Prelude¶
The design philosophy of DeepSeek Harness (DSH) is “everything is a plugin”. When handling complex tasks or high-privilege operations, relying solely on the model’s own self-correction is often not robust enough. dsh-audit-mode is the fifth mode in DeepSeek Harness, with preset ID audit. It introduces an independent, persistent Codex audit mechanism and combines code review with a human-approved remediation workflow, serving as a safety net for DSH.
Core Features¶
This plugin adds an independently running auditor role to DSH with the following capabilities:
* Independent persistent audit: Audit state is independent of the main session and recorded in a sidecar file.
* Human-confirmed remediation loop: For critical or warning-level audit results, remediation can only be executed after user approval.
* Multi-backend support: Supports configuring Codex, Claude Code, or DSH’s own LLM runtime as the reviewer.
* Safe pause: Automatically pauses the session when consecutive failures or severe errors occur.
* Dual-client control: Provides TUI and Web control interfaces for viewing audit status and executing remediation.
Installation and Enablement¶
The installation is performed with pnpm in the current DSH profile directory.
- Navigate to the web configuration directory (the TUI directory also follows the same pattern):
cd ~/.dsh/profiles/web
- Install the plugin package:
pnpm add dsh-audit-mode@github:yhfgyyf/dsh-audit-mode
(It is recommended to also install `dsh-progressive-tools` for better tool discovery support)
- Modify
package.jsonand add the plugin todsh.profile.bundles:
{
"dsh": {
"profile": {
"bundles": [
"dsh-audit-mode"
]
}
}
}
- Restart the DSH profile to load the plugin.
Configuring the Reviewer¶
By default, the plugin uses Codex as the reviewer. If you need to change the review backend or model configuration, edit cordis.patch.yml.
Default Configuration¶
- id: audit-bundle
config:
reviewer: codex
binary: codex
args: [app-server, --stdio]
models:
summarizer: { model: gpt-5.6-luna, effort: medium }
auditor: { model: gpt-5.6-sol, effort: max }
Using Claude Code¶
- id: audit-bundle
config:
reviewer: claude-code
claudeBinary: claude
claudeArgs: []
models:
summarizer: { model: haiku, effort: medium }
auditor: { model: opus, effort: max }
Using the DSH LLM Runtime¶
- id: audit-bundle
config:
reviewer: dsh
dshProvider: deepseek-official
models:
summarizer: { model: deepseek-v4-flash, effort: off }
auditor: { model: deepseek-v4-flash, effort: high }
Common Commands¶
In the audit preset mode, use the following commands to control the audit workflow:
* /audit status: View the current round, frequency interval, last verdict, and pause status.
* /audit now: Force an immediate audit (bypassing normal frequency limits).
* /audit history: Read recent audit history records from the sidecar file.
* /audit accept [audit-id]: Approve the latest or specified remediation plan by ID. After approval, the model loads the corresponding skill and executes the repair.
* /audit resume: Resume the session from a non-critical review failure or manual pause.
Behavior and State¶
- Frequency control: The first audit requires at least two steps and is spaced 60 seconds apart; subsequent audits run every 3 steps or every 3 minutes, with a minimum interval of 60 seconds. Anomalies trigger an audit at the next safe boundary.
- Warning vs critical: A warning does not pause the main Agent; the user can execute or edit the remediation plan. A critical warning pauses the main Agent and the current Goal; remediation starts immediately after approval and temporarily exposes Codis tools.
- Failure handling: If the reviewer fails three consecutive times (unreachable, timeout, or format error), the session is paused for reason
failures. - Final audit: When the session ends or when an audit with
final: trueis triggered via the Remote API, a full alignment audit is performed (including the goal, boundary rules, and recent summaries).
Frontend and Terminal Control¶
- Web interface: The plugin registers Remote API and Dock components on the Web side. The audit strip is displayed in
conversation.input.dock(order 5), between Todo and Goal. Snapshots and real-time updates can be obtained via the APIs/api/audit/snapshotand/api/audit/watch(SSE). - Terminal interface (TUI):
dsh-tui-apprenders a standalone status block.a: Execute the proposed remediation directly.e: Load the remediation plan into the editor; Enter executes it, Esc cancels.c: Copy feedback content while paused.r: Resume a non-critical review pause.Esc/Ctrl+C: Stop current work.
Notes¶
- Version requirement: This plugin currently supports DSH version 0.1.3-alpha.2.
- Permissions and security: The plugin runs with the permissions of the current DSH process. Please review the source code before installing.
- Data persistence: Audit state is written in JSON format to the sidecar file (
${DSH_HOME:-~/.dsh}/audit/sidecars/<sessionId>.json).
Summary¶
dsh-audit-mode provides a structured security review layer for DeepSeek Harness. By configuring Codex or another LLM as the auditor and combining it with a human approval workflow, it significantly reduces the risks of code generation and tool invocation while maintaining Agent autonomy.
- Catalog page: yhfgyyf/dsh-guardian-mode
- GitHub: yhfgyyf/dsh-audit-mode