dsh-supervisor
Lifecycle supervision, evidence-driven audit subagents, safe intervention, and blind acceptance gates for DeepSeek Harness
docjlm
@docjlm
⬇ 1
★ 0
main
安装
dsh plugin --profile web add github:docjlm/dsh-supervisor
需要可复现安装时,可在仓库后追加 #commit 固定提交。
Lifecycle supervision, evidence-driven audit subagents, safe intervention, and blind acceptance gates for DeepSeek Harness
该插件未提供要点说明,请参考仓库 README。
auditdeepseekdeepseek-harnessdsh-pluginsupervisorai-agents
- 安装并启动 DeepSeek Harness:
npx @deepseek-ai/dsh web - 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
- 用 dsh plugins list 确认已安装,必要时重启 Harness 生效
插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。
| 代码仓库 | github.com/docjlm/dsh-supervisor |
| 许可证 | MIT |
| 主要语言 | main |
| 下载量 | 1 |
| GitHub 星标 | 0 |
| 最近推送 | 2026-08-19 |
| 收录日期 | 2026-09-19 |
| 分类 | 安全与权限 |
事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。
以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。
# DSH Supervisor
DSH Supervisor is a lifecycle supervision and acceptance-control plugin for [DeepSeek Harness (DSH)](https://github.com/deepseek-ai/deepseek-harness). It records deterministic facts continuously, asks isolated audit subagents for semantic review only at high-value checkpoints, and applies bounded intervention policies before a task can be accepted.
It complements, rather than replaces, specialist subagents: audit agents provide independent depth, while the Supervisor owns state, evidence, deduplication, intervention, recovery, and the final acceptance gate.
> DSH Supervisor is an early `0.1.x` release. Use it as an additional control layer, not as a substitute for sandboxing, backups, code review, or deployment controls.
[中文文档](./README.zh-CN.md) · [Architecture](https://github.com/DocJlm/dsh-supervisor/blob/main/docs/architecture.md) · [Security policy](https://github.com/DocJlm/dsh-supervisor/blob/main/SECURITY.md) · [Changelog](https://github.com/DocJlm/dsh-supervisor/blob/main/CHANGELOG.md)
## What it does
- Creates an append-only, versioned acceptance contract from user requirements and supplies this authority policy to audit components: latest user instruction → latest acceptance contract → repository rules → execution plan → audit advice.
- Records file, tool, validation, agent, and checkpoint facts without calling a model for every event.
- Runs deterministic guards for failures, risky external operations, and likely credential exposure.
- Selects up to three isolated audit roles at semantic checkpoints: requirements, architecture, testing, security, UI, or documentation/data.
- Produces one deduplicated correction package per checkpoint and routes it as an emergency stop, next-step steer, queued correction, or report-only finding.
- Tracks findings with stable `SUP--` IDs and the `open`, `fixed`, `rejected`, `waived`, and `unresolved` lifecycle.
- Performs a blind final audit from the original request, latest contract, current contract/revision-bound final evidence, and current validation evidence—not from the main agent's explanation or hidden reasoning.
- Persists a redacted JSONL ledger and a human-readable Markdown report, and exposes a polling, read-only Web panel.
New ideas are report-only by default. They do not expand task scope unless the latest user instruction adopts them or they directly satisfy the existing acceptance contract.
## Requirements
- Node.js `22.19+` or `24+`
- `pnpm` available on `PATH` for the DSH plugin installer
- `@deepseek-ai/dsh@0.1.0-rc.7` or a compatible `0.1.x` build
- A DeepSeek-compatible audit credential supplied through the DSH credential service, `DEEPSEEK_API_KEY`, or an explicitly configured key file
## Install
Install the host plugin and its Web client into the Web profile:
```sh
dsh plugin --profile web add dsh-supervisor@0.1.0
```
The package bundle patch inserts the `dsh-supervisor` service. Restart the affected DSH host/Web process after installation if it is already running.
## Configure credentials
Prefer the DSH credential service. Environment variables are the next choice:
```sh
# POSIX shells
export DEEPSEEK_API_KEY="your-api-key"
```
```powershell
# PowerShell
$env:DEEPSEEK_API_KEY = "your-api-key"
```
For a local, uncommitted key file, point the bundle configuration at a path through an environment variable:
```powershell
$env:DSH_SUPERVISOR_API_KEY_FILE = "C:\private\deepseek-api-key.txt"
```
The file should contain only the key (surrounding whitespace is ignored). Never commit the key, the file, or a literal machine-specific path. Credential resolution order is: DSH credential service → configured environment variable → configured key file.
The default patch is equivalent to:
```yaml
- insert:
- id: dsh-supervisor
name: dsh-supervisor
config:
enabled: true
model: deepseek-v4-pro
reasoningEffort: high
apiKeyEnv: DEEPSEEK_API_KEY
apiKeyFile: !!js process.env.DSH_SUPERVISOR_API_KEY_FILE
includeRecentReasoning: false
maxAuditRoles: 3
maxAuditRetries: 3
auditDeadlineMs: 300000
allowAuditDegradedForLocal: true
```
Important defaults:
| Setting | Default | Meaning |
|---|---:|---|
| `includeRecentReasoning` | `false` | Raw execution-agent reasoning is not collected. Explicit diagnostic opt-in stores it as redacted, untrusted checkpoint evidence; it remains outside final blind-audit input and the Markdown report. |
| `maxAuditRoles` | `3` | Maximum audit roles selected at one checkpoint. |
| `maxAuditRetries` | `3` | Infrastructure retries after the first audit attempt. |
| `auditDeadlineMs` | `300000` | One monotonic five-minute window including attempts, queueing, and backoff. |
| `auditAttemptTimeoutMs` | `90000` | Per-attempt ceiling, also capped by the remaining audit window. |
| `auditBackoffMs` | `5000, 15000, 30000` | Retry delays for audit infrastructure errors. |
| `allowAuditDegradedForLocal` | `true` | Allows a local-only task to close with an explicit degraded warning after deterministic validation passes. |
| `sameClassHardLimit` / `totalHardLimit` | `2` / `5` | Circuit breakers for model-driven hard intervention; deterministic safety guards remain active. |
`SupervisorConfig` supports per-task and per-role model routing, call budgets, and Token budgets. The dispatcher checks budget headroom before a role batch or retry, reserves concurrent output allowances, and forwards each available output ceiling to supported providers. Call budgets are enforced per recorded backend call. Token budgets are a concurrency-safe output reservation plus a soft total-usage ceiling: input and separately reported reasoning Tokens are known only after a call, so that call can take the reported total above the configured limit; later calls are then blocked. Role-specific provider/model routes apply to DSH subagents; the direct fallback uses the top-level DeepSeek model configuration.
`validationScriptNames` controls validation-command recognition and `package.json` script discovery. The Host discovers scripts when a root run opens and refreshes them immediately before completion or completion recovery. Every configured script that is then present is required; no script name, including `check`, is assumed to aggregate the others. Repository-script evidence must use the exact foreground form ` run
数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。