dsh-admin-bridge
Run the following command in DeepSeek Harness:
dsh plugin install zjlww/dsh-admin-bridge
Paste the following prompt into your AI chat to install this plugin:
Run dsh plugin install zjlww/dsh-admin-bridge in DeepSeek Harness to install this plugin; source is available at https://github.com/zjlww/dsh-admin-bridge
About this plugin
DSH's permission system has long stopped at three tiers: Read Only, Workspace Write, and Full access. When an agent needs to perform system-level tasks—restarting services, tweaking kernel parameters, managing user accounts—Full access still falls one step short, and the user has to drop back into a terminal and type sudo by hand. dsh-admin-bridge inserts a fourth mode, Sudo access, into the composer selector so that agents can make a request while the actual gate remains in human hands: a fresh password entry, a session-scoped temporary grant, and automatic revocation on expiry.
The core flow is deliberately minimal. The agent calls admin_request to open a GUI dialog; the user reviews the command scope and duration, then types the password into a dedicated input field. The credential travels only through same-origin HTTP and a private sudo pipe—never through chat, model context, argv, or persistent storage. Once authenticated, admin_run can execute arbitrary Bash commands as root; the capability lapses on timeout, mode switch, or worker failure. Delegated sub-agents cannot request, enter, or inherit this mode, and a request never equals permission.
It is built for developers and operations engineers running DSH Web on a trusted single-user Linux host who genuinely need their agent to reach into root-level operations. It does not replace a sandbox, does not alter DSH's native approval policy, and does not store passwords or run a persistent root daemon—it simply embeds the agent-requests, human-approves, temporary-grant, auto-revoke security chain into the existing interface.
Use Cases
- Agent needs to restart system services or tweak kernel parameters
- Deployment scripts require root-level configuration changes
- Debugging system issues where the agent must temporarily read restricted files
Best For
- Developers running DSH Web on a trusted single-user Linux host
- Ops engineers whose agents need root-level operations
- Security-sensitive teams that value human-gated approval flows
Related Plugins
A network security red-team benchmark plugin for DeepSeek-V4.1/Flash featuring dual-layer kernel injection and zero-tool architecture for controlled model safety assessment.
A security red-team prompt plugin for DeepSeek-V4 that uses code-formal mapping and zero-trigger system prompts to enable unconditional output, intended for authorized testing and research only.
Adds an Auto approval mode on the official workspace-write sandbox, classifying semantic risks, asking when ambiguous, and denying destructive operations.
Undo/rollback system for DSH: config & plugin snapshots, one-click undo/redo/restore, message-level revert, secret masking, safe mode, and offline WebUI/GUI/CLI rescue tools for when DSH won't start.