jhckevin/dsh-auto-review
面向 DeepSeek Harness 的自动审批审查插件,借鉴 Codex 风格设计,结合原生沙盒与独立审查模型,提供风险审批、拒绝熔断及 WebUI/TUI 状态提示。
Project Overview项目介绍
dsh-auto-review is a native Cordis plugin built specifically for DeepSeek Harness (DSH); its repo name carries the dsh- prefix and ships a bundle-manifest, and it is installed via dsh plugin --profile web add @jhckevin/dsh-auto-review@next on Linux x86_64 with Node.js 24.20.0. The plugin routes every permission-expanding operation through an independent Reviewer model before execution, while leaving ordinary sandboxed actions untouched; during review a shield appears next to the tool, disappearing on approval and turning red on rejection. Three consecutive refusals in the same turn, or ten refusals across the last fifty reviews, trigger a circuit breaker that ends the current turn without deleting the session, and a Reviewer failure never auto-approves the action.
The target user is a DSH developer tired of repeated permission prompts who still wants the native sandbox preserved; after configuring Provider and API key under Settings → Models, they enable the plugin in Settings → Auto Review and pick a Reviewer model, optionally mapping risk tiers to a stronger model for high-risk operations. Rejected actions can be retried with a safer alternative, and only when no safe path exists does the plugin stop to ask the user. The design is inspired by OpenAI's Codex-style Auto Review rather than being an official DSH component, and it deliberately sits on top of DSH's own permission and sandbox layers instead of replacing them.
Dependencies are narrow: a fixed DSH host (0.1.0-rc.6, 0.1.1-rc.2, or 0.1.2-alpha.5) must already be installed, and an administrator must additionally install the native bridge package into /opt/dsh-auto-review-native/ with --ignore-scripts, then export DSH_AUTO_REVIEW_NATIVE_RUNTIME; the bridge is checked at startup and before every paid review, so missing dependencies never silently burn Reviewer tokens. The UI adapter is downloaded and hash-verified separately via npx --yes --package=@jhckevin/dsh-auto-review@next dsh-auto-review-ui, with DSH_AUTO_REVIEW_DOWNLOAD_MIRROR available for networks that cannot reach GitHub directly, and --restore available for rollback. Current release is the 0.6.2-rc.1 candidate on the npm next channel; full autonomous-rejection and cross-version browser coverage are still being completed, and DSH latest 0.1.2-rc.1 is not yet supported. Review incurs extra token charges billed by the configured Provider, partial-enforcement sandbox reports must not be treated as full isolation, and the project's own code is MIT while third-party policies and icons are listed in NOTICE and THIRD_PARTY_NOTICES.md.
dsh-auto-review 是面向 DeepSeek Harness(DSH)的原生 Cordis 插件,仓库名称以 dsh- 前缀开头并附带 bundle-manifest,使用 dsh plugin --profile web add @jhckevin/dsh-auto-review@next 安装。它引入独立的 Reviewer 模型,需要扩大权限的操作先由该模型审批,沙盒内普通动作默认免审;审查中工具旁显示盾牌,批准后消失,拒绝则变红并要求换方案或请求人工授权。同一回合连续三次被拒或近五十次累计十次拒绝时熔断当前回合,不删除会话,区别于单纯的自动放行。
典型用户是经常被 DSH 反复询问权限、希望减少打断、又不愿放弃原生沙盒保护的开发者;他们通过 设置 → 自动审批审查 启用并选定 Reviewer 模型,可选单模型或按风险分级为高风险动作指定更强模型。该插件是 Codex-style Auto Review 的 DSH 移植,受其思路启发而非官方配套,因此仍依赖 DSH 自身的权限与沙盒层。
依赖方面仅支持 Linux x86_64 与 glibc 2.31+,建议 Node.js 24.20.0,并需先安装 DSH 0.1.0-rc.6 / 0.1.1-rc.2 / 0.1.2-alpha.5 三档固定宿主之一,npm 包只下载对应界面适配并校验内容哈希;管理员需在 /opt/dsh-auto-review-native/ 下额外安装原生 bridge 包并导出 DSH_AUTO_REVIEW_NATIVE_RUNTIME,不可用时不会消耗 Reviewer token。当前为 0.6.2-rc.1 候选版,发布于 npm next 通道,自主拒绝与跨版本浏览器验证仍在补齐;DSH latest 0.1.2-rc.1 暂未覆盖。审查会额外产生 token 费用,按 Provider 实际用量计费;项目自有代码 MIT,第三方策略与图标见 NOTICE。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-auto-review(jhckevin/dsh-auto-review)
仓库:https://github.com/jhckevin/dsh-auto-review
本站详情页:https://www.yhbd.top/plugins/jhckevin-dsh-auto-review/
本站登记:类型 client · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 2 · 最近提交 2026-09-14 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add @jhckevin/dsh-auto-review@next
把 jhckevin/dsh-auto-review 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
Auto Review for DeepSeek Harness
让需要审批的操作先由独立模型审查,减少反复确认,同时保留原生沙盒和人工审批。


图片来自真实 DSH WebUI,使用配套 UI 适配,不是模拟页面。
使用体验
- 原生沙盒内的普通动作默认免审;需要扩大权限时,由 Reviewer 判断。
- 审查中显示小盾牌,批准后移除;拒绝显示红色盾牌与斜杠。
- 被拒后可以寻找更安全的替代方案,无法继续时请求用户授权。
- 同一回合连续 3 次拒绝,或最近 50 次审查累计 10 次拒绝,会强制结束当前回合,不会删除会话。
- 默认使用 Flash,也可选择 DSH 已配置的其他模型,或按风险分级选择模型。
它如何工作
普通操作先遵循 DSH 的权限与沙盒设置;需要审查的操作,再交给独立的 Reviewer:
操作 → 原生权限与沙盒 → 无需审查:继续执行
→ 需要审查:Reviewer → 批准后继续
→ 拒绝:换安全方案,或停下来问你
反复被拒仍继续尝试时,熔断会结束当前回合。它不是自动放行,也不会因为审查出错而跳过安全检查。
请留意额外的 token 费用。 每次审查都需要发送操作、相关上下文与策略。以此前反馈的小样本为例,约 8 次较高频审查可能累计数万输入 token,输入缓存命中约 50%;这不是固定开销或命中率保证,实际取决于模型、上下文和请求前缀是否重复。缓存命中的输入通常也并非免费,请以 Provider 的用量与价格为准。

新版账本单独统计 Reviewer 的未缓存输入、缓存和输出;缺失用量显示为未知或下界。截图中的动作累计包含历史记录,用量账本不包含升级前数据。
安装
支持 Linux x86_64 / glibc 2.31+,建议 Node.js 24.20.0。
一个 npm 包共用后端,安装时只下载当前宿主需要的界面适配。自动匹配 DSH 0.1.0-rc.6、0.1.1-rc.2、0.1.2-alpha.5,不用选择插件的 rc6 / rc2 / alpha5 通道。不识别的宿主版本会明确报错,不会强行安装旧适配。
当前为 0.6.2-rc.1 候选版,发布到 npm 的
next通道,不替换latest。三版本 Loop 回归已通过;完整自主拒绝与跨版本浏览器验证仍在补齐。详见本版说明。 DSH 的latest目前已到 0.1.2-rc.1,尚不在上述兼容范围。新环境请先安装下面的固定宿主版本。
1. 安装 DSH 和插件
已有兼容版本的 DSH 时,跳过第一条:
npm install -g @deepseek-ai/dsh@0.1.1-rc.2
dsh plugin --profile web add @jhckevin/dsh-auto-review@next
2. 初始化执行组件
每台机器首次安装时由管理员执行一次。执行组件与普通用户的插件目录分离,避免 Agent 修改它。
sudo npm install --prefix /opt/dsh-auto-review-native/0.1.0-rc.2 \
--ignore-scripts --no-audit --no-fund \
@jhckevin/dsh-auto-review-bridge-linux-x64-gnu@0.1.0-rc.2
export DSH_AUTO_REVIEW_NATIVE_RUNTIME=/opt/dsh-auto-review-native/0.1.0-rc.2/node_modules/@jhckevin/dsh-auto-review-bridge-linux-x64-gnu
在启动 DSH 的终端或服务配置中保留这个环境变量。不要用 root 运行整个 DSH。
3. 安装界面图标
停止 DSH 后运行;会自动识别宿主版本,只下载对应适配,校验内容并保留原文件备份:
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
w2112515/dsh-plugin-development
loguhan/dsh-workshop
sb1733831438-maker/DSH-closerAI
kenryu42/cc-safety-net
hyhmrright/brooks-lint
saya-ch/dsh-mobile
liguobao/ds-harness-remote
zhu1090093659/dsh-trading