dsh-approval-gate: An Automatic Approval Gate Plugin for DeepSeek Harness
moon09300731/dsh-approval-gate
DSH plugin approval gate: Flash predicts sandbox escapes, auto-approves safe actions, escalates risky ones to human review, with confirmation-based learning and UI review.
dsh-approval-gate is an automatic approval gate plugin for DeepSeek Harness, providing a safe release mechanism with minimal human intervention for sandbox escape operations. It uses the Flash model to pre-judge each escape, auto-approving routine operations while forcing irreversible ones—delete, credentials, remote, system paths, batch—to human confirmation, ensuring fail-safe. The plugin also offers confirmation-based learning, semantic similarity validation, hot-reload configuration, a human review UI, and file diff with revert, keeping human oversight over high-risk AI actions.
How to Install
dsh plugin --profile web add dsh-approval-gate- Category
- Workflow & Automation
- Platform
- DSH Plugin
- Author
- moon09300731
- Distribution
- Plugin
dsh-approval-gate Key Features
dsh-approval-gate Repo Summary
What Does It Do?
dsh-approval-gate is a DSH plugin for DeepSeek Harness that provides an automatic approval gate for sandbox escape operations, ensuring minimal human intervention while keeping high-risk actions safe. It solves the problem of AI executing dangerous operations without human oversight by using Flash model to pre-judge each escape: routine operations are auto-approved, while irreversible ones (delete, credentials, remote/production, system paths, batch) are always routed to human confirmation (fail-safe). Core capabilities include risk prediction, confirmation-based learning, semantic similarity validation, hot-reload configuration, human review UI, and file diff with revert.
Core Features
- Flash risk pre-judgment: each sandbox escape is classified as SAFE or RISKY, with reversible operations auto-approved.
- Hard risks always require human: delete, credentials, remote/production, system paths, and batch operations are always routed to human, not counted or learned.
- Confirmation-based learning: after N-1 confirmations, the same operation is auto-approved; learned rules carry operation fingerprints, only approving operations you confirmed.
- Semantic similarity validation: operations with different wording but same intent are judged by Flash against your confirmed samples, not keywords.
- Hot-reload configuration: changes to allowlist.json take effect immediately without restart.
- Human review UI: green indicator appears above input on auto-approval; approval view shows full timeline of approvals.
- File diff and revert (v0.5.0+): files involved in approvals can be viewed as unified diff, with one-click revert.
- Session-level snapshot management (v0.5.0+): snapshots are attributed to sessions, cleanup supports only current session or all sessions.
How to Use This Plugin?
After enabling it in DSH, first configure the permission preset in the settings page under 'Auto Approval' section, which writes the auto-approve preset to cordis.patch.yml. Then restart dsh web, and finally select 'Auto Approval (Flash)' in the session permission dropdown. From then on, every sandbox escape goes through the pipeline: DENY → allowlist → denyRules → Flash → learning. On auto-approval, a green indicator appears above the input; for human review, check the approval view for the timeline, click files to see diffs and revert changes.
This page is an independent rewrite of the plugin's official README — for authoritative documentation and the latest changes, refer to the source: moon09300731/dsh-approval-gate. The plugin is third-party code that runs on your machine once installed; inclusion does not imply endorsement — please review the source before installing.
