/repro exports a minimal, secret-scrubbed, replayable problem bundle: the session log, failed commands, and Git diff.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:EvilIrving/dsh-repro
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
Export a minimal, secret-scrubbed, replayable problem bundle for the DeepSeek Harness.
/repro reads the current session's complete canonical log through
sessionPersistence.inspect, scrubs secrets value by value, collects failed
commands and a git diff, and writes a repro-<sessionId>.json manifest.
Install
dsh plugin --profile <name> add github:EvilIrving/dsh-repro
Or, from a checkout:
dsh plugin --profile <name> add ./dsh-repro
The bundle patch inserts one plugin row (dsh-repro); it needs the
commands and sessionPersistence services, which the base profile already
mounts.
What the bundle contains
interface ReproManifest {
formatVersion: number // 1
header: SessionHeader // cwd, lineage, delegation depth
events: SessionEvent[] // complete, secret-scrubbed canonical log
failedCommands: string[] // `name <arguments>` for each errored tool call
gitDiff: string // empty when git or a repo is unavailable
versions: Record<string, string>
}
The events array is the full canonical log (contiguous from seq 0), so it can
later be replayed via ctx.sessions.create(id, { seed }); secrets are redacted,
not dropped, which preserves replay balance.
Secret scrubbing (fail-closed)
redactValue walks the detached JSON log and:
- redacts any object key matching the harness's credential pattern
(
/KEY|PASSWORD|SECRET|TOKEN/i) whole; - redacts any string beginning with a known token prefix (
sk-,ghp_,xoxb-,Bearer, …); - redacts any high-entropy run (long base64/hex/token-shaped sequence).
Both prefix and entropy thresholds are Config-driven. The default is
fail-closed: a string that looks credential-shaped is redacted rather than
passed through. This mirrors session-telemetry's waterfall shape (rewrite an
outbound copy, never the canonical log) while supplying the value-level rules
the telemetry seam deliberately ships without.
Config
export interface Config {
tokenPrefixes: string[]
minHighEntropyLength: number // default 20
gitDiffMaxBytes: number // default 256 KiB
gitGraceMs: number // default 5000
}
Dependencies
commandsandsessionPersistenceare hard dependencies (inject).subprocessis optional (ctx.get):git diffdegrades to an empty string when it is absent or the cwd is not a repository.
Model Experience
Request context and condition
What the model sees
A single slash command /repro [output directory]. Its result is a one-line
success message naming the written bundle path; the bundle contents are never
injected into the model context.
Token effect
Zero-direct effect; the command result is a single short text line.
KV Cache effect
Append-only: the command lifecycle events (command/run, command/done) append
to the log and never rewrite earlier tokens.
Known Limitations and Deferred Work
- Bundle write bypasses the sandboxed
ctx.fsseam — v1 usesnode:fs/promisesdirectly; routing the write throughctx.fs(so a sandboxed deployment constrains the output path) is deferred. - Replay CLI is out of scope —
dsh repro run <bundle>is a separate process-level seam (boot/cmdline+cmdlineArgs), not/repro; v1 only exports. - No oversized-artifact inlining — spill artifacts are referenced by locator, never inlined; any file-byte inlining would need a size policy.
Links
More in this category
yjh051108/dsh-routing-suite★ 7000
One repository, three parts: a runtime injector for DSH plugin packages (inject, hot-reload, unload, promote a dev staging tool to the front, route self-heal, plus a settings-page plugin manager that lists, unloads and drags folders in to internalize), a task-aware reasoning-mode router agent preset (router-standard / router-spec / router-react), and a graded two-level task protocol whose six tools (commit_star, lock_stage, revise_do, edit_plan, mark_task, redteam_verdict) pin task state to disk. The injector implementation ships in-tree, so the install carries its own behaviour rather than a dependency list.
strukto-ai/mirage#dsh★ 3663
Swaps the filesystem and bash providers for a mirage virtual workspace: file tools and shell commands run over mounted resources (RAM, S3, Redis, Slack, Gmail, Notion, Postgres) instead of the host disk, with per-mount read/write/exec modes, per-command sandbox routing (monty, pyodide, quickjs in process; docker, e2b, daytona remote), and installed CLIs (git, gh, slack, linear, ntn, gws, or one you register) as head words in the virtual terminal.
hust-open-atom-club/oh-dsh★ 325
Community distribution: TUI, desktop, and Web UI as one bundle with layered installation.
weijiafu14/pi2dsh★ 206
Pi Host ABI compatibility engine: after one install, unmodified Pi extensions from npm mount as native DSH plugins with `dsh plugin add <pi-package>`. Verified end to end on stock DSH with pi-mcp-adapter (full MCP manager: OAuth, resources, prompts, MCP Apps, elicitation, sampling), @tintinweb/pi-subagents, pi-code, pi-hermes-memory and pi-background-tasks; `pi2dsh inspect` reports a package's compatibility before installing.
lire1131/dsh-undo-savepoint★ 165
Undo/redo & rollback system for DSH: every config change is auto-snapshotted; undo/redo/restore to any version from the WebUI or the offline CLI/GUI tools (works even when DSH fails to boot).
Fishquito7/dsh-skill-mcp-panel★ 152
Manages DSH skills and MCP servers from the web settings: skill cards with hot enable/disable, workspace scopes, groups, batch migration and drag-and-drop import, plus stdio/HTTP MCP CRUD with connection tests, secret redaction and the unified dsh-panel CLI.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.