PAKIKNOWLEDGE/dsh-auto-classifier

Autonomous permission classifier for the auto preset: tool-scoped allow/deny rules, an LLM semantic judge, and git checkpointing for unattended sessions.

dsh-auto-classifier adds a fourth permission preset — auto (Autonomous) — beside read-only / workspace-write / danger-full-access, in the style of Claude Code auto mode. On tools/pre-execute every tool call sees its name plus full arguments and dangerous commands (system-directory deletion, formatting, registry writes, git reset --hard / force push, credential access) are denied before anything executes; on approval/request, sandbox escalations are auto-allowed/auto-rejected by the classifier without a browser prompt. Before an allowed high-risk escalation the workspace is checkpointed with a throttled git add -A && git commit (auto_snapshot snapshots manually anytime). A systemPrompt section injects autonomous-mode discipline (risk tiers, git rescue, no infinite retry loops, email-and-stop when a human decision is needed). A bilingual (EN · 中文) web control page — Settings → Plugins → Auto Classifier — provides live phone-style toggles (LLM judge, write-content scan, strict default, judge stages, default decision), judge-model configuration (provider / base URL / API key / model; credentials saved and the judge calls that provider directly over HTTPS with a Test button; the API key is never returned, only masked), session stats and the recently-denied list. A Claude Code style tool-scoped rule engine supports Tool(pattern) rules with case-insensitive regexes and field projection to avoid false positives.

Development & Runtime ★ 0 updated 2026-08-16
View on GitHub ↗

Install

dsh plugin --profile web add dsh-auto-classifier

npm dsh-auto-classifier 0.1.14 verified 2026-09-03 (repository field → github.com/PAKIKNOWLEDGE/dsh-auto-classifier; README EN primary with zh edition). The README's recommended route is pack-and-add for Windows workspaces (workspace-write sandbox blocks npm's default cache dir): npm pack --cache <workspace-path> in the repo, then in ~/.dsh/profiles/web pnpm add "dsh-auto-classifier@file:...tgz" --force with the bundle row appended, then dsh --profile web --dump-config and restart. Its cordis.patch.yml injects rows as a bundle patch — never manually insert the same row ids in profile/home layers (duplicate loader entry kills web startup). The classifier is active only in sessions whose permission preset is auto; all other sessions keep stock behavior.

Compatibility

DSH web profile; active only under the auto (Autonomous) permission preset; judge-model direct HTTPS mode supports OpenAI-compatible and Anthropic endpoints; web control page requires the host webServer service.

Details

Recent updates

auto permission preset; pre-execute danger classifier + sandbox auto-approval; git checkpoint before high-risk escalation; system-prompt discipline section; bilingual control page with direct-connect judge-model config (v0.1.14).

FAQ

When is the classifier active?
Only in sessions whose permission preset is auto. Every other session keeps the stock interactive behavior — handlers simply call next().
How are dangerous commands handled?
On the tools/pre-execute waterfall each call is checked by name plus full arguments; patterns like system-directory deletion, git reset --hard or credential access are denied before anything executes.
Where is the judge API key stored?
In the model configuration endpoint, persisted server-side; the web page never returns it — only a mask — and a Test button pings the exact credentials typed.

Alternatives

940842546/dsh-permissions · tappass/dsh-governance · 863683348/dsh-gov

More plugins in Development & Runtime

Browse more in Development & Runtime

Guides for Development & Runtime plugins