Preface¶
DeepSeek Harness currently provides three permission presets: read-only, workspace write, and full access. For scenarios that require performing operations in the workspace but also demand strict risk control, the fourth mode, “Review for Me,” provides a compromise. This plugin uses a three-level funnel mechanism: it silently handles ordinary workspace writes while blocking high-risk operations or handing them to an independent review model.
Core Features¶
deepseek-autoreview is the fourth permission preset for DeepSeek Harness, with a core three-level funnel mechanism:
- Whitelist (zero-token fast approval)
It approves only structurally validated commands (such asnpm,git,pip,poetry,cargo, etc.), requiring the command to be a single verb and contain no Shell metacharacters. - Blacklist (zero-token blocking)
It contains 26 built-in rules for blocking obviously malicious operations (such asrm -rf /, writing to/etc, executing scripts through pipes, etc.). - Independent review model
For gray-area cases outside the whitelist and blacklist, decisions are delegated to an independent review model. You can switch the review model in settings, either following the main session or using a fixed model.
In addition, the plugin has built-in automatic-approval rate limiting (default 5/min, 30/hour); requests exceeding the budget are forwarded to human review. The policy follows a fail-closed design, rejecting by default when a safe decision cannot be made.
Installation and Activation¶
The installation process requires a configured dsh profile.
- Install the plugin
Run the official install command in the terminal:
dsh plugin add deepseek-autoreview
- Register bundles
Add the dependency and bundles to your profile’spackage.json:
{
"dependencies": { "deepseek-autoreview": "latest" },
"dsh": {
"profile": {
"bundles": ["@deepseek-ai/dsh-base", "@deepseek-ai/dsh-web-app", "deepseek-autoreview"]
}
}
}
- Restart the service
After modifying bundles, restart dsh to apply the host patch layer:
dsh web
Usage¶
After enabling, this preset replaces the preset table in the permission line and adds a review mode.
- Switch the review model
In DeepSeek HarnessSettings → General, a “Review-for-me model” option appears. You can choose “Follow the main conversation” (default) or specify a fixed model (such asdeepseek-official/deepseek-v4-flash). - Configure funnel parameters
Adjust the funnel behavior incordis.patch.yml:
- id: permission-review
name: deepseek-autoreview
config:
provider: deepseek-official
model: deepseek-v4-flash
whitelist: true
whitelistVerbs: [npm, pnpm, yarn, pip, pip3, poetry, cargo, git]
blocklist: 26 built-in rules
maxAutoPerMinute: 5
maxAutoPerHour: 30
Notes¶
- Environment requirement: dsh profile must already be configured.
- Network access: Network access (such as
curl,wget) is outside the review scope. - Sub-agent policy: Sub-agents retain a pinned
neverpolicy; the review model does not participate in sub-agent escalation. - Review model escalation: The review model does not participate in sub-agent escalation logic.
Summary¶
By using whitelist and blacklist mechanisms, deepseek-autoreview achieves zero-token review of command execution while retaining the ability to use an independent model to handle complex scenarios. It is suitable for developers who need read/write access in the workspace but want mandatory validation for high-risk instructions.