DSH Marketplace

dsh-auto-review

PerryLink/dsh-auto-review

Second-model auto-review on the approval answerer chain: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default.

1982TypeScriptApache-2.0Source

Install

Add dsh-auto-review to DeepSeek Harness

via npm

Resolves a published tarball rather than cloning the repository, and installs without any extra setup. Swap `web` for your profile name if you run another one.

via GitHub · npm package

Installing from GitHub runs the project's build script, which pnpm blocks until you allowlist it — run the command once and pnpm prints the exact key to add under `allowBuilds` in ~/.dsh/profiles/web/pnpm-workspace.yaml.

What happened when we ran it

Installed cleanly when we ran it

Every command here is run in a throwaway container against a clean profile, and the result is whatever the harness recorded — not a guess from the source. Last run 19d ago.

Show it in your README

install verified — dshmarketplace

For maintainers: the badge serves this listing's latest sandbox verdict, so a re-run updates it on its own — and it links readers to the full result here.

Due diligence

Before you install dsh-auto-review

  • Source of record: PerryLink/dsh-auto-review — present in the community registry that DSH's own plugin market installs from.
  • Licensed under Apache-2.0.
  • Detected: terminal surface, requires credentials. Read the source before granting these.
  • A listing here is not a security review. Plugins run with your agent's permissions.

The AI take

What it is — dsh-auto-review adds a second model as a read-only reviewer subagent to the approval answerer chain in DeepSeek Harness.

Who it is for — When you are handling tool request approvals in DeepSeek Harness, it is suitable to install dsh-auto-review to obtain second model review. If your work does not involve tool request approvals, you do not need to install it.

Watch out — It requires providing an API key or token and may execute shell commands. The sandbox test passed: successfully installed in a fresh profile and registered by harness.

The verdict — I would install it because it can feed the reason back to the calling model when denied, avoiding blind retries.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.

What dsh-auto-review does

Abstract diagram of evidence flowing through a read-only review gate into an allow path or deny barrier.

dsh-auto-review is a DeepSeek Harness plugin that adds a second-model, read-only review step to approval requests before actions cross the sandbox boundary. DeepSeek Harness loads an approval/request answerer that claims requests covered by the ai policy and delegates other requests with next(), preserving the existing human approval chain. For an AI-reviewed request, a one-shot reviewer subagent reads the workspace with read, glob and grep, the streamed tool-call arguments with sensitive values redacted, the request reason and configured risk rules. It returns { decision, reason, riskLevel }; the reason is linked to the denied tool result by callId.

The default fallbackPolicy is rejected, so a reviewer crash, timeout or schema mismatch fails closed. autoReview/verdict and autoReview/rejection events provide a session audit trail, while /auto-review on, /auto-review off and /auto-review approve control session behaviour. Policies and limits are configured in cordis.yml, including toolsPolicy, riskRules, reviewerModel, reviewerTimeoutMs and reviewerTools.

dsh-auto-review suits workflows that need model-based evidence review without giving the reviewer write or terminal tools. It is the wrong choice when every request should remain a human decision, or when a second model and its credentials should not inspect workspace evidence. The listed risk surface includes a terminal surface and required credentials; the shipped policy reviews bash and write with AI, while other tools, including edit, remain on the human chain unless configured otherwise.

dsh-auto-review documentation

How dsh-auto-review behaves

DeepSeek Harness invokes the plugin on the approval/request answerer chain. The plugin recognises reviewer requests by identity and delegates them, while the reviewer child is bounded by maxDepth and its non-empty reviewerTools allow-list. Each decision follows approval/asked to autoReview/verdict or autoReview/rejection, then approval/decided. Audit events are log-only and marked ignorable: true. An optional invariant companion checks that rejection markers and events correspond.

A deny reason is injected into the calling model's denied tool result. Fallback and never decisions add [auto-review-fallback] and [auto-review-never] markers. The rejection circuit breaker acts after three consecutive denials, or six of the last ten verdicts, per turn.

Configuring dsh-auto-review

DeepSeek Harness reads these Schemastery fields from cordis.yml. An id-targeted override replaces the complete row, so required keys must be restated.

Key Default Purpose
enableByDefault true Initial session state; /auto-review on|off creates a durable override
toolsPolicy.default human Policy for unlisted tools
toolsPolicy.overrides {} Per-tool ai, human or never policy
riskRules [] Regex rules for reason, toolName or arguments
reviewerModel inherit Reviewer model route
reviewerTimeoutMs 60000 Verdict deadline
fallbackPolicy rejected Failure result: rejected, delegate or allow-once
maxReviewsPerTurn 10 AI-verdict budget
maxFailuresPerTurn 10 Reviewer-failure budget

Other documented fields include reviewerProvider (fork), reviewerTools ([read, glob, grep]), reasonMaxChars (2000), reviewerGuidance, reviewerPolicyText and denyGuidance.

Commands and requirements

DeepSeek Harness provides /auto-review on, /auto-review off and /auto-review approve. The last is a one-shot override. The plugin targets DeepSeek Harness 0.1.1-rc.2, with peers >=0.1.0-rc.8 <0.2.0, and requires Node ^22.19.0 || >=24.0.0. It supports all platforms as a host answerer; the optional Web review panel uses the session-projection capability. The reviewer inherits the session agent's route unless reviewerModel is set.

Written from the project's own documentation and kept in sync with it. Where the two disagree, the source is authoritative — read the README on GitHub

Same category

Alternatives to dsh-auto-review

api-relay-audit

toby-bridges

837

Runs local security audits of AI API relays and LLM proxies from DeepSeek Harness, producing Markdown reports for prompt injection, model substitution signals, tool-call rewriting, error leakage, stream integrity, and profile-gated Web3 risks.

Installed cleanly when we ran it

GitHub sourcePython25d ago

Authorized-security DSH collection: nine work modes (redteam coordinator, pentest, code audit, binary analysis, attack-defense, AV evasion, incident response, cloud security, CTF solving) and fifteen runtime plugins, managed from a settings page with one-click deploy, install, update and uninstall.

Installed cleanly when we ran it

GitHub sourcePython14d ago

AI review

dsh-redteam-model

What it is — Integrates nine redteam security research modes and fifteen runtime plugins.

Who it is for — Suitable for installation when redteam security research needs mode support and tool plugins. Not needed if you are writing normal business code.

Watch out — Sandbox test passed: successfully registered in a fresh profile. It will execute shell commands. No other obvious issues found.

The verdict — I would install it for authorized redteam security research because it provides structured modes and tools, but only under the premise of authorized use.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
1Source
601

Authorized pentest mode for DeepSeek Harness — exploration chain, assets and findings with a Web view.

Installed cleanly when we ran it

npm packageJavaScripttoday

AI review

dsh-pentest

What it is — Integrates authorized pentest mode into DeepSeek Harness, with exploration chain, assets and findings displayed via Web view.

Who it is for — When users need to record pentest targets, clues and assets in DeepSeek Harness, this plugin is suitable to install. For users running on Node.js versions below 22.5, this plugin is not suitable because it depends on the sqlite backend.

Watch out — Sandbox test passed: successfully installed in a new profile and registered by Harness. No obvious compatibility issues found. However, runtime requires Node.js >= 22.5 to use the sqlite backend.

The verdict — I would not install it because it records data only within a single session and does not support cross-session continuation.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
1Source

Claude Code-style declarative permission rules: ordered allow/deny/ask YAML rules matching tool names, arguments, workspace paths, and agent identity on the tools/pre-execute waterfall, with full session-log audit, dry-run mode, and hot reload.

Installed cleanly when we ran it

npm packageTypeScript14d ago

AI review

dsh-permission-rules

What it is — Inserts declarative permission rules in the DeepSeek Harness tools/pre-execute stage.

Who it is for — When using any model with DeepSeek Harness for precise tool call control, the plugin is suitable. For users who only need the default sandbox preset, they can skip this plugin.

Watch out — Sandbox test passed: successfully installed in a new profile and registered into the profile. The static check indicates it will execute shell commands. No other obvious issues found.

The verdict — I would install it because it provides full session-log audit and supports hot reload.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
2Source
85

Read-only security and compliance plugin for DeepSeek Harness: prompt-injection detection, Chinese-PII redaction, and a local configuration audit with redacted, reproducible reports.

Installed cleanly when we ran it

npm packageJavaScript26d ago

AI review

dsh-secure-audit

What it is — Detects prompt injection, redacts Chinese PII, and performs local configuration audit.

Who it is for — Users needing security checks when using DeepSeek Harness are suitable for installing this plugin. If you focus on tool calls rather than security review, you don't need this plugin.

Watch out — Sandbox test passes: installed in fresh profile and registered by Harness. The plugin only performs reads, with no write or delete risk. No obvious pitfalls found.

The verdict — I would install it because it audits configuration read-only and provides reproducible reports, assuming use of supported dsh-tools version.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
2Source

dsh-approval-gate

moon09300731

81

Risk-gated approval automation for DeepSeek Harness: flash pre-classifies whether a write/command is irreversible — safe operations are auto-approved, dangerous ones are escalated to human approval (fail-safe). File-diff review with one-click revert and session-scoped snapshots (v0.5.1: precise snapshots via tool-call parameter tracing, incl. human-approval cases).

Installed cleanly when we ran it

npm packageJavaScript1mo ago

AI review

dsh-approval-gate

What it is — dsh-approval-gate provides automated approval gate for DeepSeek Harness write commands.

Who it is for — Users executing write commands in DeepSeek Harness are suitable to install it because it uses Flash model to auto-classify risks and approve. Users not working in the DeepSeek Harness environment can skip installing it because it requires DSH profile for registration.

Watch out — Sandbox test passed: installed in new profile and registered in profile. No obvious issues found.

The verdict — I would install it because it supports session-scoped snapshots and one-click revert for file diffs.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
1Source