masquerator-coder/dsh-permission-gate ↗★ 1

dsh-permission-gate

A DeepSeek Harness (DSH) plugin that adds an AI-adjudicated 'smart' approval mode: safe operations are auto-allowed via an isolated side-channel LLM judge, everything else falls back to the normal human approval popup. 适合希望减少审批弹窗、又保留人工兜底的用户。

パッケージ
dsh-permission-gate
互換性
未検証
Harness ピア範囲
>=0.1.0-rc.8 <0.2.0
Cordis ピア範囲
^4.0.2
バージョン
0.1.0
最終更新
2026/09/08

同名パッケージの別リポジトリ

インストール

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:masquerator-coder/dsh-permission-gate

ドキュメント

README 全文を読む ↗

Configuration

All keys are Schemastery-validated and changeable from cordis.yml/--patch. Example:

- insert:
    - id: permission-gate
      name: dsh-permission-gate
      config:
        provider: deepseek      # explicit provider route; must pair with model.
        model: deepseek-chat    # explicit judge model.
        judgeTimeoutMs: 15000   # deadline for one judge call before falling back to human.
        maxTokens: 256          # judge output-token cap.
        minConfidence: 0.85     # min confidence for an allow to auto-release.
        # Optional override of the built-in safety-adjudication system prompt.
        systemPrompt: "..."
        # Deterministic-danger rules evaluated before any LLM call. A match → human.
        dangerRules:
          - label: secrets
            patterns: ["ssh", ".env", "api.key"]
          - label: destructive
            patterns: ["rm -rf", "format "]
  • provider / model: if omitted, the judge uses the session's last logged model route (request/header). If neither an explicit pair nor a logged route is available, the request is treated as an internal-exception fallback (human decides) — fail-safe.
  • dangerRules: substring patterns, case-insensitive, matched against toolName and reason. Set to [] to disable the local gate entirely.