Foreword¶
The core design philosophy of DeepSeek Harness (DSH) is “everything is a plugin”. When building agent applications, approving operations such as Shell, network, MCP, and sandbox upgrades is a key part of security control. The dsh-auto-review plugin introduces a Guardian model review mechanism, adding an automated permission preset for DSH and addressing the need for frequent manual intervention in some scenarios.
Plugin Positioning¶
This is a plugin-level implementation and does not modify the DSH kernel. It adds a permission preset named auto-review for DSH, allowing the Guardian model to make automated decisions about specific security risks.
- Maintainer: Xinlong-Wu
- License: MIT
- Category: admin-security
Core Features¶
The plugin mainly implements the following capabilities:
- Automatic approval preset: Adds an
auto-reviewpreset to DSH permission configuration. - Workspace read-only pass-through: In a provable workspace, read-only operations are allowed directly without Guardian review.
- Guardian model review: The Guardian model reviews approval requests for Shell, network, MCP, sandbox upgrades, and other extensions.
- Audit logs: Every approved operation generates an audit record and calls
fsyncto ensure the data is persisted to disk. - UI optimization: Guardian card display is limited to 240 characters, and credentials and URLs are automatically masked.
- Manual override: Manual override approval is supported through the native DSH panel.
Installation and Enablement¶
Before installation, make sure Node.js is installed in your local environment (^22.19.0 || >=24 required).
Run the following commands to complete installation and configuration:
cd dsh-auto-review
pnpm install
pnpm build
dsh plugin --profile web add "$PWD"
dsh --profile web --dump-config
Uninstallation:
dsh plugin --profile web remove dsh-auto-review-plugin
Dependency build script handling (only needed when using pnpm 11 and encountering the ERR_PNPM_IGNORED_BUILDS error):
pnpm approve-builds @deepseek-ai/dsh-subprocess-local koffi
pnpm rebuild @deepseek-ai/dsh-subprocess-local koffi
Configuration and Usage¶
After installing the plugin, configure it in the Web interface.
- UI configuration: Go to Settings → Plugins → Auto Review. Expand the settings card and configure the review model, review scope, evidence budget, manual approval, and audit options.
- Environment variables: You can also configure it using environment variables. For example:
export DSH_AUTO_REVIEW_PROVIDER=deepseek
export DSH_AUTO_REVIEW_MODEL=deepseek-chat
export DSH_AUTO_REVIEW_MANUAL_OVERRIDE=denied-and-unavailable
export DSH_AUTO_REVIEW_AUDIT_DETAIL=summary
*Note: Provider and Model must be set together or both left empty.*
- Review flow:
- Explicit and safe targets are allowed directly.
- Other targets enter Guardian Review, and the card displays the status.
- If Guardian denies the request or is unavailable, DSH shows the native single-approval panel.
Applicable Scenarios and Notes¶
- Permission scope: All approvals are
allowed-once(allowed once) and do not establish permanent authorization. - Safety fallback:
criticalrisks are never automatically approved;highrisks require explicit user authorization. - Fail closed: For unclear invocations, tool mismatches, or situations where the exact action cannot be reconstructed, the plugin adopts a Fail Closed policy.
- Configuration conflicts: The Cordis patch replaces the entire
permission.config.presetstable. If you already have a custom preset in DSH, redeclare it in a later Profile patch and use--dump-configto check the combined result. - Runtime name: The npm package name is
dsh-auto-review-plugin, but the runtime module name isdsh-auto-review.
Conclusion¶
dsh-auto-review provides DSH with a Guardian-model-based automated security review solution, suitable for developers who want to improve approval efficiency while maintaining security.