DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Experimental Auto Review — DeepSeek Harness 插件(DSH Plugin)
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录
← Plugins

@deepseek-ai/dsh-experimental-auto-review

Experimental Auto Review

针对每个工具的 LLM 授权审查,适用于 DeepSeek Harness Auto 权限预设

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add @deepseek-ai/dsh-experimental-auto-review@0.1.6-alpha.1
README兼容性版本

兼容性与来源证明

Experimental Auto Review 以 @deepseek-ai/dsh-experimental-auto-review 发布,当前版本为 0.1.6-alpha.1。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
any
发布来源
npm
Registry 更新时间
2026/10/7

版本

0.1.6-alpha.1prerelease
2026/9/15
查看其余 8 个版本收起版本
0.2.1-alpha.1prerelease
2026/10/3
0.2.0-rc.2prerelease
2026/9/29
0.2.0-rc.1prerelease
2026/9/28
0.1.7-rc.2prerelease
2026/9/24
0.1.7-rc.1prerelease
2026/9/23
0.1.7-alpha.2prerelease
2026/9/22
0.1.7-alpha.1prerelease
2026/9/22
0.1.6-alpha.2prerelease
2026/9/17

相关插件

正在加载相关插件…

最新版
0.1.6-alpha.1
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
43 kB
文件数
8
Surface
any
许可证
MIT
发布源
npm
GitHub
★ 0
周下载
301,718
安全扫描
✓ v0.1.6-alpha.1 扫描通过
查看源码 ↗项目主页 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题

README


description: "Add experimental per-call Auto review to a Web profile, using the current agent's model before tools execute with Full access." kind: "package-bundle"

@deepseek-ai/dsh-experimental-auto-review

English | 中文

Summary

Add Auto review to the current-session permission pickers in a Web profile. Before each native or PTC inner tool call, the current agent's provider and model assess the pending action; an allowed call executes with Full access. Default Web keeps its three permission modes until this layer is explicitly installed. Auto review is experimental: it can allow unsafe actions, deny useful work, and spend additional tokens.

Table of Contents

  • Use this package
  • Understand the implementation
  • Further Exploration
  • Model Experience
  • Known Limitations and Deferred Work
  • Dev Note

Use this package

Install into a profile

From this source checkout, install the package into the Web profile through the existing CLI:

pnpm dsh plugin --profile web add ./packages/experimental/auto-review

The CLI initializes the profile when needed and appends this package's declared patch after the base and Web layers. Reconciliation activates the patch as a profile layer; a package without dsh.bundle.patch is only an installed dependency. Select Auto review with its superscript EXP badge in the composer or /permission picker and confirm the current-session risk dialog. An explicit /permission auto command switches directly. General settings and future-session defaults do not offer Auto.

Remove the layer through the same CLI:

pnpm dsh plugin --profile web remove @deepseek-ai/dsh-experimental-auto-review

What you get

Auto reviews every supported call once before its body, including each started PTC tools.* inner call. It classifies actual effects: ordinary project-local work and exact cleanup of objects created in this Session are low risk and allowed; irreversible deletion of pre-existing objects, production operations, external writes, and security changes are medium risk and require explicit current human or direct-parent authorization of the action, target, and scope. Sensitive exfiltration across a trust boundary is high risk and always denied. Ambiguous effects, unresolved authorization conflicts, malformed responses, and technical failures fail closed.

A denied call uses the ordinary tool card. The collapsed row identifies Auto review; expanded output states that the body did not execute and displays the optional reason. The Web permission package owns picker interaction, and the tool UI owns reason display.


Understand the implementation

Implementation internals — click to expand

cordis.patch.yml inserts the package itself as the auto-review row. src/index.ts requires the LLM, permission, Session, and tools services, then installs the preset contribution and prepended pre-execute listener in one effect. The permission owner supplies the current identity and process catalog; Auto shares Full access's existing sandbox and approval values without changing tool definitions.

The reviewer reconstructs five sections from the current Session surface and pending execution: fixed policy, cwd-only environment, sourced project constraints, filtered sourced history, and the complete pending action. Native schema comes from the latest request header. A PTC binding freezes its schema and carries it through the scheduler into transient execution metadata; start and settle events never serialize description or parameters. Main-agent system/message nodes, assistant text and reasoning, and tool results are excluded. The decision record owns authority, lifecycle, and child-inheritance rationale.

Unloading closes selection and review admission, migrates live Auto Sessions to Full access through the existing preset writer, then aborts and drains reviews before withdrawing the listener and contribution. Knobs and persistent terminals survive that migration. A persisted Auto Session cannot publish without the complete integration; reopening it after installation is an explicit user action. Reinstalling the layer restores the option but does not switch live Sessions back to Auto.

No runtime invariant companion is published: this single effect owns selection admission, review enrollment, cancellation, and cleanup; it has no independent observation that can diverge from those owned operations.


Further Exploration

  • Experimental packages — publication policy and dependency isolation.
  • Web bundle — the stable profile this patch extends.
  • Auto review decision — fixed risk policy, authority, and lifecycle.
  • Tools — execution, cancellation, and PTC result propagation.

Model Experience

Per-call reviewer

What the model sees

The reviewer uses the latest request/header.config provider and model with the shipped adapter's default reasoning. Its fixed REVIEW_POLICY replaces human approval for exactly one action: allow executes immediately with Full access. The other four sections contain only the retained facts described above. It returns one strict JSON text object with risk and decision; deny may include a string reason. Reasoning blocks may precede that single text block. Only low + allow, medium + allow/deny, and high + deny are valid.

Token effect

One additional model request per supported call, without caching, retries, truncation, compaction, or a separate small output budget. An oversized request fails closed.

KV Cache effect

The fixed reviewer policy can share a prefix; retained history and the pending action vary per call. Auto adds no dedicated runtime context or mode-switch prompt to the main agent.

Tool denial

What the model sees

The denial message is Auto review rejected tool "<name>"; its body was not executed. Ordinary native error rendering prefixes it with Error: . PTC uses the existing inner-call exception and catch behavior; a caught denial does not force the outer run_code to fail. The raw optional reason is durable structured error detail for users, never main-model content. Risk, reviewer prompt, reasoning, and raw response are not persisted.

Token effect

A denied call contributes only the ordinary fixed error result to the main conversation.

KV Cache effect

The denial appends an ordinary tool result; it does not rewrite earlier context or hide existing model-visible information.

Known Limitations and Deferred Work

  • Auto requires an explicitly installed Web layer; it is absent from default Web, Headless, General settings, and new-session defaults.
  • Auto provides no file sandbox. The outer run_code transport and direct Node effects inside a PTC program do not pass through inner-tool review.
  • Model classification can be wrong. There are no deterministic tool exemptions, persistent grants, manual fallback, configurable policy, or retry layer.
  • In-process Auto children review their own calls. Out-of-process children retain their native permission systems after the parent delegation call is allowed.
  • The reviewer reads the Session action history through the deprecated synchronous snapshotEvents() reader under a line-scoped waiver. Prior calls, PTC starts, and the direct parent's initial prompt have no projection or paged reader yet, so the migration stays deferred by the synchronous-read decision.

Dev Note

Working context for maintainers — click to expand

None.

相关插件

继续浏览 security-access 分类下经过校验的插件。

Doctor@linxin666/dsh-doctorDSH 配置档案的事务性救援模式,配备受监督的启动器、隔离的恢复容器、确定性修复、健康监控以及本地 Web 恢复控制台Cc Safety Netcc-safety-net编码代理 CLI 钩子——阻止破坏性命令和访问机密文件Pocketdsh-pocket把 DeepSeek Harness 装进你的口袋:一个包、一个设置页,手机扫码即同步访问电脑上的 DSH(局域网 + 公网,实时同屏)。Mobiledsh-mobileDeepSeek Harness 移动端适配与安全访问插件,支持局域网、远程连接、Android App 和手机浏览器。