当原生可续接 DSH 子代理因明确的 max-tokens 终止时自动续接一次,然后停止介入。
安装
# npm 包(预构建)
dsh plugin --profile web add dsh-subagent-watchdog
# GitHub 源码(首次需按提示配置 allowBuilds 构建授权后重试)
dsh plugin --profile web add github:quaner1234-cmd/dsh-subagent-watchdog
装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络,工具审批管不到它。GitHub 来源的插件还会在安装时执行构建脚本——pnpm 默认拦截,所以安装可能停在 ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED 或 ERR_PNPM_IGNORED_BUILDS;dsh 会打印出需要添加的确切键名,把它加进该 profile 的 pnpm-workspace.yaml 的 allowBuilds 下,重跑一次即可装上。放行构建本身就是一次信任判断:请只安装可信来源,并尽量锁定 commit(github:owner/repo#sha)。
README
该插件的 README 只有英文版本。
A DSH plugin that safely recovers native continuable subagents from one high-confidence failure: explicit max-tokens termination.
When a native continuable DSH subagent ends because it hit
max-tokens, Watchdog automatically continues the same child conversation once, then stops. No loops.
Why
When you delegate a task to a continuable subagent in DSH and the child runs out of output tokens mid-task, the runtime ends the turn with stopReason: 'max-tokens', reports the failure to the delegating agent, and stops. The work sits unfinished; the parent has to notice the failure, decide it is recoverable, and manually continue the child.
Watchdog does exactly that one recovery — deterministically, at most once — using only official DSH seams.
What it does
- First
max-tokenson a continuable child — Watchdog observes the terminalturn/end { kind: 'max-tokens' }, starts one official durability checkpoint (sessions.flush) while the child session is still live, waits for normal settlement and checkpoint resolution, then sends exactly one continuation through the officialsubagents.followup()seam. The same durable child conversation cold-resumes in a new activation epoch with a short instruction to continue the unfinished task from its existing state. - Recovered run completes normally — Watchdog stays silent. No messages, no markers, nothing further.
- Second failure (
max-tokensagain, or an explicit runtime/provider error) — Watchdog stops intervening and delivers one notice to the delegating parent with the failure facts and the official manual options (manualsend_message,interrupt_agent, or re-delegating a fresh subagent). - Never recovered — one-shot subagents (DSH exposes no resume seam for them), normal completion, clean aborts, refusals, unknown future stop reasons, and any first-seen outcome that is an error rather than
max-tokens. Provider/model errors are reported, never auto-retried. - No persistence / unverifiable children — recovery decisions verify the child's durable log through the official persistence seam when available; a child whose continuable mode cannot be verified is skipped, never guessed. Without durable session logs the restart-safe "already continued" marker cannot be consulted across restarts, so protection there rests on the process-lifetime guard alone.
The continue-once guarantee is enforced against the child's durable session id (stable across activation epochs) plus a continuation marker written into the child's own durable log — repeated events, plugin restarts, or duplicate settlements cannot cause a second automatic continuation.
Install
Through the ordinary DSH plugin path (verified on dsh 0.1.1-rc.2):
dsh plugin --profile <profile> add dsh-subagent-watchdog
or from a local tarball:
npm pack
dsh plugin --profile <profile> add ./dsh-subagent-watchdog-0.1.0.tgz
The package declares dsh.bundle.patch; dsh plugin add reconciles it into the profile's bundle stack automatically. Zero dependencies, no build step, Node >= 20.
Safety and non-goals
- At most one automatic continuation per child task/recovery chain.
max-tokensis the only automatic recovery trigger.- No timers, no polling, no custom persistence, no private runtime APIs — official seams only.
- No second LLM deciding whether recovery is needed; no dashboard, no DAG, no team manager, no heuristic stuck detector.
Compatibility
Live-tested end-to-end against @deepseek-ai/dsh 0.1.1-rc.2 only. No broader compatibility is claimed or tested.
Verification and evidence
- Local suite: 38 scenarios over both shipped artifacts (
lib/index.jsand the derived dynamic-package body) against real cordis/dsh-subagent/dsh-sessiondispatch —node --test test/watchdog.test.mjs. - Final packaged re-validation directly observed a real native continuable child end with explicit
max-tokens, the same durable child session id start a new activation under a fresh runId 68 ms after settlement, exactly one durablesubagent-watchdog/relaymarker remain present across later inspection, and the recovered activation complete normally with no watchdog failure notice. - The checkpoint-before-followup ordering and genuine
AbortSignalplumbing are supported by prior instrumented live probes plus the deterministic suite; they were not independently emitted as explicit records in the final packaged trace.
The full verified seam survey and evidence log lives in docs/DSH-SEAMS.md. The final acceptance phase crossed its original one-run/STOP boundary during debugging; that protocol deviation and the resulting evidence calibration are recorded in docs/PROTOCOL-DEVIATION-2026-08-23.md.
License
链接
同类插件
Q00/ouroboros#integrations/dsh-plugin★ 6194
通过 DSH MCP 客户端挂载 Ouroboros 的纯配置包,在 DSH 中提供 36 个涵盖需求访谈、Seed、执行、评估与演化流程的工具。
loopx-project/loopx#dsh-loopx-plugin★ 6188
LoopX——面向长周期 Agent 的提供商中立、本地优先状态内核与控制平面:在 DeepSeek Harness 执行层之上持久化 Goal、Todo、门禁、证据、配额、恢复与交接状态;插件负责引导安装 CLI 与技能、准入有界的同会话续跑,并为精确绑定的工作循环提供本地 GoalBar。
chuspeeism/dashi-taskboard#deepseek-harness★ 3299
把当前已安装并运行中的 Codex Taskboard 嵌入 DeepSeek Harness 侧边栏,并通过 Launcher 运行时描述文件连接,而不是使用固定端口。
NanmiCoder/dsh-agent-teams★ 1959
AgentTeams 多智能体团队。
EthanYoQ/AI-Novel-Writer#dsh-ai-novel-writer★ 1347
安装专用 AI 小说创作预设与工作台:提供带修订号的本地项目资产、紧凑侧边工作台,以及需要原生审批的逐文件变更。
tong-io/tongflow#dsh-tongflow★ 1041
基于 TongFlow 的“片场”插件,用于图片、配音、音乐与视频制作:agent 为每个资产生成 TongFlow 工作流文件(.tongflow.json)并通过 TongFlow 插件执行,内嵌工作流画布,按镜头/角色/take 组织项目,附漫剧模板;以 @tongflow 开头的会话进入 Studio 界面。
社区评论
评论公开保存在 GitHub Discussions。加载评论会连接 GitHub 和 Giscus;发表内容需要 GitHub 账号。