全部插件

DSH / BUNDLE / CLIENT-UI

dsh-managed-approval

v0.4.0-beta.5jalllychun / dsh-managed-approvala6e6532fd7

可安装组合包UI 与客户端插件社区 · Topic 自动分析Web UI

概览

dsh-managed-approval

Codex-inspired managed approval for DeepSeek Harness: risk-based MCP review, one-time grants, explicit denials, and human fallback on reviewer failure.

README / ZH

插件文档

目录摘要

Codex-inspired managed approval for DeepSeek Harness: risk-based MCP review, one-time grants, explicit denials, and human fallback on reviewer failure.

dsh.pub 核对固定版本的组合包契约、运行时事实与分发语义;完整 README 请查看源仓库。

在 GitHub 阅读完整 README

LIMITATIONS

已知限制

- DSH rc.6 discards MCP `readOnlyHint` and `destructiveHint` metadata before this hook. Risk classification is therefore a conservative lexical compatibility layer and can produce false positives or false negatives. - There is no dedicated Web action to manually override one exact operation rejected by the reviewer. - The circuit breaker covers three consecutive denials in one turn; it does not yet implement a rolling multi-turn threshold. - Third-party permission presets have no i18n API in DSH rc.6. The UI label is intentionally the static English text **Approve for me**, matching the three built-in entries. The Web client still recognizes the old beta.1 Chinese label so an upgrade does not lose its icon. - Linux, Windows, and the Headless profile have not yet passed the release smoke suite. - Model review reduces approval fatigue; it is not a security boundary equivalent to a sandbox. Keep DSH's sandbox enabled and inspect human prompts carefully.