Introduction

The core of DeepSeek Harness (DSH) is workflow orchestration, and agents invoke tools during execution. Without intervention, an agent may perform destructive operations or deviate from user intent. dsh-advisor aims to solve this problem by introducing an independent review model that audits the agent’s actions after each step and, when necessary, injects guidance to help the agent self-correct.

Plugin Overview

slhssb/dsh-advisor is an independent model review plugin designed for DeepSeek Harness.

  • Maintainer: slhssb
  • Category: Workflow plugin
  • Problem Solved: After an agent executes a tool step, an independent review model intervenes to detect destructive operations, logic errors, or deviations from instructions, and injects feedback into the next model call.

Core Features

This plugin provides the following core capabilities:

  1. Independent Model Review: After each tool execution, an independent Reviewer Model reviews the latest operation records.
  2. Guidance Injection: When the review model identifies a genuine concern, such as destructive deletion or a logic error, it generates an [advisor] guidance message and inserts it into the message stream for the next model call.
  3. Zero-Cost Rule Checks: The rules configuration option uses regular expressions for deterministic checks. These rules do not consume Tokens and never fail, making them suitable for intercepting specific command patterns.
  4. Standard Injection Channel: Uses the DSH standard agent/pre-step waterfall injection channel, the same mechanism used by dsh-agent-instructions and dsh-compaction-basic.

Installation and Enablement

Installing the plugin requires the following steps:

  1. Install the plugin
dsh plugin add @slhssb/dsh-advisor
  1. Handle dependencies
    After installation, navigate to your DSH Profile directory (usually the project root directory), use your package manager to install dependencies, and restart DSH:
npm install  # or pnpm install

Configuration and Typical Usage

By default, the plugin targets the official DeepSeek API and uses the cheaper deepseek-v4-flash model. The API key is handled by the deepseek-official adapter and does not need to be configured in this plugin.

If you need to customize the review model or provider, you can override the configuration in your Profile’s cordis.patch.yml (the last written configuration entry takes precedence).

Basic Configuration Example

- id: advisor
  config:
    provider: deepseek-official
    model: deepseek-v4-flash
    maxTokens: 512
    maxHistoryMessages: 40
    interval: 1
    timeoutMs: 30000
  • provider: Provider routing for the review model; defaults to deepseek-official.
  • model: Review model name; defaults to deepseek-v4-flash.
  • interval: Perform a review every N steps that contain tool results; 1 means reviewing every step.
  • timeoutMs: Timeout duration for a single review.

Disabling the Plugin

To completely disable the plugin, add disabled: true to the configuration entry.

Rule Configuration (Deterministic Checks)

In addition to LLM review, you can define regex rules with rules. These rules match tool names and raw argument JSON. They do not consume Tokens and do not cause review failures.

- id: advisor
  config:
    provider: deepseek-official
    rules:
      - id: no-recursive-delete
        pattern: 'Remove-Item|rm\s+(-rf|-r\s*-f)|del\s+/[sq]'
        message: 'Destructive delete command detected. Please confirm the target path is authorized by the user.'
        action: warn            # or block
        tools: ['pwsh', 'bash'] # Optional: apply only to specific tools
        enabled: true
  • action: When set to warn, injects a warning message. When set to block, rejects execution of the step (in which case LLM review is not performed).

Important Notes

  1. Permissions and Security: The plugin runs with the permissions of the current DSH process. Be sure to review the source code and license (MIT) before installing it.
  2. API Keys: This plugin does not handle API keys. Keys are resolved by the deepseek-official adapter from environment variables or the credential store.
  3. Review Failure Handling: If the review process encounters an error, such as a timeout or empty output, the plugin logs a warning but does not interrupt the agent’s main workflow; it only skips the review for that step.
  4. Recursion Limits: Injected messages are ordinary user messages and do not trigger tool/result events, so they do not cause the review process to run recursively.

Conclusion

dsh-advisor provides a low-cost, highly configurable audit layer for DeepSeek Harness workflows. By combining LLM review with deterministic rules, it can significantly improve operational safety without changing the agent’s core architecture.

Directory Page | GitHub Repository