dsh-auto-review
Manifest validDSH Auto Mode — pre-execution rule interception + delivery-time independent subagent security review. The native auto-mode for long-running agents in DeepSeek Harness (the DSH native implementation of Codex/Claude Code auto mode).
dsh-auto-review
DSH Auto Mode — the native security-review plugin for DeepSeek Harness (DSH).
Pre-execution rule interception + delivery-time independent subagent deep review. Security first, trust second, quality third.
A native implementation of the Codex / Claude Code auto mode idea — built for long-running agents.
Why dsh-auto-review is a good choice for long-running agents
Long-running agents accumulate trust, context and write access over hours or days — and risk accumulates with them. dsh-auto-review adds a persistent, always-on security layer that never depends on the model remembering to be careful:
- Always on by default — Auto Mode is session-scoped, enabled by default, and survives restarts (folded from official
command/runevents, replayable)./security auto offis the only way to disable it, and it only affects the current session. - Orthogonal to permissions — granting
danger-full-accessor any other permission preset never disables content review. The permission system answers "can the agent do this?"; Auto Mode answers "should it?". Both fail closed. - Two independent layers — local rules intercept before execution (no LLM involved, cannot be argued with); a fresh read-only subagent reviews every delivery (no confirmation bias, no shared context).
- Fail-closed by default — interception defaults to deny; high-severity findings ask "fix / ignore" and default to fix; an interrupted or unparseable review is never reported as clean.
- Zero-friction UX — one-sentence risk summaries, a green "auto" badge on the composer (status only, not clickable), plain slash commands.
How it works
Layer 1 — pre-execution rule interception
write / edit / str_replace_editor / bash / read actions are checked against local rules (secrets, dangerous commands, sensitive paths). A match raises an approval question — allow once / deny, default deny (fail-closed). Only the root agent is intercepted.
Layer 2 — delivery-time deep review
When the root agent idles after making changes, a fresh read-only subagent (read / grep / glob only — no writes, no commands) reviews the changes:
- clean → reports so
- high-severity issues → asks fix / ignore, default fix (answer injected into the main agent)
- mid/low issues → reports only
- interrupted / unparseable → never reports clean
Auto Mode
- Session-scoped toggle, default ON, survives restarts.
/securityshows status;/security auto on|offtoggles (off = current session only, reversible).- Web: green "auto" badge at the left of the input box when active, dim when off — status only, not clickable.
- cc-tui: no slot mechanism — status via
/securityoutput and toggle command replies.
Install
Requires DSH (DeepSeek Harness). The plugin is a single ESM package (Node 18+).
git clone https://github.com/AtropinolTT/dsh-auto-review.git
dsh plugin --profile web add /path/to/dsh-auto-review
dsh plugin --profile cc-tui add /path/to/dsh-auto-review
For the web "auto" badge, add "dsh-auto-review" to dsh.profile.bundles in ~/.dsh/profiles/web/package.json, then restart dsh web.
Configuration
Deep-merged from the plugin's cordis.patch.yml config field:
- id: dsh-auto-review
name: 'dsh-auto-review'
config:
rules:
enabled: true
custom:
- ruleId: key-aws
disabled: true
review:
mode: auto # auto | manual
provider: spawn
highSeverity: [critical, high]
Commands
/review— trigger a review manually (background)/security— plugin status (Auto Mode, rules, review layer, high-severity threshold)/security auto on|off— toggle Auto Mode for this session
Behavior summary
| Trigger | Mechanism | Default |
|---|---|---|
| write/edit/bash/read hits a rule | approval question (allow once / deny) | deny |
| agent idle with changes | read-only subagent review | report; high → ask fix |
| review interrupted / unparseable | — | never reports clean |
中文说明
dsh-auto-review 是 DeepSeek Harness(DSH)的安全审查插件,实现 Codex / Claude Code "auto mode" 的原生版本,面向 长时运行 agent(长时间会话中信任、上下文与写权限不断累积,风险随之累积):
- 两层审查:执行前本地规则拦截(不经过 LLM、无法被说服,命中即弹「批准一次/拒绝」,默认拒绝,fail-closed)+ 交付时独立只读子代理深审(read/grep/glob,无写、无命令;干净才报干净,高危默认要求修复,中断绝不报 clean)。
- Auto Mode:会话级总开关,默认开启且跨重启保留(由官方
command/run事件折叠);与 permission 正交——即使 full access 也不豁免内容审查;/security auto off仅停用当前会话。 - 呈现:web 输入框左侧绿色 "auto" 徽标(仅状态,不可点击);cc-tui 无 Slot 机制,以
/security输出为准。 - 原则:安全第一、信任第二、质量第三;安全、精简、快速、高效。
- 项目前名 security-review(git 历史中可见),正式名 dsh-auto-review。
- 命令:
/review手动触发审查;/security、/security auto on|off查看/切换状态。
License
MIT — see LICENSE.
Comments
Loading…
From the same category
by nexu-io
🎨 Best DeepSeek Harness Design Plugin. The open-source Claude Design alternative. 🖥️ Local-first desktop app. 🖼️ Your coding agent becomes the design engine: prototypes, landing pages, dashboards,
★ 98.9k
Apache-2.0
TypeScript
Sep 30, 2026
by Molunerfinn
:rocket: The Ultimate Image Uploader for Efficient Creators. Supports Obsidian, Typora, VS Code etc. and 60+ image hosting services (S3, GitHub, Cloudflare R2, Imgur, Aliyun OSS...). Paste, upload, d
★ 27.3k
MIT
TypeScript
Sep 24, 2026
by zhu1090093659
DeepSeek Harness (DSH) Web Plugin Aggregation Ecosystem · Everything is a plugin, distributed via the Creative Workshop
★ 8.2k
↓ 134/wk
Apache-2.0
TypeScript
Sep 30, 2026
dsh plugin --profile web add dsh-webby YaoApp
✨ All your agents and workspaces in one place, on every device you own. Track tasks on a board, accessible from desktop, mobile, browser, or API. Self-hosted.
★ 8.1k
Go
Sep 28, 2026
by omdsh-dev
开放的侧边栏底座,支持三方拓展注册新侧边栏页面。内置文件渲染编辑/终端/侧边对话/Git/子代理页面 | Open sidebar foundation, supports third-party extensions to register new sidebar pages. Built-in file rendering/editing, terminal, side chat, Git,
★ 3.9k
↓ 53.7k/wk
MIT
TypeScript
Sep 28, 2026
dsh plugin --profile web add dsh-better-sidebarby ccch1mneyyy
DSH 官方公众号收录的 TUI 补位插件:Claude Code 风,鲸鱼顶栏/实时状态/流式思考/双击 Esc 回滚/上下文进度+TPS。npm 一键装。 DSH official WeChat featured TUI plugin — Claude Code style: whale bar, live status, streaming thoughts, double-Esc rol
★ 3.9k
↓ 11.6k/wk
MIT
TypeScript
Sep 30, 2026
dsh plugin --profile terminal add @deepseek-harness-tui/dsh-tui