dsh-approval-autofocus
Manifest valid★ 1Automatically moves focus into the card when the approval card appears; press Enter to approve or Esc to reject (DSH Web / Desktop client plugin).
dsh-approval-autofocus
Make Enter approve a pending DSH approval, without clicking the card first.
A tiny, dependency-free client plugin for DeepSeek Harness (DSH) Web / Desktop profiles. Once an approval card appears, focus is already inside it, so:
Enter→ Allow onceEsc→ Reject
The problem it fixes
DSH's approval card (@deepseek-ai/dsh-client-ui-approval) does bind Enter/Escape — but only when the card already contains document.activeElement:
if (event.defaultPrevented || !event.currentTarget.contains(document.activeElement) || ...) return;
The card is rendered as a composer takeover: the composer it replaces is hidden with display:none, so the browser drops focus back to <body>, and the card never focuses itself. A plain Enter therefore lands nowhere — you have to click the card's text once before the documented "Enter approves / Esc rejects" actually works.
Without this plugin: click anywhere on the card's text, then press Enter.
What it does
It watches the DOM and, as soon as an approval card appears, moves focus into the card's detail area — but only when nothing else owns the focus:
| Current focus | Behavior |
|---|---|
<body>, or lost to the composer takeover | focus moves into the card |
| terminal, dialog, any input / contenteditable | left alone — focus is never stolen |
The card's own behavior is untouched: the Reject button, Esc, IME composition handling and the pending-request lock all still work exactly as shipped.
Safety notes
Approval is a security decision, and this plugin deliberately makes it a one-keystroke action — worth knowing what that means:
- The plugin only moves focus. It never presses keys and never approves anything;
Enterstill has to come from you. - It only takes focus when focus is otherwise idle (
<body>or the hidden composer). While you are typing in a terminal, a dialog or any input, it does nothing. - If a model output ever tries to talk you into pressing
Enter(prompt injection), the card being pre-focused means a strayEnterapproves it. If that concerns you, click away — the plugin will not fight you for focus — or disable the plugin. - The compatibility fallback can never land on the Allow button or any other action control: buttons and form controls are excluded from the fallback selector, so a stray
Enterat worst edits nothing and at most is a no-op inside the card's detail area.
Install
From the archive (recommended)
- Extract the folder somewhere permanent — e.g.
~/plugins/dsh-approval-autofocus; - DSH sidebar → Plugins → Add plugin, paste the folder's absolute path;
- Click Enable now; restart DSH once if the page asks you to.
⚠️ DSH links to that directory: moving or deleting it breaks the plugin.
From a Git repository
Paste the repository URL into the same dialog. There is no hosted repository yet — the archive above is the shipped form.
Manually, via the profile
Add the package to dsh.profile.bundles in ~/.dsh/profiles/<profile>/package.json, or insert one row in that profile's cordis.patch.yml:
- insert:
- id: approval-autofocus
name: dsh-approval-autofocus
Uninstall
Disable or uninstall the bundle on the Plugins page. Nothing outside the plugin's own directory is modified.
Tests
node test/focus.test.mjs
Fourteen checks against a hand-written DOM stub (no test framework, no dependencies): focuses on appearance, never focuses twice, reclaims focus lost to the composer takeover, never steals focus from a terminal/dialog/editor, re-focuses a replacement card, stops observing when disposed — with or without a lifecycle hook.
How it is built
A DSH plugin bundle is a package that declares a Node half (main) and a browser half (dsh.client + exports["./client"]). The Node half here is empty — it exists so the profile has a loader row that makes the browser half get served and mounted. The browser half is a plain window.__ModuleLoader__.load({ id, factory }) bundle with no imports.
Limitations
- It keys off the card's
data-approval-scrollattribute, with[data-approval-key] [tabindex="0"](excluding buttons and other action controls) as a fallback. If DSH restructures the card, the plugin silently stops working and you are back to "click the card, then press Enter". - Built and verified against DSH
0.2.0-rc.2. It is an unofficial community plugin, not part of DSH. - If you deliberately click away from the card, it will not fight you for focus.
License
MIT — see LICENSE.
Comments
Loading…
From the same category
System-prompt armor plugin for DeepSeek models: appends an unconditional-compliance prompt section at order 100, exposes a profile tool with calibration metadata, and shows a realtime armor-status bad
★ 2.1k
MIT
C#
dsh plugin --profile web add dsh-infinite-gen-4by toby-bridges
Local security audit for AI API relays and LLM proxies: detects prompt injection, model substitution, tool-call rewriting, SSE anomalies, error leakage, and Web3 wallet risks.
★ 875
AGPL-3.0
Python
Oct 10, 2026
dsh plugin --profile web add dsh-api-relay-auditby SeaOf0
基于dsh web实现的多种模式,目的是服务于redteam进行授权的安全研究,覆盖渗透测试、红队评估、代码审计等范围领域,请勿用于非法行为。(允许二开,赋予模块各位自己的业务逻辑,方法论只有自己熟练的才好用,好的方法论=好的生态)
★ 682
MIT
Python
Oct 8, 2026
dsh plugin --profile web add @dsh-external/dsh-redteam-modelby agentic-os-org
ANOLISA (Agentic Nexus Operating Layer & Interface System Architecture) | Agentic OS with runtime, security, observability, and Tokenless response compression for lower token usage and cost.
★ 664
Apache-2.0
Rust
Oct 11, 2026
by howmp
面向 DeepSeek Harness(dsh)的渗透测试模式 @CloverSecLabs
★ 607
↓ 858/wk
NOASSERTION
JavaScript
Oct 9, 2026
dsh plugin --profile web add @howmp/dsh-pentestby xiaods
k8e.sh - OpenSource Agentic AI Sandbox Matrix
★ 500
↓ 9/wk
Apache-2.0
Go
Sep 28, 2026
dsh plugin --profile agent add @k8e-sandbox/dsh-k8e-sandbox-bundle