独立只读验收层:顶层 turn 收尾前 spawn 只读 verifier,未通过时把缺口注回主 agent。
安装
# GitHub 源码(首次需按提示配置 allowBuilds 构建授权后重试)
dsh plugin --profile web add github:EvilIrving/dsh-proof
装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络,工具审批管不到它。GitHub 来源的插件还会在安装时执行构建脚本——pnpm 默认拦截,所以安装可能停在 ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED 或 ERR_PNPM_IGNORED_BUILDS;dsh 会打印出需要添加的确切键名,把它加进该 profile 的 pnpm-workspace.yaml 的 allowBuilds 下,重跑一次即可装上。放行构建本身就是一次信任判断:请只安装可信来源,并尽量锁定 commit(github:owner/repo#sha)。
README
该插件的 README 只有英文版本。
Independent read-only acceptance layer for the DeepSeek Harness.
Before each top-level turn closes, dsh-proof spawns a read-only verifier
subagent, collects its structured verdict, and steers any non-pass gaps back
into the driving agent. It is the harness's missing "is the agent actually
done" gate — no other plugin can substitute for it.
Install
dsh plugin --profile <name> add github:EvilIrving/dsh-proof
Or, from a checkout:
dsh plugin --profile <name> add ./dsh-proof
The bundle patch inserts one plugin row (dsh-proof); it needs the
subagents service (the official dsh-subagent providers), which the base
profile already mounts.
How it works
| Step | Mechanism |
|---|---|
| Intercept "about to close" | agent/turn-stopping (serial, awaited before the turn commits) |
| Spawn a read-only verifier | ctx.subagents.start('spawn', …) with toolFilter.deny + outputSchema |
| Block recursion | delegationDepthOf(agent) > 0 filter + maxDepth: 0 |
| Steer gaps back | agent.inject(gap details) + agent.steer(followup) on fail / insufficient-evidence |
The verifier inherits the parent's tool set and is narrowed by the deny list
(see deny list); it never sees a whitelist that could
accidentally hide a newly added read-only tool. A verifier that ends with
stopReason !== 'completed' or a missing structured result is treated as
"no objection", so a failed proof never fails the user's turn.
Config
export interface Config {
providerName: string // default 'spawn'
maxAttemptsPerTurn: number // default 3
denyTools: string[] // default mutating-tool deny list
verifierPrompt: string // read-only acceptance instruction
followupInstruction: string // steering text after a failed verdict
}
Set any field from cordis.yml:
plugins:
dsh-proof:
config:
maxAttemptsPerTurn: 2
denyTools: [write, edit, str_replace_editor, bash, run_code, subagent]
Deny list
toolFilter.deny removes tools from the verifier's inherited full set.
tools.restrict validates every name loudly, so denyTools must name tools the
deployment actually registers. The default is
write, edit, str_replace_editor, bash, run_code, subagent, which keeps
read-only discovery tools (read, read_image, glob, grep) available. A
deployment that adds its own mutating tools must extend the list; a deployment
that forbids even shell/read access should switch to an explicit allow
whitelist (set denyTools and verifierPrompt to match, or extend the plugin
for an allowTools field).
Model Experience
Request context and condition
What the model sees
The top-level agent receives an injected user message listing the verifier's
gaps and evidence, followed by the configured followupInstruction. Only a
non-pass verdict injects anything; a passing turn adds nothing.
Token effect
Zero-direct effect on passing turns. A failing turn adds one bounded injected message (gaps + evidence) plus the short follow-up line.
KV Cache effect
Append-only: the injected context and follow-up are appended as new user messages, never rewriting earlier request tokens.
Known Limitations and Deferred Work
- Deny list must match the deployment's tools —
tools.restrictfails loud on unknown names, so a mismatched default blocks verifier startup. The exact mutating-tool set is deployment-specific and is resolved at first install. - No evidence normalization — the verifier gathers evidence itself; this
plugin does not re-implement diff/test/typecheck/lint. A deployment wanting
specific evidence channels should extend
verifierPrompt. - Best-effort spawn — a provider that is absent or rejects the request degrades to a no-op (logged), rather than failing the user's turn.
链接
同类插件
Q00/ouroboros#integrations/dsh-plugin★ 6118
通过 DSH MCP 客户端挂载 Ouroboros 的纯配置包,在 DSH 中提供 36 个涵盖需求访谈、Seed、执行、评估与演化流程的工具。
loopx-project/loopx#dsh-loopx-plugin★ 6072
LoopX——面向长周期 Agent 的提供商中立、本地优先状态内核与控制平面:在 DeepSeek Harness 执行层之上持久化 Goal、Todo、门禁、证据、配额、恢复与交接状态;插件负责引导安装 CLI 与技能、准入有界的同会话续跑,并为精确绑定的工作循环提供本地 GoalBar。
chuspeeism/dashi-taskboard#deepseek-harness★ 3244
把当前已安装并运行中的 Codex Taskboard 嵌入 DeepSeek Harness 侧边栏,并通过 Launcher 运行时描述文件连接,而不是使用固定端口。
NanmiCoder/dsh-agent-teams★ 1829
AgentTeams 多智能体团队。
EthanYoQ/AI-Novel-Writer#dsh-ai-novel-writer★ 1149
安装专用 AI 小说创作预设与工作台:提供带修订号的本地项目资产、紧凑侧边工作台,以及需要原生审批的逐文件变更。
tong-io/tongflow#dsh-tongflow★ 1033
基于 TongFlow 的“片场”插件,用于图片、配音、音乐与视频制作:agent 为每个资产生成 TongFlow 工作流文件(.tongflow.json)并通过 TongFlow 插件执行,内嵌工作流画布,按镜头/角色/take 组织项目,附漫剧模板;以 @tongflow 开头的会话进入 Studio 界面。
社区评论
评论公开保存在 GitHub Discussions。加载评论会连接 GitHub 和 Giscus;发表内容需要 GitHub 账号。