Skip to main content

dsh-approval-llm

7Stars0Forks1Issues0Watchers

Add "Help Me Approve" permission mode to DSH, replacing manual approval with an independent review model; other mode behaviors remain unchanged.

Evidence4/5methodologySourceInstallMaintenanceDSH versionSecurity scan
Machine-auditedInstall commandRepo verifieddsh-plugin topicLicenseREADMEAI wiki
Language
TypeScript
Branch
main
dsh-plugin

Install

cmdweb profile
$ dsh plugin --profile web add dsh-approval-llm

Run the command above in your terminal to install this plugin via the dsh CLI. You can switch Profile in the top-right corner. New to dsh? Read the beginner tutorial

Install via your agent

Install the DeepSeek Harness plugin Letter2025/dsh-approval-llm for me: review the repository at https://github.com/Letter2025/dsh-approval-llm first, then run the install command and verify the plugin loads successfully.

Paste this instruction to the DSH Web GUI assistant — it will install and verify for you.

One-Line Description

This plugin adds an "Auto-Approve" permission mode to DeepSeek Harness: in this mode, an independent review model replaces human judgment for approval/request, providing a three-value decision of ALLOW / DENY / ESCALATE; in other permission modes the plugin remains completely silent, and the human approval process is unaffected.

Core Capabilities

  • In model-approval permission mode, the review model automatically determines approval/request, giving pass, reject, or escalate-to-human decisions
  • Before decision-making, deterministic routing is performed via whitelist, blacklist, and human-only lists; matched requests skip model invocation
  • On model timeout, parsing errors, or upstream failures, always escalate to human (fail-to-human), not counted toward consecutive denial circuit breaking
  • After consecutive denials reach the threshold in a single session, automatically route subsequent requests back to human; the review model stops acting as judge
  • During review, replay tool real parameters from session logs to avoid being misled by agent self-reports
  • Bundled with configure-approval-llm skill; AI can write review configuration following a "suggest first, then confirm" workflow

Technical Implementation

  • Language: TypeScript (ESM, strict mode tsconfig)
  • Key Dependencies: @deepseek-ai/dsh-user-approval (approval outcome vocabulary), @deepseek-ai/dsh-permission-presets (preset services), @deepseek-ai/dsh-llm (streaming review calls), @deepseek-ai/schemastery (config schema validation)
  • Architecture Pattern: cordis plugin, registered via inject = ['llm','tools','permissionPresets','skills'] and listens to approval/request events, processing via "deterministic routing → circuit breaking → review model" waterfall; inserts plugin line and model-approval preset via package.json#dsh.bundle.patch
  • Entry File: src/index.ts (apply(ctx, rawConfig))

Use Cases

Developers who want to implement low-risk automation workflows like "let model review first, escalate to human when uncertain" in DSH. Suitable for scenarios requiring models to continuously execute autonomously in workspace-write mode while still retaining human oversight for high-risk tools like delete, terminal commands, job_kill; not suitable for unattended high-risk tasks.

Prerequisites & Compatibility

DependencyMin VersionDescription
@deepseek-ai/dsh-agent^0.1.0-rc.7Host Agent, peerDependencies
@deepseek-ai/dsh-llm^0.1.0-rc.7LLM streaming interface and BlockAssembler
@deepseek-ai/dsh-user-approval^0.1.0-rc.7Approval outcome vocabulary (allowed-once / rejected)
@deepseek-ai/dsh-permission-presets^0.1.0-rc.7Preset service (model-approval preset injected here)
@deepseek-ai/dsh-session^0.1.0-rc.7Session log replay tool parameters and conversation routing
@deepseek-ai/dsh-skill^0.1.0-rc.7Bundled configure-approval-llm skill registration
@deepseek-ai/dsh-tools^0.1.0-rc.7Tool registry (fetch tool descriptions in real-time)
@deepseek-ai/dsh-timeout^0.1.0-rc.7Review request timeout management
Node VersionNot Declaredpackage.json does not declare engines
PlatformCross-Platformpackage.json does not declare os / cpu limits
Native ModulesNoneNo native module dependencies

Installation

dsh plugin --profile web add github:Letter2025/dsh-approval-llm

Configuration Options

ConfigTypeDescriptionDefault
enabledBooleanMaster switch; when disabled, all requests pass through to the next answerer (human approval) as-istrue
modePresetStringPermission preset name that triggers the review model; only intervenes when current session's preset matches; set to empty string to review all requests"model-approval"
providerStringProvider used by review model; must appear in pair with model; if not set, falls back to conversation routing in sessionNot set
modelStringReview model id; must appear in pair with providerNot set
timeoutMsNumberEnd-to-end timeout for review requests (ms); escalates to human on timeout, not counted toward circuit breaking60000
maxOutputTokensNumberMaximum output tokens for review model256
systemPromptStringCustom security policy; if empty, uses built-in "default allow, reject only critical harm" short rulesBuilt-in policy
allowlistString ArrayTool names that are directly allowed when matched (skip model)[]
denyListString ArrayTool names that are directly rejected when matched, higher priority than allowlist[]
humanOnlyListString ArrayTool names that must be decided by human, never auto-reviewed[]
maxConsecutiveDenialsNumberUpper limit for consecutive denials in single session; exceeds limit, session escalates to human; set to 0 to disable circuit breaking3
maxArgsCharsNumberCharacter limit for tool arguments JSON rendered to review model4000
includeArgsBooleanWhether to include tool parameters in review model request; can be disabled when parameters are sensitivetrue
notifyUserBooleanWhether to append a user-visible decision message to session after each model allow/rejecttrue

FAQ

Q: Can it work without configuring provider/model?

A: Yes. When not set, it falls back to the conversation routing from the last request/header in the session; if there's also no routing in session logs, review fails and escalates to human, it won't fake a decision.

Q: Does human approval stop working after installing?

A: No. The plugin only responds under the model-approval preset; other presets (including the default 请求批准) still go through the original human approval, behavior is identical to before the plugin was installed.

Q: What happens when the review model says "uncertain" or crashes?

A: Always escalate to human: timeout, parsing errors, upstream errors all produce ESCALATE and pass the request to the next answerer; these failures are not counted toward consecutive denial circuit breaking to avoid misinterpreting model failures as "repeated rejections".

Q: I'm worried the model might be fooled by tool outputs. What to do?

A: This is a known risk. Suggest tightening humanOnlyList (high-risk tools requiring human), denyList (blacklist), maxConsecutiveDenials (circuit breaking threshold), and avoid enabling in unattended high-risk scenarios.

Q: How to configure the review model after installation?

A: Have any agent load the configure-approval-llm skill or say "configure approval review model" to it; it will follow an AI-suggests-then-you-confirm workflow to write the approval-llm line into ~/.dsh/profiles/web/cordis.patch.yml, restart dsh web to take effect.

Q: How to uninstall?

A: Remove via the host DSH's plugin removal command and restart dsh web; the model-approval preset declared by the plugin is injected via bundle patch, after uninstall the preset will disappear.

Difficulty Level

Advanced — requires understanding DSH's permission presets, cordis patch mechanism, and model selection for review; built-in configure-approval-llm skill can reduce configuration work, but strategy tuning for whitelist/blacklist/circuit breaking still requires deployer judgment.

Known Issues & Limitations

  • No dedicated machine-readable audit event type yet: review decisions appear as user/message in the main pipeline and can be persisted/replayed; waiting for host to open custom event registration channel before adding session/approval-llm-request events
  • Client badge not provided yet (browser half): review decisions displayed as conversation messages, not as shield icon on tool cards
  • One request equals one model call: batch review (PLAN-0063) requires approval service to first open batch entry; single request latency constrained by timeoutMs and selected review model speed
  • Review model may be prompt-injected by tool outputs: configure humanOnlyList / denyList / circuit breaking parameters well, do not enable in unattended high-risk scenarios
  • Lists only exact name matching: allowlist / denyList / humanOnlyList do not support wildcards or parameter pattern matching

Read the usage guide →

Install steps, key points, FAQ and compatibility for this plugin — auto-derived from indexed fields.

Listing badge

Listed on deepseek-plugin.org
[![Listed on deepseek-plugin.org](https://img.shields.io/badge/listed_on-deepseek--plugin.org-007EC6)](https://deepseek-plugin.org/plugins/Letter2025/dsh-approval-llm)

Paste this markdown into your GitHub README to link back to this listing. The badge only states the listing — not a security endorsement.

← Back to plugin directory