dsh-auto-pass
提供基于模型审查的自动审批预设及日志面板 适合需要对智能体操作进行安全审查与自动授权过滤的用户。
安裝
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:sujingkpo/dsh-auto-pass說明文件
閱讀完整 README ↗Configuration
Below are the keys from the bundled cordis.patch.yml that belong in a config file; every key except the reviewer pair is optional, and the values shown are the plugin's defaults. The remaining preferences are changed in the UI (see the end of this section).
- id: dsh-auto-pass
name: dsh-auto-pass
config:
language: auto
reviewerProvider: deepseek-official
reviewerModel: deepseek-v4-flash
reviewerReasoningEffort: high
timeoutMs: 90000
maxEvidenceChars: 400
maxActionChars: 16000
maxOutputTokens: 2048
logFile: ''
maxRecords: 1000
policyFile: ''
Key reference
language— the language of the review:auto(default) counts Han characters in the messages you send (four or more selects Chinese, otherwise English; agent instructions, assistant messages and tool results do not count), or pin it withzh/en. An invalid value only warns and falls back toauto. The security policy text is one Chinese prompt in both modes, so translation never changes review semantics.reviewerProvider/reviewerModel— which provider and model run the review; they must be set together. With both omitted the Reviewer uses the parent session's current provider and model, and a review with no route at all is handed to the user.reviewerReasoningEffort— the reasoning effort handed to the review model (for examplehigh); it must be a non-empty string, and leaving it out uses the model's own default.timeoutMs— the deadline for one review in milliseconds (90000 by default), covering that single model call including streaming; a timeout hands the request to the user.maxEvidenceChars— how much evidence is kept (your last direct message and the most recentask_user_questionanswer), each truncated to this many characters, 400 by default.maxActionChars— the character cap on the normalized action JSON (16000 by default); a longer action is handed to the user without calling the model.maxOutputTokens— the token cap on the review reply (2048 by default).logFile— the approval-record file; empty means one file per workspace ($DSH_HOME/dsh-auto-pass/records/.json), while an explicit path falls back to single-file mode (every workspace in one file, useful for debugging).maxRecords— how many records are kept per workspace, 1000 by default.policyFile— the global policy file (thresholds and global lists only); empty means$DSH_HOME/dsh-auto-pass/policy.json. Consecutive counters live elsewhere, one file per workspace ($DSH_HOME/dsh-auto-pass/counters/.json, same slug scheme as the approval records; no cwd meansunknown.json). Each counter file holds at most 500 entries: past the cap the least recently used active entries are evicted first anddismissedentries last, while entries with both sides at zero that were never dismissed are dropped at startup. Upgrading splits thecwd-prefixed counters of an older global file into those files, removing them from the global file only after every write succeeded.
Numeric keys must be positive integers and logFile / policyFile must be strings — a wrong type fails plugin load outright, and setting only one of reviewerProvider / reviewerModel does too.
A few more keys belong in the UI: placement, notice, denyDirect, autoOpenTimeline, askRejectReason (the four behaviour switches) and autoApproveAfter / autoDenyAfter (the default consecutive-approval / consecutive-denial thresholds). They do not have to be written into a config file; when they are, the settings value still wins, and a threshold changed in the panel is stored in the policy file.
notice (default true) controls whether the approval result line is injected into the model context; denyDirect (default false) controls whether a denylist hit rejects the call outright; autoOpenTimeline (default true) controls whether an approval opens the timeline automatically whenever it is not already on screen; askRejectReason (default true) controls whether rejecting an approval asks you for a reason (the first option is that review's model note, one click away; you can also type your own or pick "No comment"), and the reason you give is injected as its own line even when notice is off — the two switches are independent. All four can be changed from the settings card or the "Approval policy" panel, and the settings value wins over these defaults. Because they are read on every approval, a change applies immediately with no restart.
A profile override replaces the complete matching bundle-row config, so repeat every value that should remain configured.
The Reviewer's system prompt is prompts/review.md and the match-condition prompt used for rule suggestions is prompts/rule.md; both are plain Markdown, read when the plugin loads. Restart DSH after changing the configuration, policy, or plugin code.