Andy8647/dsh-auto-approval ↗★ 3

dsh-auto-approval

在工具调用前通过大模型分类器进行自动审批 适合追求全自动运行、希望由AI自主判断工具调用安全性的用户。

包名
dsh-auto-approval
兼容性
待验证
Harness 依赖范围
^0.1.2-rc.1
Cordis 依赖范围
^4.0.2
版本
0.2.0
许可证
BSD-3-Clause
最近更新
2026年9月9日

同名包的其他仓库

安装

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:Andy8647/dsh-auto-approval

Configuration

$DSH_HOME/settings.yaml, hot-reloaded:

automode:
  denyPatterns:
    - 'rm\s+(-[a-z]*[fr][a-z]*\s+)*/\s*$'
    - 'curl\s+[^|]*\x7c\s*(ba)?sh'
  autoApproveTools: [read, write, edit, glob, grep, ls]
  bashCommandPrefixes: [ls, pwd, git status, git diff, pnpm test]
  classifierFastProvider: deepseek-official
  classifierFastModel: deepseek-v4-flash
  classifierDeepProvider: deepseek-official
  classifierDeepModel: deepseek-v4-pro
  classifierGuidance: 'Prefer allowing read-only and test commands.'

Every key is optional. denyPatterns / autoApproveTools / bashCommandPrefixes replace the defaults wholesale (YAML arrays do not merge), so restate the values you want to keep.

Without classifierFastProvider/classifierFastModel there is no L1, and automode fails closed: only trusted tools and allowlisted commands run, everything else is denied. That is deliberate — a session with no classifier is not a safety net, and silently allowing everything would make the gate a rubber stamp.