ilharp/dsh-tool-approval

dsh-tool-approval adds a pre-approval gate to any Tool Calling in DeepSeek Harness — a "Manual Mode" / "Ask Mode" switch. With the default configuration every tool call waits for your approval before it executes; with a custom config you can scope the gate with include and exclude patterns (wildcards supported, e.g. include: [fs_*, web_*] and exclude: [task_output]), and set your own reason text shown on the approval prompt. Tools listed in include get pre-approval, tools in exclude pass through untouched, and anything else follows the default policy.

Agent Capabilities ★ 1 updated 2026-08-13 — untested
View on GitHub ↗

Install

dsh plugin --profile web add dsh-tool-approval

npm dsh-tool-approval 0.1.0 verified 2026-09-04 (repository field → github.com/ilharp/dsh-tool-approval; README EN primary w/ zh edition). Install: dsh plugin --profile web add dsh-tool-approval, then the plugin applies pre-approval ("Manual Mode"/"Ask Mode") to tool calls.

Compatibility

DeepSeek Harness profiles that run model tool calling (web profile default). BSD 3-Clause.

Details

Recent updates

Wildcard include/exclude filtering keeps the gate scoped to the tools that actually need a human check.

FAQ

What does pre-approval mean?
Every matching tool call pauses for your approval before it runs — the opposite of auto-approval. The approval prompt can carry a custom reason.
Can I exempt some tools?
Yes — tools listed in exclude pass through without prompting; only tools matching include (or the default, all tools) are gated. Wildcards like fs_* and web_* are supported.
Which license is it under?
BSD 3-Clause.

Alternatives

Andy8647/dsh-auto-approval · moon09300731/dsh-approval-gate · Jiao-XXX/dsh-auto-approve

More plugins in Agent Capabilities

Browse more in Agent Capabilities

Guides for Agent Capabilities plugins