Andy8647/dsh-auto-approval ↗★ 3

dsh-auto-approval

Automode for DeepSeek Harness: a fourth permission preset that runs on full access with an LLM classifier as the only gate before every tool call 适合追求全自动运行、希望由AI自主判断工具调用安全性的用户。

Package
dsh-auto-approval
Compatibility
Unverified
Harness peer range
^0.1.2-rc.1
Cordis peer range
^4.0.2
Version
0.2.0
License
BSD-3-Clause
Last updated
Sep 9, 2026

Other repositories with this package name

Install

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:Andy8647/dsh-auto-approval

Configuration

$DSH_HOME/settings.yaml, hot-reloaded:

automode:
  denyPatterns:
    - 'rm\s+(-[a-z]*[fr][a-z]*\s+)*/\s*$'
    - 'curl\s+[^|]*\x7c\s*(ba)?sh'
  autoApproveTools: [read, write, edit, glob, grep, ls]
  bashCommandPrefixes: [ls, pwd, git status, git diff, pnpm test]
  classifierFastProvider: deepseek-official
  classifierFastModel: deepseek-v4-flash
  classifierDeepProvider: deepseek-official
  classifierDeepModel: deepseek-v4-pro
  classifierGuidance: 'Prefer allowing read-only and test commands.'

Every key is optional. denyPatterns / autoApproveTools / bashCommandPrefixes replace the defaults wholesale (YAML arrays do not merge), so restate the values you want to keep.

Without classifierFastProvider/classifierFastModel there is no L1, and automode fails closed: only trusted tools and allowlisted commands run, everything else is denied. That is deliberate — a session with no classifier is not a safety net, and silently allowing everything would make the gate a rubber stamp.