Permission Rules
Declarative, ordered allow/deny/ask permission rules for DeepSeek Harness: match tool names, arguments (glob/regex), workspace paths, and network targets (domain/IP/port/scheme), plus a Codex-style process-level network policy.
What it is
Permission Rules is a DeepSeek Harness plugin in the workflow & approvals group, published to npm as `dsh-permission-rules`. Declarative, ordered allow/deny/ask permission rules for DeepSeek Harness: match tool names, arguments (glob/regex), workspace paths, and network targets (domain/IP/port/scheme), plus a Codex-style process-level network policy.
Version 0.7.14, licensed Apache-2.0, Node ^22.19.0 || >=24.0.0, DSH >=0.1.2-rc.1 <0.2.0 || >=0.1.5-alpha.1 <0.2.0 || >=0.1.6-0 <0.2.0 || >=0.1.7-0 <0.2.0 || >=0.2.0-0 <0.3.0 || >=0.2.1-0 <0.3.0.
The repository is available as a local checkout, so the version and licence above are read from the package manifest that is actually published rather than from a registry copy.
Other plugins in the same group: Auto Review.
Install
The plugin is installed with dsh plugin add. Same command on both platforms — only the verification line differs.
bash / sh
dsh plugin --profile default add dsh-permission-rules
dsh --profile default --dump-config | grep 'dsh-permission-rules'
PowerShell
dsh plugin --profile default add dsh-permission-rules
dsh --profile default --dump-config | Select-String 'dsh-permission-rules'
Replace default with the profile you actually use. Restart the session afterwards so the plugin’s tools are registered.
Full documentation
This page covers what the plugin is, how to install it, and where it comes from. Configuration keys, tool schemas and the full manual live in the repository.
Full documentation → GitHub · 中文说明
Related plugins
- Auto Review — Second-model AI auto-review for DeepSeek Harness approval requests: a read-only reviewer subagent decides allo…
More
- All 43 non-checker plugins
- The 53 compliance checkers (Chinese) — a separate family, grouped by profession.
- Home