只在会话首轮把工具清单裁剪到白名单并注入一段结构化前言,之后每一轮原样放行。
安装
# GitHub 源码(首次需按提示配置 allowBuilds 构建授权后重试)
dsh plugin --profile web add github:rand0wn/dsh-minimal-anchor
装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络,工具审批管不到它。GitHub 来源的插件还会在安装时执行构建脚本——pnpm 默认拦截,所以安装可能停在 ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED 或 ERR_PNPM_IGNORED_BUILDS;dsh 会打印出需要添加的确切键名,把它加进该 profile 的 pnpm-workspace.yaml 的 allowBuilds 下,重跑一次即可装上。放行构建本身就是一次信任判断:请只安装可信来源,并尽量锁定 commit(github:owner/repo#sha)。
README
该插件的 README 只有英文版本。
A DeepSeek Harness (dsh) plugin that shields turn 1 from tool-schema overload.
Why
A fresh dsh session hands the model the entire configured toolset — file
edits, bash, subagents, jobs — on message one, even when the first message is
just "look at this repo and tell me what's going on." A smaller, focused
schema on that first turn keeps the model's early reasoning on exploration
instead of premature action, without touching how any later turn behaves.
dsh-minimal-anchor hooks the harness's own prompt-assembly pipeline to:
- Prune tools on turn 1 only — down to a configurable whitelist (default:
read,glob,grep). - Prepend a short structural preamble on that same turn, framing the session as exploration-first.
- Get out of the way from turn 2 onward — every later assembly for that session passes through completely untouched, full toolset restored.
Install
dsh plugin --profile <name> add dsh-minimal-anchor
or from a local checkout:
dsh plugin --profile <name> add /path/to/dsh-minimal-anchor
This adds the package as a dependency of the profile, but does not by
itself activate it — dsh only applies a package's dsh.bundle patch for
packages listed in that profile's dsh.profile.bundles. Add the package
name to that list in profiles/<name>/package.json:
{
"dsh": {
"profile": {
"bundles": [
"@deepseek-ai/dsh-base",
"@deepseek-ai/dsh-headless",
"dsh-minimal-anchor"
]
}
}
}
Confirm it composed with dsh --profile <name> --dump-config — you should
see a minimal-anchor entry. (An equivalent alternative that skips the
bundles list entirely: insert it directly in your own
profiles/<name>/cordis.patch.yml — see Configuration.)
Usage
Nothing to invoke — it's a passive plugin. Boot your profile as usual
(dsh web, dsh --profile headless "...", etc.) and the first turn of every
new session goes out with the pruned tool list and preamble automatically.
Configuration
# profiles/<name>/cordis.patch.yml
- insert:
- id: minimal-anchor
name: 'dsh-minimal-anchor'
config:
whitelistedTools: [read, glob, grep]
enforcePreamble: true
customPreamble: 'Your own turn-1 framing text.'
| Field | Default | Description |
|---|---|---|
whitelistedTools |
[read, glob, grep] |
Tool names kept on turn 1. Must match the exact registered tool names in your profile — check dsh --profile <name> --dump-config if unsure, names differ from plugin to plugin. |
enforcePreamble |
true |
Whether to prepend the structural preamble section on turn 1. |
customPreamble |
(built-in exploration-framing text) | Preamble text, used only when enforcePreamble is true. |
Extending rather than replacing the default whitelist? DEFAULT_WHITELISTED_TOOLS
and DEFAULT_PREAMBLE are exported from the package if you're composing config
in TypeScript rather than YAML.
How it works
Hooks the system-prompt/assemble waterfall from
@deepseek-ai/dsh-system-prompt,
which runs once per turn and produces the PromptAssembly (sections, tools,
contexts) actually sent to the model. A WeakSet keyed on the assembly's
scope tracks whether that scope has assembled before; the first time, it
filters assembly.tools to the whitelist and unshifts the preamble section,
then calls next() so every other listener in the waterfall still runs
normally. Every later assembly for that scope short-circuits straight to
next() — no mutation, no persisted per-session state beyond the WeakSet
entry, which needs no explicit teardown since it dies with the scope object.
There is no agent/request or per-message hook in the real harness — this
plugin does not use one, unlike an earlier draft of this same idea that
assumed events that don't exist in dsh.
Troubleshooting
Turn 1's tool list came back empty. whitelistedTools matches on the
exact registered tool name — these differ per harness install and per other
plugins you have active. Check the real names with
dsh --profile <name> --dump-config, or open the Trajectory tab in the web
UI for a session and look at the Tools panel on "Initial System Prompt". An
early draft of this plugin shipped with guessed names (read_file,
list_dir, search_files) that don't exist in the real harness — the
whitelist silently matched nothing and pruned every tool.
Plugin doesn't seem to load / no minimal-anchor entry in --dump-config.
Being a listed dependency of the profile (e.g. after dsh plugin add) is
not enough — the package also needs to be in that profile's
dsh.profile.bundles list (see Install) before its dsh.bundle
patch gets applied.
Loader crashes with Cannot read properties of undefined (reading 'validate')
on a fork. A Cordis plugin's exported Config must be a schemastery
schema (z.object({...})), not a plain object — the loader calls
.validate on whatever Config exports.
Development
npm install
npm run typecheck
npm test
Verified against a real local dsh boot (not just types): installed into a
scratch profile, patched in, and run against a live model — the outbound
request on turn 1 carried exactly the whitelisted tools and the preamble
text, and turn 2 carried the full toolset with no preamble.
License
MIT
链接
同类插件
yjh051108/dsh-routing-suite★ 7001
一个仓库三件套:DSH 插件包的运行时注入器(注入、热重载、卸载、开发侧挂区一键转正、路由自愈,外带设置页插件管理:列出、卸载、拖入文件夹内化)、任务感知的思维模式路由 agent 预设(router-standard / router-spec / router-react)、以及分级两级任务协议(commit_star / lock_stage / revise_do / edit_plan / mark_task / redteam_verdict 六个工具,任务状态落盘)。注入器实现直接在库内,安装的是它自己的行为而不是一份依赖清单。
strukto-ai/mirage#dsh★ 3677
把文件系统与 bash 提供者换成 mirage 虚拟工作区:文件工具与 shell 命令作用于挂载的资源(RAM、S3、Redis、Slack、Gmail、Notion、Postgres)而非宿主磁盘,支持按挂载点设置读/写/执行模式、按命令选择沙箱(进程内 monty、pyodide、quickjs;远程 docker、e2b、daytona),并可在虚拟终端中安装 CLI(git、gh、slack、linear、ntn、gws,或自行注册的程序树)作为命令头词。
hust-open-atom-club/oh-dsh★ 325
社区发行版:TUI、桌面端与 Web UI 统一体验,分层安装、一步到位。
weijiafu14/pi2dsh★ 212
Pi Host ABI 兼容引擎:装一次之后,npm 上的 Pi 扩展原包经 `dsh plugin add <pi-package>` 直接作为 DSH 原生插件挂载。已在官方 DSH 上端到端验证 pi-mcp-adapter(完整 MCP 管理面:OAuth、resources、prompts、MCP Apps、elicitation、sampling)、@tintinweb/pi-subagents、pi-code、pi-hermes-memory、pi-background-tasks;`pi2dsh inspect` 在安装前报告一个包的兼容情况。
Fishquito7/dsh-skill-mcp-panel★ 174
在 DSH Web 设置中管理技能与 MCP 服务器:技能卡片热启停、工作区作用域、分组、批量迁移与拖拽导入,以及 stdio/HTTP MCP 增删改查、连接测试、密钥脱敏,并附带统一 dsh-panel 命令行。
lire1131/dsh-undo-savepoint★ 171
DSH 撤销/回退系统:配置变更自动存档,一键撤销/恢复/回退到任意版本,支持 WebUI 与离线 CLI/GUI 工具(DSH 启动失败也能救)。
社区评论
评论公开保存在 GitHub Discussions。加载评论会连接 GitHub 和 Giscus;发表内容需要 GitHub 账号。