by PerryLink
Second-model AI auto-review for DeepSeek Harness approval requests: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default, fully auditable from the session log (approval/asked -> autoReview/verdict -> approval/decided).
# Add to your Claude Code skills
git clone https://github.com/PerryLink/dsh-auto-reviewGuides for using ai agents skills like dsh-auto-review.
Last scanned: 10/5/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-10-05T11:12:56.375Z",
"npmAuditRan": false,
"pipAuditRan": true,
"promptInjectionRan": true
}See how dsh-auto-review compares with popular alternatives.
dsh-auto-review is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by PerryLink. Second-model AI auto-review for DeepSeek Harness approval requests: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default, fully auditable from the session log (approval/asked -> autoReview/verdict -> approval/decided). It has 234 GitHub stars.
Yes. dsh-auto-review passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/PerryLink/dsh-auto-review" and add it to your Claude Code skills directory (see the Installation section above).
dsh-auto-review is primarily written in TypeScript. It is open-source under PerryLink on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh dsh-auto-review against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
See comparison
Second-model AI approval for DeepSeek Harness — a read-only reviewer subagent decides allow/deny on the approval chain, fail-closed by default.
When an action crosses the sandbox boundary, a second model reads the evidence and returns a verdict with a reason — so humans approve nothing while nothing unsafe slips through.
Official repository. This is the only official repository of dsh-auto-review, maintained by PerryLink. Same-name repositories under other accounts are not affiliated.
English · 简体中文 · Español · Português · हिन्दी
这个插件是 DSH 插件家族的一员(40+ 个,全部 Apache-2.0)。如果你在用,给个 star —— 它不会解锁任何功能,但会让下一个人在搜索里更容易找到它。
English: part of a 40+ plugin family for DeepSeek Harness. If it is useful, a star helps the next person find it — nothing is gated behind it.
| Surface | Status |
|---|---|
| Harness | DeepSeek Harness dsh-v0.2.1-alpha.1 (verified 2026-09-25). Dual-line npm support: dev pins and runtime deps 0.1.7-rc.2, peers >=0.1.2-rc.1 <0.2.0 || >=0.1.5-alpha.1 <0.2.0 || >=0.1.6-0 <0.2.0 || >=0.1.7-0 <0.2.0 || >=0.1.7-0 <0.2.0 — the plugin code feature-detects the published host lines and each line runs the full gate chain; the runtime dependency pins follow the host line so a profile install never shadows the host's own tree. pnpm-workspace.yaml pins the whole @deepseek-ai/dsh-* graph to that line, because autoInstallPeers otherwise fills the frozen dsh-agent-spine-demo subgraph's ^0.1.1-rc.2 peers with previews that lack the exports the 0.1.7 packages import. On the alpha.2 line the eval fixtures pin deepseek-flash (the removed deepseek-v4-flash id is gone from eval/). |
| Node | ^22.19.0 || >=24.0.0 |
| Platforms | All (host answerer; optional Web review panel via the session-projection capability) |
| Model | Any (the reviewer inherits the session agent's route; reviewerModel overrides) |
dsh-auto-review puts a second model on the approval/request answerer chain:
ai policy) and delegates everything else via next(); the human approval flow is never short-circuited.read/glob/grep tool allow-list returns a structured verdict { decision, reason, riskLevel }. Reviewer asks are recognized by identity and delegated; maxDepth + the allow-list keep the reviewer non-delegating.fallbackPolicy (default rejected); a deny verdict feeds its reason back to the calling model.ai/human/never) plus regex risk rules, all changeable from cordis.yml.never-policy rejections inject auditable markers too ([auto-review] / [auto-review-fallback] / [auto-review-never]).autoReview/verdict + autoReview/rejection session events (envelope ignorable: true) plus an optional invariant companion enforcing marker ⟺ event./auto-review approve override, and a never-policy hard disable that explains itself to the model.contextBudget) plus a Codex-style Markdown ruling policy (reviewerPolicyText).Every decision reconstructs from the session log: approval/asked → autoReview/verdict (or autoReview/rejection) → approval/decided.
Pattern-based auto-approvers decide before dispatch, with no evidence. dsh-auto-review gives the decision to a reviewer subagent that reads the actual workspace (through its read-only tool face), the already-streamed tool-call arguments (sensitive values redacted), the request reason, and your risk rules — then returns a structured verdict. A deny verdict feeds its reason back to the calling model, so the agent learns why instead of retrying blindly.
# 1. install the bundle into your profile
dsh plugin --profile web add "github:PerryLink/dsh-auto-review#main"
# or from npm (published releases)
dsh plugin --profile web add dsh-auto-review
# 2. restart and verify the row
dsh --profile web --dump-config | grep -A4 'id: auto-review'
Out of the box the shipped patch AI-reviews bash and write; every other tool (including edit — in-place modification) delegates to the human chain. Add edit: ai explicitly if you accept in-place edits without a human in the loop.
main): dsh plugin --profile web add "github:PerryLink/dsh-auto-review#main" — the isolated prepare build needs the single allowBuilds: { esbuild: true } key the dsh CLI prints for dsh-auto-review.dsh plugin --profile web add dsh-auto-review.npm i -g dsh1024 once, then dsh1024 plugin --profile web add dsh-auto-review (counts toward the deepseek1024.com install ranking).pnpm pack in this repo, then dsh plugin --profile web add ./dsh-auto-review-<version>.tgz.dsh plugin --profile web remove dsh-auto-review (or remove the row from the profile patch).dsh plugin add stops at ERR_PNPM_IGNORED_BUILDS for koffi / node-pty (pulled in by the eval harness), run pnpm approve-builds to approve those build scripts.All tunables are Schemastery Config fields (changeable from cordis.yml). An id-targeted override replaces the whole row — restate every key you need.
| Key | Default | Meaning |
|---|---|---|
enableByDefault |
true |
Sessions start with auto-review enabled; /auto-review on|off writes a durable override that beats this |
toolsPolicy.default |
human |
Policy for unlisted tools (delegate to the human answerer) |
toolsPolicy.overrides |
{} |
Per-tool policy: ai / human / never |
riskRules |
[] |
{pattern, policy, field?} matched before the tool table; field selects reason (default), toolName, or arguments |
reviewerProvider |
fork |
Subagent provider for the reviewer (in-process fork backend) |
reviewerModel |
(inherit) | Reviewer model id; unset inherits the session agent's route |
reviewerTimeoutMs |
60000 |
Verdict deadline; on expiry the fallback policy applies |
reviewerTools |
[read, glob, grep] |
The reviewer child's tool allow-list (must be non-empty) |
fallbackPolicy |
rejected |
Reviewer failure: rejected (fail closed) / delegate / allow-once |
maxReviewsPerTurn |
10 |
Real AI-verdict budget per open turn; beyond it, requests delegate |
maxFailuresPerTurn |
10 |
Reviewer-failure budget per open turn |
reasonMaxChars |
2000 |
Cap for reviewer reasons and the redacted argument preview |
reviewerGuidance |
(none) | Optional advisory guidance appended to the reviewer prompt |
reviewerPolicyText |
(none) | Markdown ruling policy injected into the reviewer prompt (Codex-style) |
denyGuidance |
(anti-circumvention text) | Guidance appended to every injected deny reason |
contextBudget |
{turns: 2, maxChars: 4000} |
Compact transcript budget for the reviewer prompt (the open turn plus the one before it); turns: 0 disables the section — and a blind reviewer denies user-authorized actions, so the runtime warns when 0 meets an ai policy. The character budget is spent on the most recent lines |
riskPolicy |
{maxAutoAllow: high, onHighRisk: delegate} |
allow verdicts above maxAutoAllow delegate or deny |
circuitBreaker |
{consecutiveDenies: 3, windowDenies: 6, windowSize: 10, action: delegate} |
Rejection circuit breaker |
overrideTtlMs |
300000 |
How long a /auto-review approve override stays usable |
verdictCacheTtlMs |