Dsh Automode
log-li/dsh-automode · skills
Claude Code-style auto approval layer for DeepSeek Harness: deterministic rules + two-stage classifier, circuit breaker, fail-to-human.
★ 4GitHub stars
0Forks
2026-09-08Last updated
JavaScriptLanguage
MITLicense
Key features
- Deterministic first line — regex deny bands hard-block exfiltration, secrets, and system paths before any LLM call
- Claude Code–style auto mode for DeepSeek Harness — let your agent run hands-free, while a deterministic guardrail and a cost-aware reviewer keep the dangerous stuff from ever executing.
- deny — regex patterns that hard-reject.
- The classifier reads these as standing rejections.
- prefix-glob allow rules approve routine commands for free.
Requirements
- Tested against the macOS filesystem, the DeepSeek Harness (DSH) runtime, and the DSH version in use at development time.
- Path semantics — including the macOS /tmp → /private/tmp symlink (handled by realpath-nearest-ancestor resolution) and workspace-path trust — have not been verified on Linux or Windows, and deny-pattern/path matching may differ there.
Install command
dsh plugin --profile web add github:log-li/dsh-automode