Preface

DeepSeek Harness currently provides three permission presets: read-only, workspace write, and full access. For scenarios that require performing operations in the workspace but also demand strict risk control, the fourth mode, “Review for Me,” provides a compromise. This plugin uses a three-level funnel mechanism: it silently handles ordinary workspace writes while blocking high-risk operations or handing them to an independent review model.

Core Features

deepseek-autoreview is the fourth permission preset for DeepSeek Harness, with a core three-level funnel mechanism:

  1. Whitelist (zero-token fast approval)
    It approves only structurally validated commands (such as npm, git, pip, poetry, cargo, etc.), requiring the command to be a single verb and contain no Shell metacharacters.
  2. Blacklist (zero-token blocking)
    It contains 26 built-in rules for blocking obviously malicious operations (such as rm -rf /, writing to /etc, executing scripts through pipes, etc.).
  3. Independent review model
    For gray-area cases outside the whitelist and blacklist, decisions are delegated to an independent review model. You can switch the review model in settings, either following the main session or using a fixed model.

In addition, the plugin has built-in automatic-approval rate limiting (default 5/min, 30/hour); requests exceeding the budget are forwarded to human review. The policy follows a fail-closed design, rejecting by default when a safe decision cannot be made.

Installation and Activation

The installation process requires a configured dsh profile.

  1. Install the plugin
    Run the official install command in the terminal:
    dsh plugin add deepseek-autoreview
  1. Register bundles
    Add the dependency and bundles to your profile’s package.json:
    {
      "dependencies": { "deepseek-autoreview": "latest" },
      "dsh": {
        "profile": {
          "bundles": ["@deepseek-ai/dsh-base", "@deepseek-ai/dsh-web-app", "deepseek-autoreview"]
        }
      }
    }
  1. Restart the service
    After modifying bundles, restart dsh to apply the host patch layer:
    dsh web

Usage

After enabling, this preset replaces the preset table in the permission line and adds a review mode.

  1. Switch the review model
    In DeepSeek Harness Settings → General, a “Review-for-me model” option appears. You can choose “Follow the main conversation” (default) or specify a fixed model (such as deepseek-official / deepseek-v4-flash).
  2. Configure funnel parameters
    Adjust the funnel behavior in cordis.patch.yml:
    - id: permission-review
      name: deepseek-autoreview
      config:
        provider: deepseek-official
        model: deepseek-v4-flash
        whitelist: true
        whitelistVerbs: [npm, pnpm, yarn, pip, pip3, poetry, cargo, git]
        blocklist: 26 built-in rules
        maxAutoPerMinute: 5
        maxAutoPerHour: 30

Notes

  1. Environment requirement: dsh profile must already be configured.
  2. Network access: Network access (such as curl, wget) is outside the review scope.
  3. Sub-agent policy: Sub-agents retain a pinned never policy; the review model does not participate in sub-agent escalation.
  4. Review model escalation: The review model does not participate in sub-agent escalation logic.

Summary

By using whitelist and blacklist mechanisms, deepseek-autoreview achieves zero-token review of command execution while retaining the ability to use an independent model to handle complex scenarios. It is suitable for developers who need read/write access in the workspace but want mandatory validation for high-risk instructions.