全部插件

DSH / BUNDLE / CLIENT-UI

@dsh-plugin/dsh-approve-for-me

v0.4.1dsh-plugins / dsh-approve-for-me69fd09de3f

可安装组合包UI 与客户端插件社区 · Topic 自动分析Web UI

概览

@dsh-plugin/dsh-approve-for-me

DSH plugin: codex-like auto-approval for run commands 鈥?rules, full-auto, or a lightweight reviewer model (codex guardian style) 鈥?plus an "Approve For Me" (鏇挎垜鍚屾剰) option in the sandbox permission choices, with a live review status bar in the Web GUI.

README / ZH

插件文档

目录摘要

DSH plugin: codex-like auto-approval for run commands 鈥?rules, full-auto, or a lightweight reviewer model (codex guardian style) 鈥?plus an "Approve For Me" (鏇挎垜鍚屾剰) option in the sandbox permission choices, with a live review status bar in the Web GUI.

dsh.pub 核对固定版本的组合包契约、运行时事实与分发语义;完整 README 请查看源仓库。

在 GitHub 阅读完整 README

LIMITATIONS

已知限制

- The auto-review model is not perfect and cannot replace human judgment, least privilege, sandbox isolation, backups, or other security controls; keep human double-checking for operations involving sensitive data, production environments, or irreversible actions. - Approval events are written to the session audit by `ApprovalService` as usual (`approval/asked` + `approval/decided`), so auto-resolutions leave a trace too; review rulings (risk/auth/rationale) are written to the plugin log and the corresponding session-flow status line. - Strict Mode rejections return a standard `deny` at `tools/pre-execute` and the tool body does not run; approved calls still pass through the original sandbox and other tool policies. - `sandbox_permissions: "approve-for-me"` without a `justification` errors out directly (consistent with the original paired validation). - In `review` mode with a preset selected, an explicit `sandbox_permissions: "approve-for-me"` (carrying the `[approve-for-me]` marker) is treated as the user's advance consent to **that one action** and is allowed through directly without the review model; with no preset selected it still goes to native approval. - Strict Mode does not apply the above marker bypass: every call is first ruled on once by the review model, and later permission escalations with the same callId just reuse that result to avoid re-reviewing. - The review model's output is used only for ruling; its response is not written back into the session history.