Introduction

The core philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” When building agent workflows, reviewing code changes is a common requirement. If an LLM is run directly inside Harness to perform code review, there are two main risks: first, the LLM may modify local files; second, sensitive code may be exposed to unauthorized external Providers.

The dsh-pi-review plugin solves these issues by registering a root Agent tool and launching an independent Pi SDK Worker inside the read-only sandbox of the Harness. It freezes a deterministic Git snapshot, allows Pi to review changes in read-only mode only, and returns structured code review results.

Plugin Positioning

This is a read-only Pi Agent code review plugin for DeepSeek Harness. The plugin is maintained by win4r and is released under the MIT license. Its main purpose is to provide isolated, read-only Git change review capabilities, ensuring that the review process does not alter the local repository state or leak sensitive code.

Core Features

The plugin provides the following core capabilities:

  1. Freeze a deterministic Git snapshot: Lock the Git state before review begins to ensure the reviewed content remains unchanged.
  2. Register a root Agent tool: Register the pi_review_diff tool in the Harness for invocation by the Agent.
  3. Independent Worker execution: Launch an independent Pi SDK Worker inside the read-only sandbox of the Harness to avoid interference with the host process.
  4. Structured result return: Return verifiable, structured findings that include categories, severity policies, and Pi usage statistics.
  5. Strict permission restrictions: Pi is not granted bash, write, edit, extensions, Skill, Prompt templates, context files, or persistent Session. Pi can only read the current changed files in the snapshot.
  6. Multi-scope support: Supports multiple Git diff scopes such as unstaged, staged, working-tree, base, and branch.

Installation and Enablement

Before installing the plugin, it is recommended to pin an audited commit SHA to ensure environment consistency.

dsh plugin --profile web add -w github:win4r/dsh-pi-review#<commit-sha>

After installation, the corresponding Profile must be restarted for the plugin to take effect. After restarting, you can ask the Agent in a top-level conversation to invoke the pi_review_diff tool.

Configuration and Models

By default, the plugin reads Pi’s ~/.pi/agent/auth.json and ~/.pi/agent/models.json for authentication. It is recommended to explicitly configure the model ID in cordis.patch.yml to avoid relying on default behavior.

- insert:
    - id: pi-review
      name: '@charlesqin/dsh-pi-review'
      config:
        authority: direct-human
        model: kimi-coding/k3
        modelProfiles:
          fast: kimi-coding/k3
          deep: openai/gpt-5.3-codex
        thinkingLevel: high
        timeoutMs: 300000
        maxDiffBytes: 524288
        maxFiles: 200
        maxOutputBytes: 524288
        maxDiagnosticBytes: 65536
        disposeGraceMs: 3000
        requireFullSandbox: true

In the configuration, the Worker is set to PI_OFFLINE=1 to disable Pi startup updates and telemetry operations. However, model requests must still access the configured Provider.

Usage

After installing the plugin and restarting the Profile, invoke pi_review_diff directly in the conversation. The following are typical usage examples:

  • Review uncommitted changes:
    Please invoke pi_review_diff with the working-tree scope to review all uncommitted changes in the current repository, with a focus on concurrency and error handling.
  • Review staged changes:
    Please invoke pi_review_diff with the staged scope to review the staged changes in the index relative to HEAD.

The tool parameters are as follows:

Parameter Description
scope Review scope: unstaged, staged, working-tree, base, or branch.
paths Optional list of repository-relative path filters.
focus Focus of the review (maximum 2048 bytes).
severity_floor Minimum severity for returned findings: critical, high, medium, or low; defaults to low.
model_profile Optional deployment-level model alias. It must be pre-mapped in modelProfiles.

Security Boundaries and Limitations

When using the plugin, note the following security and limitation items:

  1. Nature of the read-only sandbox: The read-only sandbox prevents local files from being modified by the Worker; it is not a data confidentiality boundary. The selected diff and contents of changed files are sent to the configured model Provider.
  2. Provider security: Do not use unauthorized external Providers to review private, sensitive, or regulated code.
  3. Enforcement requirement: By default, the Harness must report full read-only enforcement.
  4. Worktree limitation: Version v0.2 only supports standalone regular worktrees with a physical .git/ directory. Linked worktrees, .git indirection files, and similar setups are rejected.
  5. File access limitation: Binary paths are not granted additional file-read access. staged, branch, and commit reviews do not open live worktree files.
  6. Command execution limitation: The Worker does not execute !command entries in Pi configuration.
  7. Dependency requirement: At least one valid HEAD commit is required. A brand-new repository with no commits will fail.

Conclusion

dsh-pi-review provides a secure and controllable code review solution for DeepSeek Harness. By freezing snapshots and enforcing strict permission restrictions, it enables the Agent to complete code review without compromising the environment. For more details, visit the GitHub repository.