All plugins

DSH / BUNDLE / CLIENT-UI

dsh-managed-approval

v0.4.0-beta.5jalllychun / dsh-managed-approvala6e6532fd7

InstallableBundlesUI & client pluginsCommunity · Topic auto-analysisWeb UI

Overview

dsh-managed-approval

Codex-inspired managed approval for DeepSeek Harness: risk-based MCP review, one-time grants, explicit denials, and human fallback on reviewer failure.

README / EN

Package documentation

Registry summary

Codex-inspired managed approval for DeepSeek Harness: risk-based MCP review, one-time grants, explicit denials, and human fallback on reviewer failure.

dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.

Read the full README on GitHub

LIMITATIONS

Known limitations

- DSH rc.6 discards MCP `readOnlyHint` and `destructiveHint` metadata before this hook. Risk classification is therefore a conservative lexical compatibility layer and can produce false positives or false negatives. - There is no dedicated Web action to manually override one exact operation rejected by the reviewer. - The circuit breaker covers three consecutive denials in one turn; it does not yet implement a rolling multi-turn threshold. - Third-party permission presets have no i18n API in DSH rc.6. The UI label is intentionally the static English text **Approve for me**, matching the three built-in entries. The Web client still recognizes the old beta.1 Chinese label so an upgrade does not lose its icon. - Linux, Windows, and the Headless profile have not yet passed the release smoke suite. - Model review reduces approval fatigue; it is not a security boundary equivalent to a sandbox. Keep DSH's sandbox enabled and inspect human prompts carefully.