AI Agent Hub
Back to plugins
🖥️

dsh-risk-gate

Client Updated 2026.09.08

Run the following command in DeepSeek Harness:

dsh plugin install leetom314/dsh-risk-gate

Paste the following prompt into your AI chat to install this plugin:

Run dsh plugin install leetom314/dsh-risk-gate inside DeepSeek Harness to install this plugin; the source repository is available at https://github.com/leetom314/dsh-risk-gate

About this plugin

In DeepSeek Harness, tool calls have historically been all-or-nothing: either every invocation passes through or each one demands manual approval. dsh-risk-gate hooks into the pre-execute phase of every tool call and classifies it by operation semantics into three tiers. Reversible, read-only operations pass straight through; side-effectful but low-risk operations route to an approval seam; redline operations carry an explicit violation type and fail closed when no answerer is present. The entire pipeline runs locally and deterministically with no network call and no LLM invocation.

The plugin also ships with progressive authorization: once a signature (tool name plus normalized arguments) has been approved and succeeded N times in a row, subsequent identical calls are auto-allowed. A single failure or rejection resets the counter to zero and restores the approval requirement. The four redlines - remote state change, outbound message, deletion, and paid quota - are never auto-allowed by default. State lives in process memory and is cleared on hot-module dispose.

This plugin suits developers who want a safety gate around DeepSeek Harness without wrapping every call in a full sandbox: those who do not want to approve every command manually, yet also refuse to let an agent execute irreversible operations unsupervised. It is a gate, not a sandbox - pair it with dsh-permission-rules or sandboxed executors for defense in depth.

Use Cases

  • Auto-classify tool calls by operation semantics before execution to cut manual approvals
  • Fail-closed deny on redline ops in unattended environments to prevent accidental damage
  • Gradually auto-allow repeat successful low-risk ops to increase throughput

Best For

  • Developers adding a safety gate to their DeepSeek Harness setup
  • Engineering teams running unattended agent pipelines with irreversible ops
  • Individual users wanting baseline risk control without a full sandbox