dsh-auto-mode
Manifest valid★ 1DSH plugin: auto mode that routes permission-gated tool calls through an LLM review before approving, blocking, or asking for confirmation.
dsh-auto-mode
中文文档:README.zh-CN.md
An auto mode for DeepSeek Harness (DSH), shown as an Auto mode entry in the permission picker next to read-only / workspace-write / danger-full-access. While auto mode is selected, tool calls that would normally require a user confirmation are decided automatically:
- explicit deny rules → rejected (operator vetoes always win)
- explicit allow rules → approved
- pre-approved tools → approved without a model call
- otherwise a review model inspects the conversation transcript and the requested call, then approves, blocks, or flags it for human confirmation
- when the review model produces no ruling (API error, abort, truncation): reject (
failClosed) or fall back to the ordinary approval chain (a prompt)
Compatibility
Tested against DSH 0.1.0-rc.6. The bundle patch restates the stock permission-preset table (read-only, workspace-write, danger-full-access); after a DSH upgrade, review that table in cordis.patch.yml and update it if the stock presets changed.
Install
dsh plugin --profile web add dsh-auto-mode@<version>
or, for a local checkout:
# add to C:\Users\<you>\.dsh\profiles\web\package.json
# "dependencies": { "dsh-auto-mode": "file:E:/Project/Interests/dsh-auto-mode" }
# "dsh.profile.bundles": [..., "dsh-auto-mode"]
pnpm install --dir C:\Users\<you>\.dsh\profiles\web
Restart the web app. The permission picker (bottom-left of the chat box) now shows Auto mode; /auto switches the current session directly.
The picker entry is declared by the plugin's bundle patch (cordis.patch.yml). DSH's stock permission glyph table has no icon for custom preset ids, and the UI intentionally falls back to text-only labels — this plugin does not patch the DSH client bundle.
Configuration
All options have defaults; a bare {} config is valid.
| Path | Type | Default | Meaning |
|---|---|---|---|
classifier.provider / classifier.model | string | '' | Route for classifier calls; empty follows the session's current model. |
classifier.maxTranscriptMessages | number | 40 | Trailing transcript messages fed to the classifier. |
classifier.maxTokens | number | 512 | Classifier output budget. |
classifier.temperature | number | 0 | Classifier sampling temperature. |
classifier.askFallback | boolean | true | Classifier decision "ask" (uncertain risky call) falls back to the human approval chain; false treats it as a rejection. |
rules.allow | string[] | [] | Always-allow rules (see rule syntax below). |
rules.deny | string[] | [] | Always-reject rules; evaluated before everything else. |
rules.environment | string[] | [] | Free-form environment facts injected into the classifier prompt. |
allowlist | string[] | read, glob, grep, todo_write, web_search, job_list, list_agents | Tools approved without a classifier call. |
failClosed | boolean | false | true: classifier failure rejects; false: falls back to the normal approval chain. |
The auto-mode preset's label, description, and sandbox mode live in cordis.patch.yml, because the permission-preset table must be available when @deepseek-ai/dsh-permission-presets constructs its settings schema.
Rule syntax
tool match a tool by name (case-insensitive), e.g. `read`
tool:pattern match a tool whose request reason contains the pattern, e.g. `read:/etc/`, `pwsh:rm -rf`
* any tool
*:pattern any tool whose reason contains the pattern
A pattern containing * or ? is a wildcard match against the whole reason (read:/etc/*); any other pattern is a case-insensitive substring match.
How it works
- Mode state — auto mode is the session's selected
permission/presetvalue'auto-mode'. The preset itself bundlesworkspace-writesandbox and the core-valid approval policyask. The plugin detects that preset and takes over the approval answerer; it never writes an out-of-unionapproval/policyvalue and never patches DSH core services. - Decision chain — the plugin registers an
approval/requestanswerer withprepend, so in auto mode requests are claimed before the web UI answerer. The review model returns one of three decisions:allow— approved without prompting;reject— the reviewer judged the call harmful or contrary to the user's interests. The model is told explicitly that the reviewer, not a person, blocked the call (the tool layer reports both outcomes as "the user rejected…");ask— consequential but plausibly intended (installs, writes outside the workspace, sends data): the plugin shows a confirmation dialog with three choices — allow, reject, or reject and type what should happen instead. The typed text is injected directly into the session (visible at the next model step, bypassing inbox scheduling). Without a questions provider the ordinary approval chain is used instead. In any other permission preset the answerer delegates immediately.
- Review call — built from the session's derived messages plus the requested action, streamed through
ctx.llmwithtemperature: 0; the reply is parsed robustly (JSON object or token scan). The review prompt carries the operator's standing approvals, standing rejections, and environment notes in separate sections. - Model awareness — the plugin shadows the core
approval:policysystem-prompt context per agent so an auto-mode session is reported as auto, not ask, and tool-result wording ("the user rejected…") is clarified as a reviewer ruling rather than a human veto. - Settings page — because
cordis.patch.ymldeclares theauto-modepreset at construction time with the validaskapproval value, the new-session default picker can advertise it without any runtime promotion or service patching.
Security & privacy
Auto mode is a convenience mode, not a security boundary:
- the review model reads the recent conversation transcript and the requested action, and sends them to the configured LLM route (by default the session model);
- the default preset runs with
workspace-writesandbox, so workspace-external writes still require sandbox escalation/approval paths; - malicious content in the workspace (files, tool results) can attempt prompt injection against the review model — deterministic deny rules and the pre-approved tool list are evaluated before the model and should carry the rules you actually depend on;
- set
failClosed: trueif you want review-model failures to reject instead of prompting.
Development
npm install
npm run typecheck # tsc --noEmit
npm run build # tsc -p tsconfig.build.json → lib/
npm test # smoke tests for pure logic
License
MIT
Versions
| Latest version | Published | Size |
|---|---|---|
| 0.1.0 | — | — |
| 0.1.1 | — | — |
Comments
Loading…
From the same category
System-prompt armor plugin for DeepSeek models: appends an unconditional-compliance prompt section at order 100, exposes a profile tool with calibration metadata, and shows a realtime armor-status bad
★ 2.1k
MIT
C#
dsh plugin --profile web add dsh-infinite-gen-4by toby-bridges
Local security audit for AI API relays and LLM proxies: detects prompt injection, model substitution, tool-call rewriting, SSE anomalies, error leakage, and Web3 wallet risks.
★ 875
AGPL-3.0
Python
Oct 10, 2026
dsh plugin --profile web add dsh-api-relay-auditby SeaOf0
基于dsh web实现的多种模式,目的是服务于redteam进行授权的安全研究,覆盖渗透测试、红队评估、代码审计等范围领域,请勿用于非法行为。(允许二开,赋予模块各位自己的业务逻辑,方法论只有自己熟练的才好用,好的方法论=好的生态)
★ 682
MIT
Python
Oct 8, 2026
dsh plugin --profile web add @dsh-external/dsh-redteam-modelby agentic-os-org
ANOLISA (Agentic Nexus Operating Layer & Interface System Architecture) | Agentic OS with runtime, security, observability, and Tokenless response compression for lower token usage and cost.
★ 664
Apache-2.0
Rust
Oct 11, 2026
by howmp
面向 DeepSeek Harness(dsh)的渗透测试模式 @CloverSecLabs
★ 607
↓ 858/wk
NOASSERTION
JavaScript
Oct 9, 2026
dsh plugin --profile web add @howmp/dsh-pentestby xiaods
k8e.sh - OpenSource Agentic AI Sandbox Matrix
★ 500
↓ 9/wk
Apache-2.0
Go
Sep 28, 2026
dsh plugin --profile agent add @k8e-sandbox/dsh-k8e-sandbox-bundle