Minimal-anchored agent preset: request #1 keeps the real bash + str_replace_editor pair with auto-injected context stripped, then promotion unlocks the full Standard catalog and posts a one-shot background-jobs notice against sleep-polling habits.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:ruby1304/dsh-preset-anchored-standard
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
An agent preset for DeepSeek Harness (dsh) that anchors a session's first request on the official Minimal preset's real tool pair — persistent bash + str_replace_editor, with auto-injected workspace/skill context stripped — then, after the first durable promotion signal (a tool call or the first assistant message), exposes the full Standard catalog from request #2 on.
Built for trajectory-evaluation runs that need the Minimal anchor at request #1 without giving up Standard capabilities for the rest of the session.
Why the promotion notice
The bootstrap anchor is behavioral, not just structural: a model that opens with only a shell keeps the habits the bootstrap bash description teaches — notably foreground sleep N + pgrep polling for long-running waits — even after the catalog silently expands. We observed a delegated session poll a benchmark with sleep 240 loops for ~90 minutes although job_output / job_list / job_kill were already in its catalog from request #2.
So the preset injects a one-shot user-role notice at the promotion step telling the model the full catalog is now active and that waits longer than ~2 minutes belong in background jobs (run_in_background: true + completion notices), not foreground polling. The notice fires only for sessions the process actually saw bootstrapping — a session resumed after promotion is not interrupted by it.
Install
As a bundle (recommended — the preset syncs into ~/.dsh/.agent-presets/ at boot):
dsh plugin --profile web add "github:ruby1304/dsh-preset-anchored-standard"
Manual:
git clone https://github.com/ruby1304/dsh-preset-anchored-standard.git
cd dsh-preset-anchored-standard
./install.sh # copies presets/anchored-standard into ~/.dsh/.agent-presets/
Then pick Anchored Standard in the preset selector, or set it as the default in ~/.dsh/settings.yaml:
agent-presets:
default: anchored-standard
Uninstall: ./uninstall.sh (or dsh plugin remove plus deleting the preset directory).
Configuration
All knobs live in the tool-bootstrap row of presets/anchored-standard/agent.cordis.yml:
| Key | Default | Meaning |
|---|---|---|
bootstrapTools |
[bash, str_replace_editor] |
Tool catalog exposed on request #1. |
promoteOn |
either |
Promotion signal: tool-call, assistant-message, or either. |
suppressedContextSources |
[agent-instructions, skill-catalog] |
Auto-injected context stripped while bootstrapping ([] disables the filter). |
bootstrapMaxTokens |
unset | Optional output cap for request #1; stripped explicitly after promotion. |
promotionNotice |
built-in text | One-shot notice at the promotion step: custom string, or false to disable. |
Compatibility
Developed and tested against dsh 0.1.0-rc.5. The preset composes only shipped @deepseek-ai/dsh-* plugins plus its own local tool-bootstrap.mjs; no third-party dependencies.
Development
node tests/bootstrap-notice.test.mjs # mock-waterfall test of the promotion-notice logic
License
MIT
Links
More in this category
yjh051108/dsh-routing-suite★ 6990
One repository, three parts: a runtime injector for DSH plugin packages (inject, hot-reload, unload, promote a dev staging tool to the front, route self-heal, plus a settings-page plugin manager that lists, unloads and drags folders in to internalize), a task-aware reasoning-mode router agent preset (router-standard / router-spec / router-react), and a graded two-level task protocol whose six tools (commit_star, lock_stage, revise_do, edit_plan, mark_task, redteam_verdict) pin task state to disk. The injector implementation ships in-tree, so the install carries its own behaviour rather than a dependency list.
strukto-ai/mirage#dsh★ 3670
Swaps the filesystem and bash providers for a mirage virtual workspace: file tools and shell commands run over mounted resources (RAM, S3, Redis, Slack, Gmail, Notion, Postgres) instead of the host disk, with per-mount read/write/exec modes, per-command sandbox routing (monty, pyodide, quickjs in process; docker, e2b, daytona remote), and installed CLIs (git, gh, slack, linear, ntn, gws, or one you register) as head words in the virtual terminal.
hust-open-atom-club/oh-dsh★ 325
Community distribution: TUI, desktop, and Web UI as one bundle with layered installation.
weijiafu14/pi2dsh★ 210
Pi Host ABI compatibility engine: after one install, unmodified Pi extensions from npm mount as native DSH plugins with `dsh plugin add <pi-package>`. Verified end to end on stock DSH with pi-mcp-adapter (full MCP manager: OAuth, resources, prompts, MCP Apps, elicitation, sampling), @tintinweb/pi-subagents, pi-code, pi-hermes-memory and pi-background-tasks; `pi2dsh inspect` reports a package's compatibility before installing.
lire1131/dsh-undo-savepoint★ 168
Undo/redo & rollback system for DSH: every config change is auto-snapshotted; undo/redo/restore to any version from the WebUI or the offline CLI/GUI tools (works even when DSH fails to boot).
Fishquito7/dsh-skill-mcp-panel★ 161
Manages DSH skills and MCP servers from the web settings: skill cards with hot enable/disable, workspace scopes, groups, batch migration and drag-and-drop import, plus stdio/HTTP MCP CRUD with connection tests, secret redaction and the unified dsh-panel CLI.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.