跳到主内容

dsh-user-approval 使用指南

为 dsh 提供用户审批接口 ctx.approval,实现工具执行和沙盒权限升级时的一次性授权决策,缺失审批者时默认拒绝,适用于需要人工确认的危险操作场景

本文为派生内容(基于 wiki / faq / compatibility_json 自动组装),非 AI 即时创作。

本文由本站基于该插件已收录的字段自动派生(wiki / faq / compatibility_json / readme),非 AI 即时创作。每节末尾标源字段。

快速上手

为 dsh 提供用户审批接口 ctx.approval,实现工具执行和沙盒权限升级时的一次性授权决策,缺失审批者时默认拒绝,适用于需要人工确认的危险操作场景

— 源: plugins.ai_summary

安装与验证

dsh plugin --profile web add npm:@deepseek-ai/dsh-user-approval

复制以上命令在 DSH Web Profile 内运行。安装完成后在「插件列表」启用即可。

— 源: plugins.install

关键要点

  • Requests are valid only inside an open turn — an idle or between-turn caller throws before auditing; a durable out-of-turn approval workflow is deferred.
  • Only one-shot grants exist — the outcome vocabulary has allowed-once but no allow-always, remembered rule, revocation, or grant store; session policy is only ask / never.
  • The request carries no tool arguments — an answerer sees the tool name, reason, and optional call id; the ACP machine channel requires a call id and delegates requests without one.
  • No built-in answerer — headless or incompletely composed deployments resolve unavailable and fail closed; the service itself never prompts a human.

— 源: plugin_wiki.readme_zh (fallback readme_raw)

踩坑提醒

安装前请审阅上游仓库;本指南基于已收录字段自动派生,可能滞后于最新版本。如发现与官方文档冲突,请以上游为准。

— 来源:通用规则