dsh-command-code-review
August 30, 2026 · View on GitHub
English | 中文
A DSH (DeepSeek Harness) slash-command bundle that runs a full code review — five parallel review lenses with per-finding confidence scoring, for both pull requests and local code.
/code-reviewslash command for DeepSeek Harness — self-contained plugin bundle, installable into any dsh profile.
Table of Contents
- Features
- Requirements
- Install
- Usage
- How it works
- Configuration
- Troubleshooting
- Layout
- Development
- Contributing
- License
Features
- Two modes, one command —
/code-review <pr number|url>reviews a pull request;/code-review [request](or empty) reviews local code. - Five parallel review lenses — dsh.md adherence, shallow bug scan, git-history, prior-change comments, and code-comment compliance.
- Per-finding confidence scoring — a parallel subagent scores each finding; anything below the threshold is dropped (default 80).
- PR auto-reply — pull-request results are posted back to the PR with
gh; local results are reported in chat. - Configurable — the confidence threshold is set per profile (see Configuration).
- Review report document — local reviews are written as a structured Markdown report (in English) under
doc/by default; override the directory with--out <dir>per invocation orconfig.outputDirper profile. The filename embeds the current HEAD's short sha (omitted outside a git repo). - Automated releases —
release-please(versioning + CHANGELOG + release notes) plus trusted publishing to npm.
Requirements
- A dsh profile built on
@deepseek-ai/dsh-base(every shipped profile), which provides thecommandsservice and the subagent/bash/todo tools the workflow uses. - The GitHub CLI (
gh) onPATH, authenticated — required only for pull-request review. Local review needs nogh.
Install
From the npm registry:
dsh plugin --profile web add dsh-command-code-review
From a local checkout or tarball:
# directory
dsh plugin --profile web add /path/to/dsh-command-code-review
# packed tarball
dsh plugin --profile web add /path/to/dsh-command-code-review-<version>.tgz
The dsh plugin add command installs the package into the profile and, because its package.json declares dsh.bundle, appends it to dsh.profile.bundles automatically. Restart or re-boot the profile to pick it up.
Usage
In the DSH web UI
- Start the web UI and open the printed URL:
dsh web(alias ofdsh --profile web). - Start a new session and type
/code-reviewin the composer. The command is registered automatically — no extra setup. - For pull requests the result is posted back to the PR via
gh; for local review, findings are reported directly in chat.
Examples
/code-review 123 # review a pull request by number
/code-review https://github.com/owner/repo/pull/123
/code-review review src/auth # local review of a named scope
/code-review review the whole project # local review of the entire repository
/code-review # local review of the current uncommitted changes
/code-review review src/auth --out reports # save the report under reports/
/code-review --out docs review src/auth # --out may come first or last
Empty input first probes the current branch's open PR, then falls back to reviewing uncommitted changes.
For local reviews, the report is also written to a Markdown document — under doc/ by default, or wherever --out <dir> (or config.outputDir) points. The filename is code-review-<sha7>-<slug>.md in a git repo (<sha7> is the current HEAD's short sha, <slug> is derived from the review scope), and code-review-<slug>.md outside a git repo.
How it works
The package is a standard dsh bundle:
package.jsondeclares"dsh": { "bundle": { "patch": "./cordis.patch.yml" } }.cordis.patch.ymlinserts one plugin row (id: command-code-review) into the profile layer stack.lib/index.jsis a Cordis plugin that injectscommandsand registers thecode-reviewcommand. The handler routes PR numbers/URLs to the pull-request workflow and everything else (including empty input) to the local-review workflow, then delivers it viaagent.followup. The confidence threshold is configurable per profile (see Configuration), and the workflows tell the agent to await subagent completion notices rather than polling.
Users can disable or override the command from their own profile cordis.patch.yml:
- disable: command-code-review
Configuration
-
Confidence threshold: the workflow drops findings scored below a threshold (default 80). Override it in your profile
cordis.patch.yml:- id: command-code-review config: threshold: 90 -
Report output directory: where local-review reports are saved (default
doc). Override per profile:- id: command-code-review config: outputDir: reportsor per invocation with
--out:/code-review --out reports review src/auth. -
Review lenses: the 5 parallel review lenses (dsh.md compliance, bug scan, git-history, prior-change comments, code-comment compliance) live in
lib/index.js; add or remove lenses to fit your needs.
Troubleshooting
- No review comment posted: the PR is closed, draft, trivial, or already reviewed; or no finding scored 80 or above.
ghnot found: install and authenticate the GitHub CLI (gh auth login); only pull-request review needs it.- Code links do not render: use the full commit SHA and the
#L[start]-L[end]line range.
Layout
lib/index.js # Cordis plugin that registers the /code-review command
lib/parse.js # invocation parsing (--out flag)
test/smoke.test.mjs # smoke test
test/parse.test.mjs # parser unit test
cordis.patch.yml # bundle patch
.github/workflows/ # ci.yml + release.yml + release-please.yml
Development
npm install
npm test # node --test (smoke + parser unit tests)
Contributing
Issues and pull requests are welcome.
License
MIT