permissions 15
Auto mode for DeepSeek Harness (dsh): an Auto entry in the Permissions selector whose approval prompts are answered by OpenGuardrails policy instead of a human — plus the full OGR guard engine underneath. No core changes.
dsh plugin add @openguardrails/dsh-auto-mode为 DeepSeek Harness 增加介于 Workspace Write 与 Full access 之间的自动批准权限档:例行沙箱升级由分类模型一次性放行,危险或不确定的操作仍转人工审批。An auto-approval permission preset for DeepSeek Harness between workspace-write and full access: routine sandbox escalations are granted once by a classifier
dsh plugin add dsh-auto-approveCC-style auto mode for DeepSeek Harness: deterministic deny/allow rules + pre-execute gate + model-agnostic two-stage classifier. Two-state (allow/reject) classifier since 0.8.0. TypeScript rewrite merging dsh-auto-mode v0.4.1 with Nuo-cl/dsh-auto-mode na
dsh plugin add @log.li/dsh-automodedsh-yolo-mode —— DeepSeek Harness 双面包插件:当会话处于可写沙箱模式且审批策略为 ask 时,用大模型自动裁决沙箱升权申请,支持内置预设与自定义权限层级,并提供宿主 settings + 自发布设置桥(/yolo-mode)与 Web 客户端 UI。
dsh plugin add dsh-yolo-modeDeepSeek Harness plugin exposing AIFeed tools: verify signed content permissions, fetch token-budgeted markdown, select delta-index entries, and decide usage.
dsh plugin add @aifeed/deepseek-harnessHold a DeepSeek Harness agent to a capmark capability manifest: mask its tools and judge every call.
dsh plugin add dsh-capmark-gate不把整台机器交出去,只送出挡路的决定和下一步:DeepSeek Harness 的审批、ask_user_question 提问与结果回复,以飞书卡片发到手机——桌面优先、只出站;执行过程实时可见,下一段任务一键即开。
dsh plugin add dsh-pocket-consoleDeepSeek Harness 权限规则引擎:hard/deny/ask/allow 四级规则(hard 高于全访问)、全局与 workspace 作用域、通配符路径保护、可视化草稿式编辑器,规则持久化于自管 JSON
dsh plugin add dsh-permissionsFine grained per tool permission rules for DeepSeek Harness (DSH). deny/ask lists in Claude Code rule syntax, enforced at the tools/pre-execute gate. Works standalone.
dsh plugin add dsh-movein-permissionsStrip sandbox_permissions / justification from model tool-call arguments so sandbox escalation is never triggered when the session already has sufficient permission.
dsh plugin add dsh-strip-sandbox-permissionsConsequence analysis for DeepSeek Harness: it says what an extra-permission call costs you — the device, your delegated authority, your wider interests. State-based, not guessed.
dsh plugin add dsh-project-guarddsh 插件 · 登录门 + 账号 / 权限 / 配额 / 审计台账(dsh-passwords 的功能已并入):HTTPS 登录网关与自签证书、用户增删改查(可一并创建工作区)、工作区白名单与归属跟踪、每小时 token 与每日时长配额、沙盒档位下限、上传/git 开关、三本审计台账(登录/访问/操作)、IP 封禁、TOTP 两步验证。
dsh plugin add kczx-user-managementFour-mode file-permission fence for DeepSeek Harness (workspace read/write x outside read/write), enforced at the tool layer, with a read-only composer mode indicator and a locale-aware UI.
dsh plugin add dsh-plugin-permission-guardDeclarative tool-call permission control for DeepSeek Harness — allow/deny/ask rules over tools, paths and commands, fail-closed by default, with JSONL audit log.
dsh plugin add dsh-tool-policyDeny an AI agent access to .env files, credential stores, keys and any path you hide — across file tools, shell commands, search selectors and run_code. A DeepSeek Harness (dsh) plugin.
dsh plugin add dsh-hidden-paths