DeepSeek Harness Plugin

ilharp/dsh-tool-approval

Stars ★ 1 Downloads (30d) 511 Category Security & Permissions Added 2026-08-13 npm dsh-tool-approval

Manual approval mode ("Manual Mode" / "Ask Mode").

Install

# from npm (prebuilt)

dsh plugin --profile web add dsh-tool-approval

# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)

dsh plugin --profile web add github:ilharp/dsh-tool-approval

Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).

README

English | 中文

Add pre-approval to any Tool Calling, aka "Manual Mode"/"Ask Mode".

Install

dsh plugin --profile web add dsh-tool-approval

Config

Default config

- id: tool-approval
  name: dsh-tool-approval

With the default config, every Tool Calling goes through pre-approval.

Custom config

- id: tool-approval
  name: dsh-tool-approval
  config:
    include: [fs_*, web_*]
    exclude: [task_output]
    reason: tool execution requires your approval

Only tools specified in include get pre-approval; tools in exclude pass through. Wildcards are supported.

LICENSE

BSD 3-Clause

Content from the project README on GitHub ↗

Links

More in this category

View the whole category →

Community comments

Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.