dsh-proof
已验证 · 实测可装 EvilIrving
功能简介
只读验收层:验证器把关每轮,引导回代理
可用 — 实测通过,早期项目
只读验收层:验证器把关每轮,引导回代理 实测能干净安装、正常启动。早期项目,但功能可用。
「已验证」表示我们的自动化 CI 在干净 profile 里实际执行了 dsh plugin add 并启动成功——仅此而已。功能描述与版本兼容性均为作者声明。这不是安全审计,也不代表对第三方代码的背书。
README
dsh-proof
Independent read-only acceptance layer for the DeepSeek Harness.
Before each top-level turn closes, dsh-proof spawns a read-only verifier
subagent, collects its structured verdict, and steers any non-pass gaps back
into the driving agent. It is the harness's missing "is the agent actually
done" gate — no other plugin can substitute for it.
Install
dsh plugin --profile <name> add github:EvilIrving/dsh-proof
Or, from a checkout:
dsh plugin --profile <name> add ./dsh-proof
The bundle patch inserts one plugin row (dsh-proof); it needs thesubagents service (the official dsh-subagent providers), which the base
profile already mounts.
How it works
| Step | Mechanism |
|---|---|
| Intercept "about to close" | agent/turn-stopping (serial, awaited before the turn commits) |
| Spawn a read-only verifier | ctx.subagents.start('spawn', …) with toolFilter.deny + outputSchema |
| Block recursion | delegationDepthOf(agent) > 0 filter + maxDepth: 0 |
| Steer gaps back | agent.inject(gap details) + agent.steer(followup) on fail / insufficient-evidence |
The verifier inherits the parent's tool set and is narrowed by the deny list
(see deny list); it never sees a whitelist that could
accidentally hide a newly added read-only tool. A verifier that ends withstopReason !== 'completed' or a missing structured result is treated as
"no objection", so a failed proof never fails the user's turn.
Config
export interface Config {
providerName: string // default 'spawn'
maxAttemptsPerTurn: number // default 3
denyTools: string[] // default mutating-tool deny list
verifierPrompt: string // read-only acceptance instruction
followupInstruction: string // steering text after a failed verdict
}
Set any field from cordis.yml:
plugins:
dsh-proof:
config:
maxAttemptsPerTurn: 2
denyTools: [write, edit, str_replace_editor, bash, run_code, subagent]
Deny list
toolFilter.deny removes tools from the verifier's inherited full set.tools.restrict validates every name loudly, so denyTools must name tools the
deployment actually registers. The default iswrite, edit, str_replace_editor, bash, run_code, subagent, which keeps
read-only discovery tools (read, read_image, glob, grep) available. A
deployment that adds its own mutating tools must extend the list; a deployment
that forbids even shell/read access should switch to an explicit allow
whitelist (set denyTools and verifierPrompt to match, or extend the plugin
for an allowTools field).
Model Experience
Request context and condition
What the model sees
The top-level agent receives an injected user message listing the verifier's
gaps and evidence, followed by the configured followupInstruction. Only a
non-pass verdict injects anything; a passing turn adds nothing.
Token effect
Zero-direct effect on passing turns. A failing turn adds one bounded injected
message (gaps + evidence) plus the short follow-up line.
KV Cache effect
Append-only: the injected context and follow-up are appended as new user
messages, never rewriting earlier request tokens.
Known Limitations and Deferred Work
- Deny list must match the deployment's tools —
tools.restrictfails loud
on unknown names, so a mismatched default blocks verifier startup. The exact
mutating-tool set is deployment-specific and is resolved at first install. - No evidence normalization — the verifier gathers evidence itself; this
plugin does not re-implement diff/test/typecheck/lint. A deployment wanting
specific evidence channels should extendverifierPrompt. - Best-effort spawn — a provider that is absent or rejects the request
degrades to a no-op (logged), rather than failing the user's turn.
安装
装一次目录插件,之后本站所有插件都能让 DeepSeek Harness 自动找、自动装:
dsh plugin add dshbase-catalog 然后对 agent 说「帮我装 dsh-proof」,它会在目录里找到并自动安装。文档:dshbase-catalog · 已验证场景包。
该插件是 GitHub 源码(未发 npm)——直接从仓库装:
Web profile:
dsh plugin --profile web add github:EvilIrving/dsh-proof Headless(CLI)profile:
dsh plugin --profile headless add github:EvilIrving/dsh-proof 实测报告
验证通过:从 GitHub 源码完成 L1 安装 + L2 加载 + L3 运行(dsh 0.1.0-rc.6)。
使用场景
把一个新模型、provider 或路由策略接入循环,让 dsh 能为任务选对脑子。
适合谁
同时用多个模型或 provider、想让成本/质量/延迟自动平衡的人。
二次开发建议
provider 适配器和路由启发式是缝——加后端、调回退链,或加按任务的模型选择。