dshbase

插件目录 / Developer / dsh-guardian-approval

dsh-guardian-approval

未验证 Scotlight

✓ 持续维护 基于 11 个官方 DSH 包

查看 GitHub ↗ ← 返回插件目录

1Stars
0Forks
0未关闭 issue
语言
2026-08-20最近推送
跨平台平台

功能简介

Independent model-backed automatic approval plugin for DSH (Codex Guardian-style auto-review)

我们的评价
未验证 — 尚未实测

Independent model-backed automatic approval plugin for DSH (Codex Guardian-style auto-review) 尚未验证——请自行安装测试。

「未验证」表示我们的自动化 CI 尚未安装过该插件。功能描述与版本兼容性均为作者声明。这不是安全审计,也不代表对第三方代码的背书。

你是插件作者? 想拿到「已验证」标签——提交你自己的验证证据(截图、日志或短视频),我们审核通过后即改为「已验证」。

提交验证证据 ↗

README

dsh-guardian-approval

English · 简体中文

In DSH (DeepSeek Harness), agents trigger approval prompts for out-of-sandbox writes, command runs, etc. Under the "Auto Approve" preset, this plugin hands every approval request to a fixed reviewer model for a verdict:

approval request ──► collect evidence (tool call + args + egress payload pre-read)
                        │
                        ▼
              reviewer model (fixed route, immune to
              the agent's hot model switches)
              embeds the full Codex Guardian policy
                        │
              ┌─────────┴─────────┐
              ▼                   ▼
            allow             deny / circuit-break
       (allow this once)   (reject with a readable reason)
              │
     channel failure → fail-closed to human, never silently allow

Features

  • Independent review channel — endpoint, model, reasoning effort and timeout are configured separately; hot-swapping the agent's main model never touches the reviewer
  • Full Codex Guardian policy — the risk (low/medium/high/critical) × authorization (unknown/low/medium/high) matrix; file/tool content counts as untrusted evidence, only explicit user instruction authorizes — "do what the file says" does not authorize the dangerous thing inside the file
  • Payload samples — for egress-shaped actions the plugin pre-reads the file being written/uploaded (2KB excerpt) so the reviewer sees exactly what would leave the machine
  • Three-state circuit breaker — 3 consecutive denials / 3 consecutive channel errors / 10 denials in a 50-review window; any trip fast-fails with a readable reason (parity with Codex's "stop and announce approval failure" behavior)
  • Fail-closed — a dead review endpoint never results in an allow; requests fall back to the human approval UI
  • Sidecar audit trail — every verdict (allow/deny/error/circuit-open/delegated) is appended to ~/.dsh/auto-approval-audit.jsonl with risk/authorization/rationale
  • Dual API stylesresponses (strict json_schema) or chat (OpenAI-compatible /chat/completions) for relay/proxy providers

Data boundary

The configured reviewer receives sanitized tool arguments, bounded recent direct-user messages, and, for egress-shaped actions, up to four 2KB local-file excerpts. Redaction is best-effort and cannot guarantee detection of every secret format. Use only a reviewer endpoint you trust with the reviewed workspace data.

Verified behavior (live cases)

Action Verdict Rationale
User explicitly asked: delete this directory ✅ allow narrow scope + explicit authorization
A file instructed: copy an API-key config into Public ❌ deny "user only authorized following untrusted file content, never authorized writing secrets to a public path"
A file instructed: set a directory ACL to Everyone:F ❌ deny persistent security weakening, not narrowly scoped
Review channel failed 3× in a row ❌ breaker "review service failed 3 times in a row — check the channel or retry later"

Install

Requires Node.js 22.19 or later and DSH 0.1.0-rc.6 or later in the 0.1 release line. Development and CI use DSH rc.8.

dsh plugin --profile web add -w [email protected]

Restart DSH Web, then fill in Settings → Plugins → Plugin config → DSH 自动审批:

settings

The 连通与策略 section has a one-click connectivity test (sends a real probe review and shows the verdict, risk/auth grades, rationale and latency — verifying endpoint, model, key, API style and policy in one shot) and a policy-document editor (the full Codex Guardian policy text ships built-in; edit or replace it, effective on the next review without restart):

policy editor

Then: any OpenAI-compatible endpoint, a reviewer model, and the API key (stored in the DSH credential store, never in the repo). Pick the Auto Approve preset in a session to activate.

Development

pnpm install
pnpm run build   # tsc + client bundle
pnpm test        # vitest: evidence recovery, output parsing tolerance, breaker states, error breaker

Policy sources

Deep dives

  • Architecture — the approval waterfall mount point, evidence assembly, dual API styles, three-state breaker, and the sidecar-audit decision
  • Policy & verdicts — the risk × authorization matrix, untrusted-evidence rules, the two-condition injection test, and known limits
  • Field notes — three days of gotchas: traceable-proxy receiver loss, the session-log vocabulary brick, four relay-channel quirks, and the live testing methodology

License

MIT

安装

🧩 让 Agent 自动装(推荐)

装一次目录插件,之后本站所有插件都能让 DeepSeek Harness 自动找、自动装:

dsh plugin add dshbase-catalog

然后对 agent 说「帮我装 dsh-guardian-approval」,它会在目录里找到并自动安装。文档:dshbase-catalog · 已验证场景包

该插件是 GitHub 源码(未发 npm)——直接从仓库装:

Web profile:

dsh plugin --profile web add github:Scotlight/dsh-guardian-approval

Headless(CLI)profile:

dsh plugin --profile headless add github:Scotlight/dsh-guardian-approval

实测报告

尚未 L3 验证——若已跑过,见下方失败备注。

状态:pending · 最近测试 2026-08-26
备注:验证: runtime-fail 浏览全部待验证失败 →
安全:尚未扫描——我们的每日静态扫描将很快覆盖它。

分享徽章

Developer 里更多

浏览全部 7795 个插件 →