Introduction

In DeepSeek Harness (DSH) development, sandbox privilege escalation requests (such as executing Shell commands or modifying files) must be handled carefully. These usually require manual approval or complex rule logic. The dsh-llm-approve-for-me plugin uses a built-in reviewer role to let an LLM automatically decide these permission requests, reducing the burden of manual intervention while maintaining flexibility in decision-making.

Plugin Positioning

This is a DeepSeek Harness plugin that automatically determines sandbox privilege escalation using a built-in reviewer role. It is maintained by the user alaxrpg and follows the MIT license. It solves the problem of “how to safely handle sandbox permission requests in automated workflows” by delegating decision-making to the configured LLM model rather than hardcoded rules.

Core Features

  1. Automatic review of privilege escalation: Intercepts all tool calls with sandbox_permissions, including Shell/PowerShell commands and write/edit file writes.
  2. Dedicated reviewer role: Uses the built-in REVIEWER_ROLE. This role has no tools and no session, quickly decides a single request, and does not borrow generic sub-agent templates from the environment.
  3. Lightweight execution: Does not create an Agent or Session and does not pollute the sub-agent list. Each approval returns only a native allowed-once one-time authorization.
  4. Visual panel: Provides a “Help Me Approve” panel at the top of the DSH Web session.
    • History: Displays the most recent 100 approval records separately by session (including the request target, rationale, permissions, reviewer model, AI conclusion, and result).
    • Settings: Visually adjust reviewer model parameters.
  5. Model configuration: Supports configuring the reviewer model’s Provider, Model, Timeout, and Max tokens.

Installation and Enablement

Run the following command in your DSH profile to install it:

dsh plugin --profile web add github:alaxrpg/dsh-llm-approve-for-me

After installation, restart DSH Web. The plugin automatically adds the “Help Me Approve” permission preset to the session (it can be overridden manually on the settings page). Click “Help Me Approve” at the top of the session to enter the approval panel.

Typical Usage

1. Configure the Reviewer Model

After installation and restart, go to the Settings page of the “Help Me Approve” panel. It is recommended to set the reviewer model to a fast non-reasoning model to improve response speed.

Setting Default Range Description
Reviewer provider Empty (inherited from main session) Any provider name If left empty, it inherits the configuration of the session that made the request
Reviewer model Empty (inherited from main session) Any model name It is recommended to point to a fast non-reasoning model
Timeout 300 seconds 1–600 seconds The thinking time of reasoning models counts toward the timeout
Max tokens 16384 256–65536 Includes the reasoning process

The saved configuration is written to ~/.dsh/llm-approve-for-me.settings.json and takes effect immediately without restarting.

2. Review Protocol

The plugin sends requests to the built-in role through the DSH llm service, requiring it to return strict JSON format:

{"decision":"allow","rationale":"原因"}
  • decision: Only allow, deny, or ask is supported.
  • rationale: A one-sentence rationale must be output in Simplified Chinese.

Notes and Configuration

  1. Strict JSON format: The reviewer model must return standard JSON. If the output contains a Markdown code fence or a non-JSON response, the system automatically falls back to manual approval.
  2. Exception handling: If the review times out, is canceled, the model call fails, or the output is invalid, the system falls back to manual approval and records the specific reason (also in Chinese).
  3. Target extraction limitation: For requests where the review target cannot be extracted (such as some tools with escalation parameters), the system hands the request back to manual approval.
  4. Content truncation: Review summaries are automatically truncated to 2000 characters to prevent large files from flooding the output.
  5. Priority rule: The configuration file ~/.dsh/llm-approve-for-me.settings. has higher priority than static configuration.
  6. Not a security product: This plugin is not a security product and cannot replace manual authorization, the principle of least privilege, data backup, or isolation measures. Its purpose is to delegate authorization decisions to an LLM, not to use it as a firewall.

Conclusion

dsh-llm-approve-for-me provides DeepSeek Harness users with an LLM-based sandbox permission review solution. By configuring and monitoring approval history, you can find a balance between automation and security. For more details, see its GitHub repository.