편집자 노트

dmsobtl/dsh-tool-code-review

dmsobtl/dsh-tool-code-review is a DeepSeek Harness ecosystem project for development and runtime. Review its public README for features, setup, and usage details.

이것은 DeepSeek Harness(DSH) 플러그인입니다. 이 사이트는 GitHub README, 설치 정보, 유지보수 상태, 공개 보안 시그널을 모아 보여줍니다.

dsh-tool-code-review

DSH 插件:结构化代码审查 — Agent 读取 git diff,按 checklist 逐项审查,输出可操作的发现。

工具

工具功能
review_diff获取并解析 git diff,返回结构化文件变更摘要
review_file读取文件指定行范围(带行号,方便定位问题)
review_checklist生成审查 checklist(bugs/security/style/performance/tests/docs)

使用示例

User: 帮我 review 一下当前的改动

Agent:
→ review_diff({ target: "main" })
  // 获取与 main 分支的 diff,了解改了什么
→ review_checklist({ checks: ["bugs", "security"] })
  // 生成要检查的点
→ review_file({ path: "src/auth.ts", startLine: 45, endLine: 80 })
  // 深入看可疑的代码段

审查结果:
1. [Security] src/auth.ts:52 — 用户输入直接拼接到 SQL,存在注入风险
2. [Bug] src/handler.ts:28 — async 函数缺少 try/catch,错误会被吞掉
3. [Style] src/utils.ts:15 — 未使用的 import

配置

- insert:
    - id: code-review
      name: dsh-tool-code-review
      config:
        maxDiffLines: 500
        defaultChecks: [bugs, security, style, performance]

审查维度

维度检查项
bugs越界、空指针、async 错误处理、竞态、资源泄漏
securitySQL 注入、XSS、命令注入、硬编码密钥、路径遍历
style命名不一致、死代码、过度复杂、缺少错误消息
performanceN+1 查询、热路径大分配、缺分页、同步 I/O 阻塞
tests新代码无测试、边界未覆盖、flaky 模式
docsAPI 变更无文档、配置变更未说明、Breaking change 无迁移指南

与 dsh-agent-eval 配合

可以定义 eval 任务验证审查质量:

{
  "id": "catch-sql-injection",
  "prompt": "Review this diff and find the security issue",
  "expectedOutcome": { "type": "output_contains", "substring": "SQL injection" }
}

License

MIT

REPOSITORY SIGNALS

보안 및 설치 증거

이 점수는 공개 저장소 메타데이터와 이 사이트에 등록된 설치 증거에만 기반하며, 코드 보안 감사와 다릅니다.

출처 추적 가능

공개 플러그인 카탈로그에서 왔으며, 공개 GitHub 저장소로 연결됩니다.

라이선스

GitHub 메타데이터에서 라이선스가 감지되지 않았습니다.

유지보수 활동

최근 180일 내 코드 업데이트가 있습니다.

설치 증거

재현 가능한 정확한 설치 메타데이터가 아직 등록되지 않았습니다. 저장소 설명에 따라 직접 확인하세요.

설치 라이프사이클 스크립트

검사한 패키지 메타데이터에 설치 라이프사이클 스크립트가 선언되지 않았습니다.

주의 사항missing-license