bingps/dsh-plugin-auto-review

dsh-plugin-auto-review adds an auto mode to DeepSeek Harness: while a session sits on a review-governed permission preset, every shell command is handed to a review model before it runs, and the model either lets it through (allow → the tools/pre-execute waterfall continues), escalates it to the human (ask → routed through ctx.approval with the reviewer's reason), or refuses it (deny → the tool result is an error naming the reason). It replaces the per-command approval prompt with a judgement rather than blind trust. A review that cannot complete — no model route, timeout, transport error, unparsable answer — never silently allows; it resolves to onUnavailable, which defaults to ask. Sandbox escalation (sandbox_permissions) is deliberately not auto-answered, so leaving the file sandbox stays a human decision. The command, purpose, working directory, resolved sandbox mode and workspace root are framed as JSON and sent as one bounded auxiliary model request (ctx.llm.stream) that must answer with a single JSON object.

Coding & Development ★ 1 updated 2026-08-14 ✅ runtime-tested
View on GitHub ↗

Install

dsh plugin --profile web add github:bingps/dsh-plugin-auto-review

DISCREPANCY: the English README (Install) shows 'dsh plugin --profile web add dsh-plugin-auto-review', but that bare npm name does NOT belong to this repo — the registry entry dsh-plugin-auto-review 0.1.0 back-links to a DIFFERENT repository, delef/dsh-plugin-auto-review, as of 2026-10-02. The bare-name install would therefore fetch the wrong package, so this page uses the GitHub form for bingps/dsh-plugin-auto-review. After installing, the README requires adding review-governed presets and the plugin row to the profile's cordis.patch.yml.

Compatibility

DeepSeek Harness (dsh). Registers exactly one tools/pre-execute listener and owns no state; nothing in the harness is patched. Requires configuration in cordis.patch.yml (review-governed presets and the plugin row).

Details

Recent updates

The README documents the verdict table (allow / ask / deny with what the agent and human see), the fail-closed onUnavailable default, the deliberate exclusion of sandbox escalation, the how-it-works pipeline (tools/pre-execute listener, bounded model request, PreToolDecision mapping) and the cordis.patch.yml presets config.

FAQ

How do I install dsh-plugin-auto-review?
dsh plugin --profile web add github:bingps/dsh-plugin-auto-review — the bare npm name belongs to a different repo (delef/dsh-plugin-auto-review), so use the GitHub form.
What happens if the review model fails?
It never silently allows — a failed review resolves to onUnavailable, which defaults to ask (the human prompt).
Does it auto-approve sandbox escalation?
No — the README says sandbox escalation is deliberately not auto-answered; leaving the file sandbox stays a human decision.

Alternatives

940842546/dsh-permissions · limbo947/dsh-recall-plugin · p2coder/dsh-task-control

More plugins in Coding & Development

Browse more in Coding & Development

Guides for Coding & Development plugins