Introduction¶
The core of DeepSeek Harness (DSH) is workflow orchestration and agent collaboration. When building automated processes, the approval step for tool calls often consumes considerable development effort. If each instruction requires manual confirmation, efficiency is greatly reduced; if all calls are allowed, security risks may arise. The dnalec/dsh-auto-approve plugin provides an automated solution between security and efficiency by using keyword matching and judge model evaluation.
Plugin Positioning¶
This is a DeepSeek Harness auto-approval plugin. It uses keyword matching and a judge model to classify tool calls and determine risk levels, then automatically allows or denies operations, and only routes uncertain cases to manual review.
Maintainer: DNAlec
License: MIT
GitHub: https://github.com/DNAlec/dsh-auto-approve
Core Features¶
The plugin provides the following capabilities:
- Keyword matching: Supports matching tool names, commands, paths, and parameters of custom tools (MCP), with deny, manual, and allow tiers.
- Judge model classification and risk assessment: Uses a judge model to classify calls and output risk levels (low/medium/high).
- Configurable risk levels: For each category, you can configure the action policy for low, medium, and high risk levels.
- Parameter interception: Unrecognized parameters automatically trigger a deny action.
- Request limiting and budget management: Supports configuring request limits and output token budgets for the judge model (default is 8192 tokens).
- Model-initiated manual review: Supports the model attaching a reason when automatically denying and triggering the manual review channel.
- Tool extension support: Supports configuring custom tools.
Installation and Activation¶
Installing this plugin requires the DeepSeek Harness plugin command. After installation, restart the web service for the configuration to take effect.
- Run the installation command:
dsh plugin --profile web add github:DNAlec/dsh-auto-approve
-
Restart the
dsh webservice. -
Enable “Auto-approve” mode in Settings. Typically, choose
workspace-writemode (skips approval for writes inside the workspace) orread-onlymode (determination is made by the judge model).
Typical Usage¶
Configuring this plugin usually involves the following steps:
-
Configure keywords:
Configure tool names, commands, or paths in the keyword settings. Three tiers are supported:
* Deny: Calls matching the keyword are blocked directly.
* Manual: Calls matching the keyword are sent to the manual review dialog.
* Allow: Calls matching the keyword pass automatically. Note that allow keywords match tool names or paths, not workspace directories, so this method cannot be used to allowbashorwritetools. -
Configure the judgment table:
Configure the actions corresponding to risk levels (low/medium/high) in the judgment table. Each row represents a category and contains a description and three cells. Theotherrow in the table cannot be deleted; it is used to handle unresolved output, but inputs that cannot be parsed always require manual review. -
Configure judge model limits:
In the Judge model settings card, configure request limits and output budget. The default output budget is 8192 tokens; routes without configured reasoning default to 256.
Notes¶
- Restart required for changes to take effect: After every configuration change or plugin installation, you must restart
dsh web. - Keyword matching scope: Keywords only match tool names, commands, paths, and custom tool parameters; they do not match content, code bodies, or numeric/boolean toggles (such as
{recursive:true}). - Parameter capture: Inputs that cannot be parsed always trigger manual review.
- Configuration meaning:
maxTokensis an output limit, not a reserved quota; limits that are too low may cause judging failures. - Check after upgrades: After upgrading the plugin, it is recommended to recheck the default settings and fallback levels, because version changes may affect default behavior.
References¶
- Plugin catalog: https://www.skillhub.cn/plugins/DNAlec/dsh-auto-approve
- GitHub repository: https://github.com/DNAlec/dsh-auto-approve