Introduction¶
The core philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” When building agent workflows, reviewing code changes is a common requirement. If an LLM is run directly inside Harness to perform code review, there are two main risks: first, the LLM may modify local files; second, sensitive code may be exposed to unauthorized external Providers.
The dsh-pi-review plugin solves these issues by registering a root Agent tool and launching an independent Pi SDK Worker inside the read-only sandbox of the Harness. It freezes a deterministic Git snapshot, allows Pi to review changes in read-only mode only, and returns structured code review results.
Plugin Positioning¶
This is a read-only Pi Agent code review plugin for DeepSeek Harness. The plugin is maintained by win4r and is released under the MIT license. Its main purpose is to provide isolated, read-only Git change review capabilities, ensuring that the review process does not alter the local repository state or leak sensitive code.
Core Features¶
The plugin provides the following core capabilities:
- Freeze a deterministic Git snapshot: Lock the Git state before review begins to ensure the reviewed content remains unchanged.
- Register a root Agent tool: Register the
pi_review_difftool in the Harness for invocation by the Agent. - Independent Worker execution: Launch an independent Pi SDK Worker inside the read-only sandbox of the Harness to avoid interference with the host process.
- Structured result return: Return verifiable, structured findings that include categories, severity policies, and Pi usage statistics.
- Strict permission restrictions: Pi is not granted
bash,write,edit, extensions, Skill, Prompt templates, context files, or persistent Session. Pi can only read the current changed files in the snapshot. - Multi-scope support: Supports multiple Git diff scopes such as
unstaged,staged,working-tree,base, andbranch.
Installation and Enablement¶
Before installing the plugin, it is recommended to pin an audited commit SHA to ensure environment consistency.
dsh plugin --profile web add -w github:win4r/dsh-pi-review#<commit-sha>
After installation, the corresponding Profile must be restarted for the plugin to take effect. After restarting, you can ask the Agent in a top-level conversation to invoke the pi_review_diff tool.
Configuration and Models¶
By default, the plugin reads Pi’s ~/.pi/agent/auth.json and ~/.pi/agent/models.json for authentication. It is recommended to explicitly configure the model ID in cordis.patch.yml to avoid relying on default behavior.
- insert:
- id: pi-review
name: '@charlesqin/dsh-pi-review'
config:
authority: direct-human
model: kimi-coding/k3
modelProfiles:
fast: kimi-coding/k3
deep: openai/gpt-5.3-codex
thinkingLevel: high
timeoutMs: 300000
maxDiffBytes: 524288
maxFiles: 200
maxOutputBytes: 524288
maxDiagnosticBytes: 65536
disposeGraceMs: 3000
requireFullSandbox: true
In the configuration, the Worker is set to PI_OFFLINE=1 to disable Pi startup updates and telemetry operations. However, model requests must still access the configured Provider.
Usage¶
After installing the plugin and restarting the Profile, invoke pi_review_diff directly in the conversation. The following are typical usage examples:
- Review uncommitted changes:
Please invokepi_review_diffwith theworking-treescope to review all uncommitted changes in the current repository, with a focus on concurrency and error handling. - Review staged changes:
Please invokepi_review_diffwith thestagedscope to review the staged changes in the index relative to HEAD.
The tool parameters are as follows:
| Parameter | Description |
|---|---|
scope |
Review scope: unstaged, staged, working-tree, base, or branch. |
paths |
Optional list of repository-relative path filters. |
focus |
Focus of the review (maximum 2048 bytes). |
severity_floor |
Minimum severity for returned findings: critical, high, medium, or low; defaults to low. |
model_profile |
Optional deployment-level model alias. It must be pre-mapped in modelProfiles. |
Security Boundaries and Limitations¶
When using the plugin, note the following security and limitation items:
- Nature of the read-only sandbox: The read-only sandbox prevents local files from being modified by the Worker; it is not a data confidentiality boundary. The selected diff and contents of changed files are sent to the configured model Provider.
- Provider security: Do not use unauthorized external Providers to review private, sensitive, or regulated code.
- Enforcement requirement: By default, the Harness must report
fullread-only enforcement. - Worktree limitation: Version v0.2 only supports standalone regular worktrees with a physical
.git/directory. Linked worktrees,.gitindirection files, and similar setups are rejected. - File access limitation: Binary paths are not granted additional file-read access.
staged,branch, andcommitreviews do not open live worktree files. - Command execution limitation: The Worker does not execute
!commandentries in Pi configuration. - Dependency requirement: At least one valid
HEADcommit is required. A brand-new repository with no commits will fail.
Conclusion¶
dsh-pi-review provides a secure and controllable code review solution for DeepSeek Harness. By freezing snapshots and enforcing strict permission restrictions, it enables the Agent to complete code review without compromising the environment. For more details, visit the GitHub repository.