TingRuDeng/dsh-smart-approval

TingRuDeng★ 0TypeScript最后同步: 2026-08-15

在 GitHub 打开

Fail-closed three-mode approval plugin for DeepSeek Harness

README 摘要

dsh-smart-approval English 中文 dsh-smart-approval is a fail-closed approval plugin for DeepSeek Harness. It separates access permission from automatic review: DSH continues to own Read Only, Workspace Write, and Full access, while this plugin adds an independent review selector beside Workspace Write . New sessions use smart approval by default. Changing review mode does not change the sandbox, and changing access permission does not change review mode. Both changes apply to the next approval request without restarting DSH. [!WARNING] This project and DSH are both in developer preview. Review the security boundaries below and pin exact versions in reproducible environments. Two independent selectors The Web composer should show two controls: - Access: Read Only, Workspace Write, and Full access, owned by DSH. - Automatic review: Manual approval, Smart approval, and Unattended, owned by this plugin. Review mode Safe request High-risk or uncertain Clearly malicious Manual approval Ask a human Ask a human Ask a human Smart approval (recommended default) Allow once Ask a human Reject Unattended Allow once Reject Reject Automatic review only handles requests that already enter DSH's appr…

在 GitHub 查看完整 README →
工具/开发dsh-plugin

分类