All plugins

DSH / BUNDLE / CLIENT-UI

@dsh-plugin/dsh-approve-for-me

v0.4.1dsh-plugins / dsh-approve-for-me69fd09de3f

InstallableBundlesUI & client pluginsCommunity · Topic auto-analysisWeb UI

Overview

@dsh-plugin/dsh-approve-for-me

DSH plugin: codex-like auto-approval for run commands 鈥?rules, full-auto, or a lightweight reviewer model (codex guardian style) 鈥?plus an "Approve For Me" (鏇挎垜鍚屾剰) option in the sandbox permission choices, with a live review status bar in the Web GUI.

README / EN

Package documentation

Registry summary

DSH plugin: codex-like auto-approval for run commands 鈥?rules, full-auto, or a lightweight reviewer model (codex guardian style) 鈥?plus an "Approve For Me" (鏇挎垜鍚屾剰) option in the sandbox permission choices, with a live review status bar in the Web GUI.

dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.

Read the full README on GitHub

LIMITATIONS

Known limitations

- The auto-review model is not perfect and cannot replace human judgment, least privilege, sandbox isolation, backups, or other security controls; keep human double-checking for operations involving sensitive data, production environments, or irreversible actions. - Approval events are written to the session audit by `ApprovalService` as usual (`approval/asked` + `approval/decided`), so auto-resolutions leave a trace too; review rulings (risk/auth/rationale) are written to the plugin log and the corresponding session-flow status line. - Strict Mode rejections return a standard `deny` at `tools/pre-execute` and the tool body does not run; approved calls still pass through the original sandbox and other tool policies. - `sandbox_permissions: "approve-for-me"` without a `justification` errors out directly (consistent with the original paired validation). - In `review` mode with a preset selected, an explicit `sandbox_permissions: "approve-for-me"` (carrying the `[approve-for-me]` marker) is treated as the user's advance consent to **that one action** and is allowed through directly without the review model; with no preset selected it still goes to native approval. - Strict Mode does not apply the above marker bypass: every call is first ruled on once by the review model, and later permission escalations with the same callId just reuse that result to avoid re-reviewing. - The review model's output is used only for ruling; its response is not written back into the session history.