Introduction¶
DeepSeek Harness (DSH) embraces the “everything is a plugin” philosophy, which makes building secure agents flexible, but also raises the question of how to balance “automated efficiency” with “execution safety”. Granting unrestricted permissions can lead to uncontrollable risks, while approving every action manually can slow down development.
The dsh-auto-review plugin aims to resolve this contradiction. It borrows from Codex’s automatic review design and, while preserving DSH’s native sandbox isolation, introduces an independent review model. Normal actions follow DSH’s existing permission policies, while high-risk actions are intercepted and sent to the Reviewer for risk assessment. Approved actions continue execution, while rejected actions force a safer alternative or request human authorization.
Plugin Overview¶
- Name:
jhckevin/dsh-auto-review - Maintainer: jhckevin
- License: MIT
- Core Value: Introduces an automated “second review” mechanism in DeepSeek Harness, using an independent model to assess risk while relying on the native sandbox for basic isolation.
Core Features¶
The plugin mainly provides the following capabilities:
- Automatic Approval Review: Distinguishes between normal actions and high-risk actions, and automatically triggers the review workflow.
- Codex-Style Design: The review interface and interaction logic follow a Codex-style design, supporting WebUI and TUI status prompts (such as a shield icon).
- Native Sandbox and Independent Model: Does not disrupt DSH’s native sandbox environment. The review model runs independently, uses the Flash model as the default option, and supports model selection based on risk level.
- Risk Tiering and Circuit Breaking: Supports risk-based model policies. If the same turn receives 3 consecutive rejections, or the last 50 reviews contain 10 rejections in total, a circuit breaker is triggered to forcibly end the current turn, preventing the Agent from retrying infinitely along an incorrect path.
- Automatic Host Version Compatibility: Automatically detects and supports specific DSH versions (0.1.0-rc.6, 0.1.1-rc.2, 0.1.2-alpha.5), eliminating the need to manually match plugin versions.
Installation and Configuration¶
The installation process consists of three steps: install the plugin core, initialize the native execution component, and install the UI adapter.
1. Install the Plugin Core¶
In an environment where a compatible version of DSH is already installed, run the following command to add the plugin:
dsh plugin --profile web add @jhckevin/dsh-auto-review@next
2. Initialize the Native Execution Component¶
On the first installation on each machine, an administrator needs to run the following once to initialize the native bridge component. This component is separated from the user directory to avoid being modified by the Agent.
sudo npm install --prefix /opt/dsh-auto-review-native/0.1.0-rc.2 \
--ignore-scripts --no-audit --no-fund \
@jhckevin/dsh-auto-review-bridge-linux-x64-gnu@0.1.0-rc.2
export DSH_AUTO_REVIEW_NATIVE_RUNTIME=/opt/dsh-auto-review-native/0.1.0-rc.2/node_modules/@jhckevin/dsh-auto-review-bridge-linux-x64-gnu
Note: Node.js version 24.20.0 is recommended. Linux x86_64 / glibc 2.31+ is supported.
3. Install the UI Adapter¶
After stopping DSH, run the installation script to obtain the WebUI icons and adaptation:
npx --yes --package=@jhckevin/dsh-auto-review@next dsh-auto-review-ui
dsh --profile web
Note: If you encounter network issues, you can set the DSH_AUTO_REVIEW_DOWNLOAD_MIRROR environment variable to use a mirror source.
4. Configure the Model and Enable the Plugin¶
- Go to Settings → Model, then configure the Provider and API Key.
- Go to Settings → Automatic Approval Review, enable the plugin, and select the Reviewer model.
Usage Logic¶
After the plugin is involved, the execution flow is as follows:
- Normal Actions: Follow DSH’s permission and sandbox settings and continue execution without review.
- High-Risk Actions: The action is sent to the Reviewer.
- Approved: The review state is cleared, and execution continues.
- Rejected: The Agent must find a safer alternative, or stop and request user authorization.
- Circuit Breaker Trigger: If failed reviews reach the threshold (3 consecutive rejections or 10 cumulative rejections), the current turn is forcibly ended.
Important Notes¶
- Cost Considerations: Reviewing actions generates additional token costs. Each review requires sending the operation, context, and policy. Although the input cache hit rate is about 50%, cache-hit input is not free, and the actual cost depends on the Provider’s pricing.
- Isolation Dependency: Do not rely on
partial enforcementas a complete isolation guarantee. If the Reviewer fails, the system will not automatically allow the action to proceed; user intervention is required. - Upgrade Behavior: When upgrading a plugin with the same name, DSH/npm replaces the old package in the current profile and does not enable multiple versions side by side. A same-name upgrade does not clear sessions, configurations, or keys.
- Dependency Requirements: The host/platform package for the native bridge is a required dependency, not a redundant version. Do not skip it during upgrades or reinstallation.
Summary¶
dsh-auto-review is a security enhancement tool for DeepSeek Harness. By introducing an independent review model and a circuit breaker mechanism, it reduces the frequency of manual approvals and improves the safety of Agent execution, without sacrificing the advantages of DSH’s native sandbox.
- Project Homepage: https://github.com/jhckevin/dsh-auto-review
- Ecosystem Catalog: https://www.skillhub.cn/plugins/jhckevin/dsh-auto-review