Andy8647/dsh-auto-approval ↗★ 3
dsh-auto-approval
Automode for DeepSeek Harness: a fourth permission preset that runs on full access with an LLM classifier as the only gate before every tool call 适合追求全自动运行、希望由AI自主判断工具调用安全性的用户。
같은 패키지 이름의 다른 저장소
설치
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:Andy8647/dsh-auto-approvalConfiguration
$DSH_HOME/settings.yaml, hot-reloaded:
automode:
denyPatterns:
- 'rm\s+(-[a-z]*[fr][a-z]*\s+)*/\s*$'
- 'curl\s+[^|]*\x7c\s*(ba)?sh'
autoApproveTools: [read, write, edit, glob, grep, ls]
bashCommandPrefixes: [ls, pwd, git status, git diff, pnpm test]
classifierFastProvider: deepseek-official
classifierFastModel: deepseek-v4-flash
classifierDeepProvider: deepseek-official
classifierDeepModel: deepseek-v4-pro
classifierGuidance: 'Prefer allowing read-only and test commands.'
Every key is optional. denyPatterns / autoApproveTools / bashCommandPrefixes replace the defaults wholesale (YAML arrays do not merge), so restate the values you want to keep.
Without classifierFastProvider/classifierFastModel there is no L1, and automode fails closed: only trusted tools and allowlisted commands run, everything else is denied. That is deliberate — a session with no classifier is not a safety net, and silently allowing everything would make the gate a rubber stamp.