Evidence-first operating kit: six read-only tools (capability catalog, staged workflow plans, packaged skill reader, bounded local memory search, repository release audit, release checklist) and five packaged skills - plans and audits, never remote writes.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:LeslieWylie/dsh-ops-kit
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
Five read-only skills that make an agent show its evidence — before it claims memory, a finished plan, a clean benchmark, or a safe release.
The bundle also includes a runtime doctor for the official PTY prompt handshake, because minimal-mode bash can otherwise look hung when the terminal and persistent-bash plugins use different completion prompts.
Why this exists
Agents are persuasive even when they are wrong. This bundle is built around one rule: before an agent says "I remember this," "the plan is ready," "the benchmark passed," or "the release is safe," it should be able to point at evidence for the claim instead of just asserting it. Five focused skill packs share that discipline — bounded memory search, evidence-based orchestration planning, agent-loop coordination rules, benchmark-result gating, and plugin release hygiene — instead of shipping the same idea as five separate packages that each need their own install and their own place in a plugin index.
Everything here is conservative by default: nothing silently creates issues, calls a remote API, starts a benchmark, mutates a repository, or reads credentials. The bundle gives an agent plans, checks, and evidence vocabulary; anything with a side effect stays an explicit, reviewable action taken outside the bundle.
Install
dsh plugin --profile <profile> add dsh-ops-kit
Installing from the registry means no build step and no allowBuilds approval. The equivalent, if you prefer editing the profile manifest by hand:
// ~/.dsh/profiles/<profile>/package.json
{
"dependencies": {
"dsh-ops-kit": "^0.1.0"
},
"dsh": {
"profile": {
"bundles": ["@deepseek-ai/dsh-base", "@deepseek-ai/dsh-web-app", "dsh-ops-kit"]
}
}
}
Then reinstall dependencies for that profile and restart it.
What's inside
| Capability pack | Tool | What it does | Side effects |
|---|---|---|---|
| Capability index | dsh_ops_capability_catalog |
Lists the included capability packs | None |
| Evidence-based orchestration | dsh_ops_workflow_plan |
Produces a scope → baseline → context → execute → verify → handoff plan for research, multi-agent, benchmark, or release work | None |
| Skill reference | dsh_ops_skill_read |
Reads a packaged full skill definition | None |
| Git-first memory | dsh_ops_memory_search |
Searches bounded local Markdown/code roots for prior context, with source provenance | Read-only |
| Repository audit | dsh_ops_repository_audit |
Audits Git cleanliness, untracked files, and credential-path hygiene | Read-only |
| Release hygiene | dsh_ops_release_checklist |
Produces a complete DSH plugin release checklist | None |
| Release verification | dsh_ops_plugin_doctor |
Checks a plugin repository against the checklist instead of restating it: dsh.bundle + cordis.patch.yml installability, patch row vs package name, private/files/exports publishability, @deepseek-ai/* kept as peers, and boot suites that print SKIPPED then exit 0 |
Read-only |
| Runtime health | dsh_ops_runtime_doctor |
Checks official terminal/persistent-bash prompt compatibility | Read-only |
dsh_ops_release_checklist says what a release needs; dsh_ops_plugin_doctor measures whether it happened. The split is deliberate — a checklist that no one verifies is how a boot suite ended up printing SKIPPED and exiting 0, turning CI green while the integration check never ran, and how a plugin stayed at "private": true and could never be published at all.
Agent-loop orchestration rules (leader-only dispatch, shared-worktree coordination, runtime ownership, cleanup evidence) and benchmark-evidence gating (manifests, prechecks, artifact inventory, result-integrity checks) ride along inside the workflow-plan and release-checklist skills rather than as separate tools.
Configure local roots
When using dsh_ops_memory_search or dsh_ops_repository_audit, configure roots to the directories the profile may inspect. Keep the root narrow and never point it at a credential directory.
# example overlay; adapt to the profile's configuration format
- id: dsh-ops-kit
config:
roots:
- /workspace/project
- /workspace/memory
maxFiles: 120
maxBytesPerFile: 160000
If no roots are configured, the tools default to the DSH process working directory. Credential-like paths and common run/secret directories are rejected or skipped.
Design provenance
This package is a standalone integration layer distilled from general engineering practice, not a copy of any internal source repository. No credentials, raw private data, generated run outputs, or machine-specific configuration belong here.
Verification
pnpm install --offline --ignore-scripts
pnpm build
pnpm typecheck
pnpm test
The package also ships a guarded dsh-terminal-hotfix command. It only patches the known official rc.6 compiled entry after an exact-layout check, creates a timestamped backup, and verifies the prompt handshake afterwards:
dsh-terminal-hotfix --check
dsh-terminal-hotfix --apply
Restart DSH after applying it. The command is intentionally not run by the plugin loader and never silently edits dependencies.
After installing into a live profile, verify that the DSH endpoint returns HTTP 200, the profile stays running after restart, the packaged skills are listed, dsh_ops_capability_catalog returns all capability packs, and dsh_ops_runtime_doctor is healthy. If it reports terminal-prompt-mismatch, use dsh-terminal-hotfix --check before applying a reversible repair; the doctor itself never edits node_modules.
License
See CONTRIBUTING.md and SECURITY.md before contributing.
MIT.
Links
More in this category
Q00/ouroboros#integrations/dsh-plugin★ 6118
Config-only bundle that mounts Ouroboros through the DSH MCP client, exposing 36 interview, Seed, execution, evaluation, and evolution workflow tools in DSH.
loopx-project/loopx#dsh-loopx-plugin★ 6072
LoopX, a provider-neutral, local-first state kernel and control plane for long-horizon agents: keeps Goal, Todo, gate, evidence, quota, recovery, and handoff state above DeepSeek Harness, while the plugin bootstraps the CLI and skills, admits bounded same-session continuation, and adds a loopback GoalBar for the exact bound loop.
chuspeeism/dashi-taskboard#deepseek-harness★ 3244
Embeds the active installed Codex Taskboard runtime in the DeepSeek Harness sidebar, using its launcher runtime descriptor instead of a fixed port.
NanmiCoder/dsh-agent-teams★ 1829
AgentTeams multi-agent teams.
EthanYoQ/AI-Novel-Writer#dsh-ai-novel-writer★ 1149
Installs a dedicated AI novel-writing preset and workbench: revisioned local project assets, a compact side drawer, and native approval-gated single-file changes.
tong-io/tongflow#dsh-tongflow★ 1033
TongFlow film-crew studio for image, voice, music and video production: the agent writes per-asset TongFlow workflow files (.tongflow.json) that run through TongFlow plugins, with an embedded workflow canvas, a shot/character/take project layout and a manga-drama template; sessions starting with @tongflow open the Studio view.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.