# dsh-auto-review

[中文](README.md) | English

`dsh-auto-review` adds an `auto-review` permission preset to DeepSeek Harness. Proven workspace-local reads pass directly, while a separate Guardian model reviews Shell, network, MCP, sandbox escalation, and extension approvals.

> This is a plugin-level implementation. It does not modify DSH internals or claim exact parity with another product's native approval protocol.

## Core safety guarantees

- Every grant is at most one `allowed-once`; the plugin never creates a durable permission grant.
- `critical` risk is never auto-approved. `high` risk requires sufficient direct-user authorization for the exact target.
- Ambiguous calls, tool mismatch, oversized evidence, reviewer failures, malformed output, and generic approvals without one exact logged action fail closed.
- When auditing is enabled, any grant requires the final JSONL record to be appended and `fsync`ed first.
- Manual override reuses DSH's native **Reject / Allow once** panel instead of a large question containing full arguments.
- The Guardian card above the composer stores no raw arguments or evidence; beyond enum-like status fields, it shows only one decision reason capped at 240 characters with common credentials and URL query values redacted.

See [Security and audit](docs/security-and-audit.en.md) for details.

## Install

The npm package and Client module identity are `dsh-auto-review-plugin`; the Host runtime plugin name remains `dsh-auto-review`.

```bash
cd dsh-auto-review
pnpm install
pnpm build
dsh plugin --profile web add "$PWD"
dsh --profile web --dump-config
```

With pnpm 11, `ERR_PNPM_IGNORED_BUILDS` for `@deepseek-ai/dsh-subprocess-local` and `koffi` is dependency build-script approval—not lockfile corruption. After reviewing their provenance, run:

```bash
pnpm approve-builds @deepseek-ai/dsh-subprocess-local koffi
pnpm rebuild @deepseek-ai/dsh-subprocess-local koffi
```

Do not use `pnpm approve-builds --all` unless every pending dependency has been reviewed. See [Development](docs/development.en.md#pnpm-dependency-build-script-approval) for details.

Remove it with:

```bash
dsh plugin --profile web remove dsh-auto-review-plugin
```

The Bundle preserves DSH's `read-only`, `workspace-write`, and `danger-full-access` entries and adds `auto-review`. The Cordis patch replaces the complete `permission.config.presets` table. Restate existing custom presets in a later Profile patch and always inspect the final composition with `--dump-config`.

## Quick configuration

Open **Settings → Plugins → Auto Review**. The card is collapsed by default; its expanded body groups review model settings, review scope, evidence budgets, manual approval, and audit settings. Save writes changed fields only, updates the reviewer route atomically, and rolls back failed transactions. The Host still accepts compatibility field `trajectoryEnabled`, but Web Settings currently hides it.

Environment variables are also supported:

```bash
export DSH_AUTO_REVIEW_PROVIDER=deepseek
export DSH_AUTO_REVIEW_MODEL=deepseek-chat
export DSH_AUTO_REVIEW_MANUAL_OVERRIDE=denied-and-unavailable
export DSH_AUTO_REVIEW_AUDIT_DETAIL=summary
```

Provider and model must be set together or both omitted. See [Configuration](docs/configuration.en.md) for every field, default, and range.

## Review experience

1. Clearly safe workspace-local reads may execute directly.
2. Other targets enter Guardian Review. A card above the composer shows Reviewing, Awaiting approval, and the final state.
3. If Guardian denies or is unavailable and policy permits, DSH opens its native one-time approval panel.
4. The card is collapsed by default and keeps the latest result visible while the current Session uses `auto-review`. Refresh, Session switching, and Client plugin reload recover the Host snapshot; after a Host restart, the latest persisted result is recovered from the current audit JSONL. Results produced with auditing disabled or after an audit failure remain only for the current Host lifetime.
5. The plugin writes no custom Session UI events; JSONL still receives exactly one final line per review.

See [Review flow and Web UI](docs/review-flow.en.md).

## Documentation

- [Configuration](docs/configuration.en.md)
- [Review flow and Web UI](docs/review-flow.en.md)
- [Security and audit](docs/security-and-audit.en.md)
- [Development, verification, and limitations](docs/development.en.md)
- [中文 README](README.md)

## Development

Requires Node `^22.19.0 || >=24`. Source, tests, and build configuration are TypeScript-only; generated JavaScript exists only under the ignored `lib/` directory.

```bash
pnpm install
pnpm verify
```

See [Development](docs/development.en.md) for architecture, commands, and release checks.

## License

MIT
