AI Agent Hub
Back to plugins
🧩

dsh-admin-bridge

admin-security Updated 2026.09.06

Run the following command in DeepSeek Harness:

dsh plugin install zjlww/dsh-admin-bridge

Paste the following prompt into your AI chat to install this plugin:

Run dsh plugin install zjlww/dsh-admin-bridge in DeepSeek Harness to install this plugin; source is available at https://github.com/zjlww/dsh-admin-bridge

About this plugin

DSH's permission system has long stopped at three tiers: Read Only, Workspace Write, and Full access. When an agent needs to perform system-level tasks—restarting services, tweaking kernel parameters, managing user accounts—Full access still falls one step short, and the user has to drop back into a terminal and type sudo by hand. dsh-admin-bridge inserts a fourth mode, Sudo access, into the composer selector so that agents can make a request while the actual gate remains in human hands: a fresh password entry, a session-scoped temporary grant, and automatic revocation on expiry.

The core flow is deliberately minimal. The agent calls admin_request to open a GUI dialog; the user reviews the command scope and duration, then types the password into a dedicated input field. The credential travels only through same-origin HTTP and a private sudo pipe—never through chat, model context, argv, or persistent storage. Once authenticated, admin_run can execute arbitrary Bash commands as root; the capability lapses on timeout, mode switch, or worker failure. Delegated sub-agents cannot request, enter, or inherit this mode, and a request never equals permission.

It is built for developers and operations engineers running DSH Web on a trusted single-user Linux host who genuinely need their agent to reach into root-level operations. It does not replace a sandbox, does not alter DSH's native approval policy, and does not store passwords or run a persistent root daemon—it simply embeds the agent-requests, human-approves, temporary-grant, auto-revoke security chain into the existing interface.

Use Cases

  • Agent needs to restart system services or tweak kernel parameters
  • Deployment scripts require root-level configuration changes
  • Debugging system issues where the agent must temporarily read restricted files

Best For

  • Developers running DSH Web on a trusted single-user Linux host
  • Ops engineers whose agents need root-level operations
  • Security-sensitive teams that value human-gated approval flows