dsh-auto-review
View on GitHubSecond-model AI auto-review for DeepSeek Harness approval requests: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default, fully auditable from the session log (approval/asked -> autoReview/verdict -> approval/decided).
A DeepSeek Harness plugin that puts a second, read-only reviewer subagent on the approval chain: it inspects tool arguments and workspace evidence, returns structured allow/deny verdicts with reasons, and fails closed by default with a full session-log audit trail.
Use Cases
Auto-approve or deny agent tool calls that cross a sandbox boundaryRead-only reviewer subagent inspects workspace before returning allow/deny verdictFail-closed fallback when the reviewer crashes, times out, or returns a bad schemaReconstruct every approval decision from the session log for auditingPer-tool AI/human/never policies plus regex risk rulesFeed deny reasons back to the calling model to stop blind retriesRejection circuit breaker after consecutive deniesExpose the reviewer as an MCP server for external hosts
Built With
- Language
- TypeScript
- Frameworks
- DeepSeek Harness (dsh) · Cordis · MCP · Vitest · tsdown · pnpm · Node.js
Tags
ai-safety · approval · auto-review · guardrails · subagent · deepseek-harness · dsh-plugin · mcp · sandbox · fail-closed · audit-trail · circuit-breaker · typescript · llm · second-model · human-in-the-loop