Introduction¶
In DeepSeek Harness (DSH), when a sandbox policy rejects a write operation, the model usually has to make a second call, including sandbox_permissions and justification in the request, before the user can see the approval card. This mechanism wastes turns and forces the model to repeat tool-calling logic.
The dsh-approval-first plugin uses a shadow tool mechanism to present an approval card directly to the user before the sandbox policy rejects the write. This allows the model to avoid repeating the tool call and lets the user review the request when they first see it.
Plugin Overview¶
Positioning: A DeepSeek Harness (DSH) plugin for implementing “approve before edit/write” security controls.
Maintainer: joao-paulo-santos
Core Value: Intercepts model intent and introduces human review before the policy allows an operation, reducing invalid model retries and providing a clearer review target (a diff instead of model-generated prose).
Core Features¶
-
Shadow Tool Interception
The plugin uses a shadow tool to add an approval step before the model repeats a call. If the model attempts a mutation that would be rejected by the current sandbox policy, the system presents the approval card first instead of requiring the model to send a second call withsandbox_permissions. -
Silent vs. Approval-Card Distinction
- Writes within the policy: remain silent and behave consistently with DSH native tools.
- Targets outside the policy: receive an approval card, giving the user their first view of the request.
-
“Read First” Gate
The system checks the “read first” gate. If the exposededittool would reject a file that has never been read (for example,edit requires reading "..." first), the plugin automatically steps back, allowing the model to follow the native path and receive the harness’s error message directly, avoiding wasted approval cards. -
Drift Detector
Because shadow tools operate based on frozen copies, the plugin performs validation at startup. If a DSH update causes the underlyingeditorwritetool definitions to change, the drift detector refuses to start the plugin, preventing stale behavior.
Installation and Activation¶
The plugin must be installed from a DeepSeek Harness checkout directory and with a specified profile (for example, web).
- Clone the repository:
git clone https://github.com/joao-paulo-santos/dsh-approval-first
- Install the plugin from the Harness checkout directory:
pnpm dsh plugin --profile web add /path/to/dsh-approval-first
- Verify that the configuration was resolved successfully:
pnpm dsh --profile web --dump-config
After installation, the plugin activates automatically and does not require additional configuration files. It applies to any session whose mode is not danger-full-access.
How It Works¶
- Registration Behavior: Shadow tools are registered at the agent level and follow the session’s current mode. When the mode changes mid-session (for example, from
read-onlytoworkspace-write), the shadow tools take effect or deactivate immediately. - Review Target: The review target shown on the approval card is a diff, not a model-generated text description.
- Rejection Handling: If the user rejects approval, the result is a normal rejection outcome (
edit rejected by the user; file unchanged), not a red error.
Use Cases and Notes¶
Use Cases:
* When model write operations to the file system require strict review under sandbox restrictions.
* When you want user approval during the first write attempt, instead of waiting for the model to retry.
Notes:
1. Transitional Stub: The plugin is currently a transitional stub and is expected to be replaced by a native single-turn escalation mechanism in DSH in the future.
2. Scope: It only affects the edit and write tools. Bash commands retain their classic escalation path.
3. Plugin Conflicts: If another plugin has already shadowed the edit or write tool for an agent, that agent is skipped to avoid shadow tool conflicts.
4. Activation Condition: The plugin requires the profile’s default mode to be different from danger-full-access; otherwise, it will not activate.
5. License: MIT License.
Summary¶
dsh-approval-first introduces a shadow tool mechanism into the DSH ecosystem, optimizing the approval process in restricted sandbox environments. It reduces unnecessary model retries, focuses the review target on code diffs, and provides protection when the underlying tool definitions used by the plugin change.