breaker mechanism: A built-in circuit breaker prevents the review model from issuing consecutive
DENYdecisions; after exceeding the threshold, it automatically switches to manual handling. - Deterministic routing policies: Supports three routing policies:
SAFE_ALLOW,DENY, andHUMAN_ONLY, performing pre-decisions before invoking the model. - Failure escalation to humans: When the review model fails, times out, or encounters parsing errors, the policy automatically switches to manual handling instead of directly denying the request.
Configuration and Usage¶
Enable the plugin by activating a specific permission preset and configure detailed policies via configuration files.
- Activate the preset: In DeepSeek Harness, activate the “Help Me Approve” preset so the review model can process approval requests. Under other presets, the plugin remains silent and does not affect the existing manual approval flow.
- Configuration overrides: Override configuration items via
cordis.patch.yml.
Main configuration fields include:
* enabled: Master switch, default is true. When set to false, all requests are handled manually.
* modePreset: Specifies the preset name that activates this review mode, default is model-approval.
* provider / model: Specifies the model provider and specific model used for review; both must be set. If not set, it attempts to reuse routing from session logs.
* timeoutMs: Review timeout, default is 60000 milliseconds.
* allowlist / denyList / humanOnlyList: Whitelist, blacklist, and human-only list for deterministic routing.
* maxConsecutiveDenials: Threshold for consecutive DENY decisions, default is 3; after exceeding it, requests are forwarded to manual handling.
* includeArgs: Whether to restore tool arguments from session logs for review, default is true.
Notes and Use Cases¶
- Policy choice, not a security guarantee: AI review is essentially a policy choice, not a security guarantee. The plugin cannot defend against attacks such as prompt injection and is suitable only for low-risk workflows.
- Parameter source: The input parameters for the review model are restored from session logs (
tool/call) rather than taken directly from the approval request. - Failure handling: A model failure is directly escalated to manual handling and is not counted toward circuit breaker statistics.
- License: Use of this plugin is subject to the MIT License.
Summary¶
dsh-approval-llm provides DeepSeek Harness with a middle-ground solution between full automation and full manual control, suitable for scenarios that require partially automated approval without completely relinquishing security control.
- Plugin directory: dsh-approval-llm - SkillHub
- Source repository: Letter2025/dsh-approval-llm