Bundle
dsh-auto-approve
Auto-approve mode for DeepSeek Harness: auto-grants approval requests (sandbox escalations, or everything) and adds an "自动审批" (auto-approve) option to the permission selector. Install with `dsh plugin --profile <name> add <path-or-package>`.
- Source
- Hanihahaha
- stars
- 1 stars
- License
- MIT
- Updated
- Updated yesterday
Readme
# dsh-auto-approve [中文](README.zh.md) A DeepSeek Harness plugin that adds an auto-approve permission mode and can automatically grant requests matching its sandbox-reason heuristic or all approval requests. ## Features - Adds an **Auto approve** permission preset that preserves the `workspace-write` boundary. - Provides `/auto-approve all|sandbox|off|status`. - Adds a session-header control that cycles between off, sandbox-matched, and all approvals. - Intercepts the `approval/request` waterfall and returns `allowed-once` for the selected mode. ## Install ```powershell # Install from the repository root. dsh plugin --profile web add ".\dsh-auto-approve" # Or, after publishing dsh plugin --profile web add dsh-auto-approve ``` Restart `dsh web` after installation. The permission selector then exposes the Auto approve preset and the command and header control become available. ## How It Works | Layer | Behavior | |---|---| | Permission preset | Extends `@deepseek-ai/dsh-permission-presets` with `auto-approve` using `workspace-write` plus `ask`. | | Approval handling | Intercepts `approval/request`; the preset grants all requests, while manual `sandbox` mode grants requests whose reason text contains `sandbox`, `all` grants every request, and `off` grants none. | DSH has `ask` and `never` policies but no native auto-approve policy. This plugin implements auto-approval by short-circuiting the waterfall. `never` means reject, not auto-approve. ## Security - `all` grants every approval request and is only suitable for trusted tasks. - Manual mode is process-local and returns to the default `sandbox` mode after restart. - The Auto approve preset remains constrained to `workspace-write`; requests outside the workspace still use escalation, although this plugin grants the resulting approval.
Install
dsh plugin --profile web add github:Hanihahaha/dsh-auto-approve#446f7fc97f958f16c46f66110f7be88e03692b51
Profile: web
With the hub plugin installed, ask your agent to install it by name — it resolves the same plan shown here.
dsh plugin --profile web add github:stvlynn/dsh.fish#path:packages/dsh-plugin-hub
install dsh-auto-approve from the hub