dsh-approval-first

Source candidate

Approval-first edit/write for DeepSeek Harness: shadow tools ask the user BEFORE a mutation the standing sandbox policy would deny, so the model never has to repeat a tool call with sandbox_permissions. In-policy writes stay silent, out-of-policy targets get an approval card on the first call.

Author: joao-paulo-santos · Security & Permissions · Catalog snapshot: 2026-09-05

What it may solve

Approval-first edit/write for DeepSeek Harness: shadow tools ask the user BEFORE a mutation the standing sandbox policy would deny, so the model never has to repeat a tool call with sandbox_permissions. In-policy writes stay silent, out-of-policy targets get an approval card on the first call.

Imported third-party catalog description; not a Registry verification conclusion.

What can currently be confirmed

Not tested

DSH compatibility

No exact-version test is available.

Not tested

Security analysis

No Registry security conclusion is available.

Not tested

Functional verification

No functional smoke evidence is available.

Not tested

Permissions

Plugin permissions have not been resolved.

Not tested

Exact artifact

Version and integrity have not been resolved.

Continue checking with the plugin manager

Describe your task in a DSH conversation and mention dsh-approval-first. The plugin manager can find this candidate through Registry, then inspect its actual source and version locally.

Get the plugin manager command