Foreword

The core design philosophy of DeepSeek Harness (DSH) is “everything is a plugin”. When building agent applications, approving operations such as Shell, network, MCP, and sandbox upgrades is a key part of security control. The dsh-auto-review plugin introduces a Guardian model review mechanism, adding an automated permission preset for DSH and addressing the need for frequent manual intervention in some scenarios.

Plugin Positioning

This is a plugin-level implementation and does not modify the DSH kernel. It adds a permission preset named auto-review for DSH, allowing the Guardian model to make automated decisions about specific security risks.

  • Maintainer: Xinlong-Wu
  • License: MIT
  • Category: admin-security

Core Features

The plugin mainly implements the following capabilities:

  1. Automatic approval preset: Adds an auto-review preset to DSH permission configuration.
  2. Workspace read-only pass-through: In a provable workspace, read-only operations are allowed directly without Guardian review.
  3. Guardian model review: The Guardian model reviews approval requests for Shell, network, MCP, sandbox upgrades, and other extensions.
  4. Audit logs: Every approved operation generates an audit record and calls fsync to ensure the data is persisted to disk.
  5. UI optimization: Guardian card display is limited to 240 characters, and credentials and URLs are automatically masked.
  6. Manual override: Manual override approval is supported through the native DSH panel.

Installation and Enablement

Before installation, make sure Node.js is installed in your local environment (^22.19.0 || >=24 required).

Run the following commands to complete installation and configuration:

cd dsh-auto-review
pnpm install
pnpm build
dsh plugin --profile web add "$PWD"
dsh --profile web --dump-config

Uninstallation:

dsh plugin --profile web remove dsh-auto-review-plugin

Dependency build script handling (only needed when using pnpm 11 and encountering the ERR_PNPM_IGNORED_BUILDS error):

pnpm approve-builds @deepseek-ai/dsh-subprocess-local koffi
pnpm rebuild @deepseek-ai/dsh-subprocess-local koffi

Configuration and Usage

After installing the plugin, configure it in the Web interface.

  1. UI configuration: Go to Settings → Plugins → Auto Review. Expand the settings card and configure the review model, review scope, evidence budget, manual approval, and audit options.
  2. Environment variables: You can also configure it using environment variables. For example:
    export DSH_AUTO_REVIEW_PROVIDER=deepseek
    export DSH_AUTO_REVIEW_MODEL=deepseek-chat
    export DSH_AUTO_REVIEW_MANUAL_OVERRIDE=denied-and-unavailable
    export DSH_AUTO_REVIEW_AUDIT_DETAIL=summary
*Note: Provider and Model must be set together or both left empty.*
  1. Review flow:
    • Explicit and safe targets are allowed directly.
    • Other targets enter Guardian Review, and the card displays the status.
    • If Guardian denies the request or is unavailable, DSH shows the native single-approval panel.

Applicable Scenarios and Notes

  • Permission scope: All approvals are allowed-once (allowed once) and do not establish permanent authorization.
  • Safety fallback: critical risks are never automatically approved; high risks require explicit user authorization.
  • Fail closed: For unclear invocations, tool mismatches, or situations where the exact action cannot be reconstructed, the plugin adopts a Fail Closed policy.
  • Configuration conflicts: The Cordis patch replaces the entire permission.config.presets table. If you already have a custom preset in DSH, redeclare it in a later Profile patch and use --dump-config to check the combined result.
  • Runtime name: The npm package name is dsh-auto-review-plugin, but the runtime module name is dsh-auto-review.

Conclusion

dsh-auto-review provides DSH with a Guardian-model-based automated security review solution, suitable for developers who want to improve approval efficiency while maintaining security.