Preface

In the development of DeepSeek Harness (DSH), a security safeguard is required when an Agent performs high-risk operations, such as deleting files, shutting down the system, or formatting disks. Traditional software-level authorization methods (such as dialog prompts or command-line input) may be intercepted by keyloggers or simulated by remote control.

The dsh-gamepad-approval plugin introduces a hardware-level confirmation mechanism. It uses an Xbox controller (XInput protocol) to convert Agent tool-call requests into physical actions, ensuring that only the person holding the controller can approve or reject high-risk commands.

What Is This

This is a DSH plugin maintained by goldgish and belongs to the admin-security category. Its core purpose is to require physical button confirmation (press A to approve / press B to reject) when an Agent attempts high-risk operations, thereby blocking malicious execution by automated scripts or remote attacks.

Features

  1. Physical button approval: When an Agent triggers a high-risk operation, the controller vibrates, and the user must press the A button to approve or the B button to reject.
  2. Hardware-level interaction: Based on the XInput protocol, the signal comes directly from the hardware layer and does not pass through the browser or keyboard drivers, so it cannot be simulated in software.
  3. Built-in permission rules: Includes 18 built-in permission rules covering common high-risk operations, including file deletion, system shutdown, disk formatting, destructive Git actions, and global installation scripts.
  4. Fail-closed policy: If no controller is connected, the operation times out, or input cannot be read, the system automatically rejects the operation and does not perform any risky action.
  5. Configurable: Supports configuring the timeout duration (timeoutSeconds) and the minimum risk level that triggers approval (minRiskLevel).

Installation and Activation

Run the following command in the DSH environment to install the plugin:

dsh plugin --profile default add dsh-gamepad-approval

After installation, it takes effect without additional configuration.

Usage

When an Agent encounters a high-risk operation that matches a permission rule, the process is as follows:

  1. Trigger: The Agent initiates a tool call.
  2. Confirmation: The controller vibrates twice.
  3. Decision: The user presses the A button to allow the operation or the B button to reject it.

If no controller is connected or the operation times out, the operation is automatically rejected.

Notes

  • Platform limitation: Only the Windows platform is supported.
  • Dependency: Depends on @deepseek-ai/schemastery.
  • Physical requirement: This plugin relies on physical button input and is designed to prevent keyloggers or remote-control simulation.

References