DeepSeek Harness plugin

dsh-auto-review-atropino

DSH Auto Mode — pre-execution rule interception + delivery-time independent subagent security review. The native auto-mode for long-running agents in DeepSeek Harness (Codex/Claude Code auto mode 的

Jump to install

Source facts

Repository
AtropinolTT/dsh-auto-review
Latest update
Aug 15, 2026
Category
Workflow & Automation
GitHub stars
1
Format
plugin
Catalog evidence
Upstream dsh.bundle evidence
Evidence path
package.json#dsh.bundle
Checked against
0.1.0-rc.8
Upstream check date
2026-08-20

This evidence comes from the upstream catalog. This site has not installed, run, or security-reviewed the plugin.

Install

Start with a prompt that asks an agent to review the GitHub repository and source. Switch to the command if you want to install it yourself.

Copy this prompt into DSH, Codex, or another agent and ask it to review the GitHub repository and source first.

Do not install or run any commands yet. Read this plugin's GitHub repository, README, and relevant source code. Then answer the questions below clearly and directly so I can decide whether it fits my needs:

1. What is this plugin, and what problem does it solve?
2. Who is it for, and what are its typical use cases?
3. How is it used after installation? Include one minimal example.
4. What known limitations or privacy, security, compatibility, or maintenance risks does it have?
5. Give a clear recommendation: recommend, conditionally recommend, or do not recommend, with reasons.

Distinguish statements documented by the repository, inferences from source code, and unknowns. If evidence is insufficient, say so explicitly. Do not guess or simply repeat the README.

GitHub: https://github.com/AtropinolTT/dsh-auto-review
Plugin: dsh-auto-review-atropino
Author: AtropinolTT

Check the source files

Read the README and other files from this plugin directory before installing.

File explorer3 files
README.mdSource · read only

dsh-auto-review

DSH Auto Mode — the native security-review plugin for DeepSeek Harness (DSH).

Pre-execution rule interception + delivery-time independent subagent deep review. Security first, trust second, quality third.

A native implementation of the Codex / Claude Code auto mode idea — built for long-running agents.

Why dsh-auto-review is a good choice for long-running agents

Long-running agents accumulate trust, context and write access over hours or days — and risk accumulates with them. dsh-auto-review adds a persistent, always-on security layer that never depends on the model remembering to be careful:

  • Always on by default — Auto Mode is session-scoped, enabled by default, and survives restarts (folded from official command/run events, replayable). /security auto off is the only way to disable it, and it only affects the current session.
  • Orthogonal to permissions — granting danger-full-access or any other permission preset never disables content review. The permission system answers "can the agent do this?"; Auto Mode answers "should it?". Both fail closed.
  • Two independent layers — local rules intercept before execution (no LLM involved, cannot be argued with); a fresh read-only subagent reviews every delivery (no confirmation bias, no shared context).
  • Fail-closed by default — interception defaults to deny; high-severity findings ask "fix / ignore" and default to fix; an interrupted or unparseable review is never reported as clean.
  • Zero-friction UX — one-sentence risk summaries, a green "auto" badge on the composer (status only, not clickable), plain slash commands.

How it works

Layer 1 — pre-execution rule interception

write / edit / str_replace_editor / bash / read actions are checked against local rules (secrets, dangerous commands, sensitive paths). A match raises an approval question — allow once / deny, default deny (fail-closed). Only the root agent is intercepted.

Layer 2 — delivery-time deep review

When the root agent idles after making changes, a fresh read-only subagent (read / grep / glob only — no writes, no commands) reviews the changes:

  • clean → reports so
  • high-severity issues → asks fix / ignore, default fix (answer injected into the main agent)
  • mid/low issues → reports only
  • interrupted / unparseable → never reports clean

Auto Mode

  • Session-scoped toggle, default ON, survives restarts.
  • /security shows status; /security auto on|off toggles (off = current session only, reversible).
  • Web: green "auto" badge at the left of the input box when active, dim when off — status only, not clickable.
  • cc-tui: no slot mechanism — status via /security output and toggle command replies.

Install

Requires DSH (DeepSeek Harness). The plugin is a single ESM package (Node 18+).

git clone https://github.com/AtropinolTT/dsh-auto-review.git
dsh plugin --profile web add /path/to/dsh-auto-review
dsh plugin --profile cc-tui add /path/to/dsh-auto-review

For the web "auto" badge, add "dsh-auto-review" to dsh.profile.bundles in ~/.dsh/profiles/web/package.json, then restart dsh web.

Configuration

Deep-merged from the plugin's cordis.patch.yml config field:

- id: dsh-auto-review
  name: 'dsh-auto-review'
  config:
    rules:
      enabled: true
      custom:
        - ruleId: key-aws
          disabled: true
    review:
      mode: auto        # auto | manual
      provider: spawn
      highSeverity: [critical, high]

Commands

  • /review — trigger a review manually (background)
  • /security — plugin status (Auto Mode, rules, review layer, high-severity threshold)
  • /security auto on|off — toggle Auto Mode for this session

Behavior summary

TriggerMechanismDefault
write/edit/bash/read hits a ruleapproval question (allow once / deny)deny
agent idle with changesread-only subagent reviewreport; high → ask fix
review interrupted / unparseablenever reports clean

中文说明

dsh-auto-review 是 DeepSeek Harness(DSH)的安全审查插件,实现 Codex / Claude Code "auto mode" 的原生版本,面向 长时运行 agent(长时间会话中信任、上下文与写权限不断累积,风险随之累积):

  • 两层审查:执行前本地规则拦截(不经过 LLM、无法被说服,命中即弹「批准一次/拒绝」,默认拒绝,fail-closed)+ 交付时独立只读子代理深审(read/grep/glob,无写、无命令;干净才报干净,高危默认要求修复,中断绝不报 clean)。
  • Auto Mode:会话级总开关,默认开启且跨重启保留(由官方 command/run 事件折叠);与 permission 正交——即使 full access 也不豁免内容审查;/security auto off 仅停用当前会话。
  • 呈现:web 输入框左侧绿色 "auto" 徽标(仅状态,不可点击);cc-tui 无 Slot 机制,以 /security 输出为准。
  • 原则:安全第一、信任第二、质量第三;安全、精简、快速、高效。
  • 项目前名 security-review(git 历史中可见),正式名 dsh-auto-review。
  • 命令:/review 手动触发审查;/security/security auto on|off 查看/切换状态。

License

MIT — see [LICENSE](./LICENSE).