Per-edit approval gate for DeepSeek Harness
SiriLee/dsh-edit-approval · skills
Ask-before-act approval for DeepSeek Harness: every write / edit / str_replace_editor call asks before the file is touched — a red/green line-level diff, approve once or reject — and every bash command asks before it runs, each with its own master switch in Settings → General.
★ 3GitHub stars
0Forks
2026-08-31Last updated
TypeScriptLanguage
MITLicense
Key features
- Escape or expand sandboxing — it never changes the sandbox mode or grants access
- Passes when the gate is disabled, the tool is not in tools, the command is blank, or the call is a sandbox escalation (sandbox_permissions + justification — those carry their own approval and must not double-prompt).
- Edit panels are rebuilt from the plain-text headline into only the changed rows — removals red, additions green, right-aligned NN| gutter — plus a white-space: pre-wrap compensation and a collapse button on multi-line diffs.
- escalation calls pass through to the sandbox's own approval.
- Intercept inside commands — file edits performed inside a bash command are not edit-gated (they are covered by Bash approval, when enabled).
Requirements
- DeepSeek Harness web profile (dsh --profile web)
- peer @deepseek-ai/ packages are resolved by the harness at runtime.
Install command
dsh plugin --profile web add github:SiriLee/dsh-edit-approval