Introduction¶
The core of DeepSeek Harness (DSH) is workflow orchestration, and agents invoke tools during execution. Without intervention, an agent may perform destructive operations or deviate from user intent. dsh-advisor aims to solve this problem by introducing an independent review model that audits the agent’s actions after each step and, when necessary, injects guidance to help the agent self-correct.
Plugin Overview¶
slhssb/dsh-advisor is an independent model review plugin designed for DeepSeek Harness.
- Maintainer:
slhssb - Category: Workflow plugin
- Problem Solved: After an agent executes a tool step, an independent review model intervenes to detect destructive operations, logic errors, or deviations from instructions, and injects feedback into the next model call.
Core Features¶
This plugin provides the following core capabilities:
- Independent Model Review: After each tool execution, an independent Reviewer Model reviews the latest operation records.
- Guidance Injection: When the review model identifies a genuine concern, such as destructive deletion or a logic error, it generates an
[advisor]guidance message and inserts it into the message stream for the next model call. - Zero-Cost Rule Checks: The
rulesconfiguration option uses regular expressions for deterministic checks. These rules do not consume Tokens and never fail, making them suitable for intercepting specific command patterns. - Standard Injection Channel: Uses the DSH standard
agent/pre-stepwaterfall injection channel, the same mechanism used bydsh-agent-instructionsanddsh-compaction-basic.
Installation and Enablement¶
Installing the plugin requires the following steps:
- Install the plugin
dsh plugin add @slhssb/dsh-advisor
- Handle dependencies
After installation, navigate to your DSH Profile directory (usually the project root directory), use your package manager to install dependencies, and restart DSH:
npm install # or pnpm install
Configuration and Typical Usage¶
By default, the plugin targets the official DeepSeek API and uses the cheaper deepseek-v4-flash model. The API key is handled by the deepseek-official adapter and does not need to be configured in this plugin.
If you need to customize the review model or provider, you can override the configuration in your Profile’s cordis.patch.yml (the last written configuration entry takes precedence).
Basic Configuration Example¶
- id: advisor
config:
provider: deepseek-official
model: deepseek-v4-flash
maxTokens: 512
maxHistoryMessages: 40
interval: 1
timeoutMs: 30000
provider: Provider routing for the review model; defaults todeepseek-official.model: Review model name; defaults todeepseek-v4-flash.interval: Perform a review every N steps that contain tool results;1means reviewing every step.timeoutMs: Timeout duration for a single review.
Disabling the Plugin¶
To completely disable the plugin, add disabled: true to the configuration entry.
Rule Configuration (Deterministic Checks)¶
In addition to LLM review, you can define regex rules with rules. These rules match tool names and raw argument JSON. They do not consume Tokens and do not cause review failures.
- id: advisor
config:
provider: deepseek-official
rules:
- id: no-recursive-delete
pattern: 'Remove-Item|rm\s+(-rf|-r\s*-f)|del\s+/[sq]'
message: 'Destructive delete command detected. Please confirm the target path is authorized by the user.'
action: warn # or block
tools: ['pwsh', 'bash'] # Optional: apply only to specific tools
enabled: true
action: When set towarn, injects a warning message. When set toblock, rejects execution of the step (in which case LLM review is not performed).
Important Notes¶
- Permissions and Security: The plugin runs with the permissions of the current DSH process. Be sure to review the source code and license (MIT) before installing it.
- API Keys: This plugin does not handle API keys. Keys are resolved by the
deepseek-officialadapter from environment variables or the credential store. - Review Failure Handling: If the review process encounters an error, such as a timeout or empty output, the plugin logs a warning but does not interrupt the agent’s main workflow; it only skips the review for that step.
- Recursion Limits: Injected messages are ordinary user messages and do not trigger
tool/resultevents, so they do not cause the review process to run recursively.
Conclusion¶
dsh-advisor provides a low-cost, highly configurable audit layer for DeepSeek Harness workflows. By combining LLM review with deterministic rules, it can significantly improve operational safety without changing the agent’s core architecture.