dshbase

Plugin directory / Developer / dsh-repro

dsh-repro

Verified · install-tested on dsh EvilIrving

✓ Actively maintained Builds on 6 official DSH packages Pure TypeScript

View on GitHub ↗ ← Back to plugin directory

1Stars
0Forks
0Open issues
TypeScriptLanguage
2026-08-14Last push
Cross-platformPlatform

What it does

Minimal, secret-scrubbed, replayable problem bundles for DeepSeek Harness sessions (/repro).

✅
Our take
Works — verified, early-stage project

Minimal, secret-scrubbed, replayable problem bundles for DeepSeek Harness sessions (/repro). It installs cleanly and boots without issues in our testing. It's early-stage but functional.

“Verified” means our automated CI actually ran dsh plugin add in a clean profile and it booted — nothing more. Feature descriptions and version compatibility are the author’s claims. This is not a security audit and not an endorsement of third-party code.

README

dsh-repro

Export a minimal, secret-scrubbed, replayable problem bundle for the DeepSeek
Harness.

Awesome DSH Plugin

/repro reads the current session's complete canonical log through
sessionPersistence.inspect, scrubs secrets value by value, collects failed
commands and a git diff, and writes a repro-<sessionId>.json manifest.

Install

dsh plugin --profile <name> add github:EvilIrving/dsh-repro

Or, from a checkout:

dsh plugin --profile <name> add ./dsh-repro

The bundle patch inserts one plugin row (dsh-repro); it needs the
commands and sessionPersistence services, which the base profile already
mounts.

What the bundle contains

interface ReproManifest {
  formatVersion: number          // 1
  header: SessionHeader          // cwd, lineage, delegation depth
  events: SessionEvent[]         // complete, secret-scrubbed canonical log
  failedCommands: string[]       // `name <arguments>` for each errored tool call
  gitDiff: string                // empty when git or a repo is unavailable
  versions: Record<string, string>
}

The events array is the full canonical log (contiguous from seq 0), so it can
later be replayed via ctx.sessions.create(id, { seed }); secrets are redacted,
not dropped, which preserves replay balance.

Secret scrubbing (fail-closed)

redactValue walks the detached JSON log and:

  1. redacts any object key matching the harness's credential pattern
    (/KEY|PASSWORD|SECRET|TOKEN/i) whole;
  2. redacts any string beginning with a known token prefix (sk-, ghp_,
    xoxb-, Bearer , 锟斤拷);
  3. redacts any high-entropy run (long base64/hex/token-shaped sequence).

Both prefix and entropy thresholds are Config-driven. The default is
fail-closed: a string that looks credential-shaped is redacted rather than
passed through. This mirrors session-telemetry's waterfall shape (rewrite an
outbound copy, never the canonical log) while supplying the value-level rules
the telemetry seam deliberately ships without.

Config

export interface Config {
  tokenPrefixes: string[]
  minHighEntropyLength: number  // default 20
  gitDiffMaxBytes: number       // default 256 KiB
  gitGraceMs: number            // default 5000
}

Dependencies

  • commands and sessionPersistence are hard dependencies (inject).
  • subprocess is optional (ctx.get): git diff degrades to an empty string
    when it is absent or the cwd is not a repository.

Model Experience

Request context and condition

What the model sees

A single slash command /repro [output directory]. Its result is a one-line
success message naming the written bundle path; the bundle contents are never
injected into the model context.

Token effect

Zero-direct effect; the command result is a single short text line.

KV Cache effect

Append-only: the command lifecycle events (command/run, command/done) append
to the log and never rewrite earlier tokens.

Known Limitations and Deferred Work

  • Bundle write bypasses the sandboxed ctx.fs seam 锟斤拷 v1 uses
    node:fs/promises directly; routing the write through ctx.fs (so a
    sandboxed deployment constrains the output path) is deferred.
  • Replay CLI is out of scope 锟斤拷 dsh repro run <bundle> is a separate
    process-level seam (boot/cmdline + cmdlineArgs), not /repro; v1 only
    exports.
  • No oversized-artifact inlining 锟斤拷 spill artifacts are referenced by
    locator, never inlined; any file-byte inlining would need a size policy.

Install

🧩 Let your agent install it (recommended)

Install the catalog once, then DeepSeek Harness can find and install any plugin from this site automatically:

dsh plugin add dshbase-catalog

Then say "install dsh-repro for me" — your agent finds it in the directory and installs it. Docs: dshbase-catalog · verified packs.

This plugin is GitHub source (not published to npm) — install it straight from the repo:

Web profile:

dsh plugin --profile web add github:EvilIrving/dsh-repro

Headless (CLI) profile:

dsh plugin --profile headless add github:EvilIrving/dsh-repro

Test report

Verified: L1 install + L2 load + L3 runtime from GitHub source on dsh 0.1.0-rc.6.

When to use it

Extend the agent's coding surface — give it a new tool, workflow, or integration so it handles a dev task it couldn't before.

Who it's for

Developers who want dsh to behave like a teammate on real codebases — editing, running, and verifying changes rather than just answering.

For developers — extending it

The tool/command surface is the seam: expose more of the SDK, add smarter context wiring, or tighten the loop between code changes and verification.

Security: not yet scanned — our daily static scan will cover it shortly.

Share this badge

More in Developer

Browse all 7797 plugins →