MrWeiCodes/dsh-permgate
Fine-grained permission gateway: per-category tool-call review (outside-workspace directories, commands, file read/write, subagents, repeated actions) with global & per-project allow/deny exceptions, quick-tool defaults, custom rules, a bilingual approval modal with inline diff details, custom rejection reasons and a sandbox-upgrade flow.
A fine-grained permission control plugin for DeepSeek Harness: DSH ships only three permission levels (Read only / Workspace Write / Full access); dsh-permgate adds a 'Custom Review' permission gateway that reviews tool calls one by one. Tool calls are reviewed per category (outside-workspace directories, command execution, file read/write, subagents, repeated actions) with ask/allow/deny per category, global + per-project configuration, allow/deny exception lists, quick-tool defaults (web_search, skill, grep, glob, web_fetch…), and custom rules combining tool name + file path + argument content (e.g. 'no tool may run rm -rf'; priority: rules > exceptions > defaults). The approval modal shows what the AI wants to do, why, and the concrete arguments with inline diffs for edit/write approvals; denial can carry a custom reason so the AI adjusts instead of retrying; a sandbox-upgrade flow grants one-shot host permissions that auto-revert. Bilingual (EN/中文) UI, settings persist in the user directory.
Install
dsh plugin --profile web add -w github:MrWeiCodes/dsh-permgateGitHub install per README (English edition): dsh plugin --profile web add -w github:MrWeiCodes/dsh-permgate. The repo has no install script, so git installs need no pnpm build authorization. Local checkout: dsh plugin --profile web add -w ./dsh-permgate (only when the checkout sits inside the profile directory). Restart dsh web, then pick 'Custom Review' in the session permission picker (/permission) or set it as the new-session default in Settings → Permission.
Compatibility
DeepSeek Harness web profile. Fine-grained permission gateway layered on the stock Read-only / Workspace Write / Full access levels.
Details
- Repo: MrWeiCodes/dsh-permgate
- Category: Tools & Capabilities
- Stars: 5
- Version: GitHub source (no npm package)
- Last push: 2026-08-26
- First seen: 2026-08-15
Recent updates
Custom Review permission gateway; six permission categories; global/project config; exceptions + custom rules; diff approval modal; sandbox upgrade flow.
FAQ
- What does it add over stock permissions?
- A 'Custom Review' gateway that reviews each tool call per category (directories, commands, files, subagents, repeats) instead of the three coarse stock levels.
- Can I deny with a reason?
- Yes — denial can carry a custom reason so the AI knows why and what to do instead, instead of retrying against a cold 'User denied'.
- How does the sandbox upgrade work?
- Even after you allow a call, if DSH's sandbox still blocks it the native upgrade approval pops up — a one-shot grant that auto-reverts afterwards.
Alternatives
ang-XWBWZ/dsh-approval-ai · Andy8647/dsh-auto-approval · pandashere/dsh-self-control-guard