The "permission" topic on GitHub groups 10 open-source projects in the DeepSeek Harness (DSH) ecosystem, led by dsh-permission-rules with 114 GitHub stars. dsh-permission-rules — Claude Code-style declarative permission rules for DeepSeek Harness: ordered allow/deny/ask rules with tool-name, argument (glob/regex), and workspace-path matching on the tools/pre-execute waterfall, session-log audit, and HMR reload. Every project here is indexed by DSH Universe with live GitHub data — stars, activity and install status — so you can compare and install directly.
Claude Code-style declarative permission rules for DeepSeek Harness: ordered allow/deny/ask rules with tool-name, argument (glob/regex), and workspace-path matching on the tools/pre-execute waterfall, session-log audit, and HMR reload.
Auto-approval permission guard for DeepSeek Harness: a middle tier between workspace-write and danger-full-access — auto-allows safe ops in trust dirs, always prompts for destructive ones
DeepSeek Harness (dsh) plugin: Workspace Only switch — out-of-bounds file access requests user confirmation in every mode (approval prompt in every mode)
DeepSeek Harness workspace management toolkit: view, create/register, rename, delete workspace records (registry only, does not touch disk directories); destructive operations (delete registration, change registered path) go through user approval, fail-closed.
DSH Web GUI plugin: session-scoped "Allow for this session" option in the approval dialog (per-mode standing grants, localStorage) + right-panel auto-open guard
DeepSeek Harness plugin: per-tool-call Auto-permission review powered by TypeSafe Jev, with account usage and API-key management inline on its settings page
Permission matrix for DeepSeek Harness: 3 sandbox modes x 4 approval strategies = 9 presets, with global and LLM-robot defaults, three-tier risk policies, audit log and git checkpoint.