Plugin directory / Developer / dsh-reviewer-bot
dsh-reviewer-bot
Verified · install-tested on dsh chaojixinren
What it does
Native DeepSeek Harness plugin form code review bot: cross-code platform, pluggable rules, local replay.
Works — verified, early-stage project
Native DeepSeek Harness plugin form code review bot: cross-code platform, pluggable rules, local replay. It installs cleanly and boots without issues in our testing. It's early-stage but functional.
“Verified” means our automated CI actually ran dsh plugin add in a clean profile and it booted — nothing more. Feature descriptions and version compatibility are the author’s claims. This is not a security audit and not an endorsement of third-party code.
README
原生 DeepSeek Harness 插件形态的代码评审机器人。跨代码平台,规则可插拔,可本地重放。
为什么不是又一个 CI Action
现有方案把 DSH 当成一个黑盒 Docker worker 来调用——拿不到插件生态、每次事件冷启动、规则写死在 prompt 里、调 prompt 只能推 PR 等 CI。
我们直接长在 Cordis 扩展点上:
| 现有方案 | DSH Reviewer Bot | |
|---|---|---|
| 与 DSH 的关系 | 外部进程调用 | 原生插件,共享 ctx |
| 平台支持 | 仅 GitHub | GitHub / GitLab / Gitea / 本地 |
| 评审规则 | prompt 内写死 | 规则包可独立发布安装 |
| 本地迭代 | 推 PR 等 CI | dshrb review --local / dshrb replay |
| 运行形态 | 一次性 Action | Action / Daemon / DSH profile / CLI |
| Docker | 写模式硬依赖 | 可选隔离后端 |
设计文档
完整设计在 docs/,含 mermaid 图:
三种安装方式
按场景选一种接入:
| 方式 | 接入入口 | 适合 |
|---|---|---|
| DSH 生态用户 | dsh plugin --profile <name> add @dshrb/bundle |
装进既有 profile,与其他插件共享 ctx |
| GitHub Action | workflow 里 uses: dshrb/[email protected] |
尝鲜、小仓库 |
| Daemon | 常驻 webhook 服务 | 大仓库、多仓库、私有部署 |
# DSH 生态用户:装进既有 profile,与其他插件共享 ctx
dsh plugin --profile web add @dshrb/bundle # --profile 换成你的 profile 名
# GitHub Action:见 examples/review.yml
# Daemon:见 docs/08-deployment-modes.md
- GitHub Action 最小配置见
examples/review.yml,命令触发见examples/commands.yml - Daemon 部署与完整模式对比见
docs/08-deployment-modes.md
本地迭代命令
dshrb review --local/dshrb replay <run-id>不构成独立安装方式,见 部署形态。
命令
评审者在 PR 评论首行触发(非首行不触发,避免引用他人评论误触):
| 命令 | 作用 | 最低信任 |
|---|---|---|
@dsr review |
重新评审 | untrusted |
@dsr explain <path> |
解释某文件改动 | untrusted |
@dsr diagnose |
读失败 CI 定位原因 | trusted-read |
@dsr fix |
改代码并跑校验 | trusted-write + allow-write |
@dsr rules |
打印生效规则 | untrusted |
@dsr fix 本身不授予任何写权限:需要 actor 权限与仓库配置同时成立。
开发
pnpm install
pnpm run typecheck
pnpm run check # typecheck + lint + test
Node 22.19+ / 24+ / 26,pnpm 11.x,对齐上游 DSH 的 engine floor。
想参与开发?先读 贡献指南。
仓库结构
docs/ 设计文档(mermaid)
packages/core/ 领域类型与评审内核
review-core 领域类型(零依赖、零 I/O,公共词汇表)
forge ForgeGateway 接口 + provider 注册表
trust-policy 四级信任判定 + 工具执行门禁
rule-registry 规则包注册表(glob 匹配)
review-runtime 八阶段评审管线编排
progress sticky 进度评论生命周期
runtime-bootstrap Cordis 容器 + 插件链 + agent loop 装配入口
packages/forge/ provider 实现(github / gitlab / local)
packages/tools/ 模型可见评审工具(注册在 ctx.tools)
packages/rules/ 评审规则包(baseline)
packages/drivers/ Action / Webhook / CLI 三种外壳
packages/probe/ 上游签名探针(仅开发期验证契约)
bundle/ dsh.bundle 声明,供 dsh plugin --profile <name> add
examples/ workflow 模板
scripts/ 包清单生成(gen-package-manifests.mjs 单一事实来源)
安全
- 凭据(forge token、DeepSeek API Key)在任何信任等级下都不进入 Agent 工作区
- 仓库内容、diff、评论、CI 日志、模型输出全部视为不可信数据
- 校验命令是 JSON argv 数组,不过 shell
.github/**、package.json的scripts、二进制文件为ctx.tools.guard()永久红线,后续 listener 无法翻案- 完整威胁清单见 信任模型
发现安全问题请私下报告,勿开公开 issue。
Star 历史
许可
MIT。非 DeepSeek 官方项目。
Install
Install the catalog once, then DeepSeek Harness can find and install any plugin from this site automatically:
dsh plugin add dshbase-catalog Then say "install dsh-reviewer-bot for me" — your agent finds it in the directory and installs it. Docs: dshbase-catalog · verified packs.
This plugin is GitHub source (not published to npm) — install it straight from the repo:
Web profile:
dsh plugin --profile web add github:chaojixinren/dsh-reviewer-bot Headless (CLI) profile:
dsh plugin --profile headless add github:chaojixinren/dsh-reviewer-bot Test report
Verified: L1 install + L2 load + L3 runtime from GitHub source on dsh 0.1.0-rc.6.
When to use it
Extend the agent's coding surface — give it a new tool, workflow, or integration so it handles a dev task it couldn't before.
Who it's for
Developers who want dsh to behave like a teammate on real codebases — editing, running, and verifying changes rather than just answering.
For developers — extending it
The tool/command surface is the seam: expose more of the SDK, add smarter context wiring, or tighten the loop between code changes and verification.