mocilukalbj/dsh-open-code-review ↗★ 0
dsh-open-code-review
Alibaba Open Code Review for DeepSeek Harness: native tools and a host-model review skill, with optional OCR-managed reviews. 适合需要对未提交代码进行本地或大模型自动审查的开发人员。
インストール
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:mocilukalbj/dsh-open-code-reviewドキュメント
README 全文を読む ↗Configuration
Add a row override to your profile's cordis.patch.yml (or edit the plugin's schema-generated configuration in a supporting host):
- id: open-code-review
config:
enableManagedReview: false
delegateTimeoutMs: 60000
reviewTimeoutMs: 900000
maxOutputBytes: 8388608
ocrPath: ''
forwardEnv: []
| Setting | Purpose |
|---|---|
enableManagedReview | Expose ocr_review and ocr_llm_test; default false. |
ocrPath | Optional absolute path to a native OCR executable, not a shell command, JS launcher or .cmd shim. Empty uses the pinned packaged binary. Custom binaries must support delegation JSON schema 1. |
delegateTimeoutMs | 1,000–300,000 ms, default 60,000. |
reviewTimeoutMs | 1,000–3,600,000 ms, default 900,000. |
maxOutputBytes | 4 KiB–64 MiB, default 8 MiB. Exceeding it fails explicitly. |
forwardEnv | Opt-in names of environment variables to forward, e.g. [DEEPSEEK_API_KEY]. Never put key values in this list. DSH scrubs credential-shaped ambient variables by default. |
For full OCR-managed reviews, configure OCR using the upstream CLI (same version recommended), then enable enableManagedReview. The plugin does not copy DSH credentials or overwrite OCR configuration. Existing ~/.opencodereview/config.json is used by upstream OCR; explicitly allowed environment variables are another option. Full mode makes external LLM requests and persists upstream session state, so it may need a per-call file-sandbox escalation. Delegation does not need that model setup.
All tools run through DSH's managed subprocess service and resolved per-session file sandbox. A wider sandbox_permissions paired with a justification uses the host approval channel; unavailable/rejected approval fails closed. Cancellation, timeout and plugin unload terminate and join the owned subprocess range. Native OCR is invoked directly, so its npm launcher's background update checks are not started. This is a local execution plugin, not a remote-container binary deployment mechanism.