Introduction¶
In DeepSeek Harness (DSH) development, sandbox privilege escalation requests (such as executing Shell commands or modifying files) must be handled carefully. These usually require manual approval or complex rule logic. The dsh-llm-approve-for-me plugin uses a built-in reviewer role to let an LLM automatically decide these permission requests, reducing the burden of manual intervention while maintaining flexibility in decision-making.
Plugin Positioning¶
This is a DeepSeek Harness plugin that automatically determines sandbox privilege escalation using a built-in reviewer role. It is maintained by the user alaxrpg and follows the MIT license. It solves the problem of “how to safely handle sandbox permission requests in automated workflows” by delegating decision-making to the configured LLM model rather than hardcoded rules.
Core Features¶
- Automatic review of privilege escalation: Intercepts all tool calls with
sandbox_permissions, including Shell/PowerShell commands andwrite/editfile writes. - Dedicated reviewer role: Uses the built-in
REVIEWER_ROLE. This role has no tools and no session, quickly decides a single request, and does not borrow generic sub-agent templates from the environment. - Lightweight execution: Does not create an Agent or Session and does not pollute the sub-agent list. Each approval returns only a native
allowed-onceone-time authorization. - Visual panel: Provides a “Help Me Approve” panel at the top of the DSH Web session.
- History: Displays the most recent 100 approval records separately by session (including the request target, rationale, permissions, reviewer model, AI conclusion, and result).
- Settings: Visually adjust reviewer model parameters.
- Model configuration: Supports configuring the reviewer model’s Provider, Model, Timeout, and Max tokens.
Installation and Enablement¶
Run the following command in your DSH profile to install it:
dsh plugin --profile web add github:alaxrpg/dsh-llm-approve-for-me
After installation, restart DSH Web. The plugin automatically adds the “Help Me Approve” permission preset to the session (it can be overridden manually on the settings page). Click “Help Me Approve” at the top of the session to enter the approval panel.
Typical Usage¶
1. Configure the Reviewer Model¶
After installation and restart, go to the Settings page of the “Help Me Approve” panel. It is recommended to set the reviewer model to a fast non-reasoning model to improve response speed.
| Setting | Default | Range | Description |
|---|---|---|---|
| Reviewer provider | Empty (inherited from main session) | Any provider name | If left empty, it inherits the configuration of the session that made the request |
| Reviewer model | Empty (inherited from main session) | Any model name | It is recommended to point to a fast non-reasoning model |
| Timeout | 300 seconds | 1–600 seconds | The thinking time of reasoning models counts toward the timeout |
| Max tokens | 16384 | 256–65536 | Includes the reasoning process |
The saved configuration is written to ~/.dsh/llm-approve-for-me.settings.json and takes effect immediately without restarting.
2. Review Protocol¶
The plugin sends requests to the built-in role through the DSH llm service, requiring it to return strict JSON format:
{"decision":"allow","rationale":"原因"}
decision: Onlyallow,deny, oraskis supported.rationale: A one-sentence rationale must be output in Simplified Chinese.
Notes and Configuration¶
- Strict JSON format: The reviewer model must return standard JSON. If the output contains a Markdown code fence or a non-JSON response, the system automatically falls back to manual approval.
- Exception handling: If the review times out, is canceled, the model call fails, or the output is invalid, the system falls back to manual approval and records the specific reason (also in Chinese).
- Target extraction limitation: For requests where the review target cannot be extracted (such as some tools with escalation parameters), the system hands the request back to manual approval.
- Content truncation: Review summaries are automatically truncated to 2000 characters to prevent large files from flooding the output.
- Priority rule: The configuration file
~/.dsh/llm-approve-for-me.settings.has higher priority than static configuration. - Not a security product: This plugin is not a security product and cannot replace manual authorization, the principle of least privilege, data backup, or isolation measures. Its purpose is to delegate authorization decisions to an LLM, not to use it as a firewall.
Conclusion¶
dsh-llm-approve-for-me provides DeepSeek Harness users with an LLM-based sandbox permission review solution. By configuring and monitoring approval history, you can find a balance between automation and security. For more details, see its GitHub repository.