Skills Plugins MCP Prompt Model 导航 博客 资讯 我的中心
安全与权限 #audit#deepseek#deepseek-harness#dsh-plugin#supervisor#ai-agents

dsh-supervisor

Lifecycle supervision, evidence-driven audit subagents, safe intervention, and blind acceptance gates for DeepSeek Harness

docjlm @docjlm ⬇ 1 ★ 0 main

安装

dsh plugin --profile web add github:docjlm/dsh-supervisor
下载安装清单

需要可复现安装时,可在仓库后追加 #commit 固定提交。

Lifecycle supervision, evidence-driven audit subagents, safe intervention, and blind acceptance gates for DeepSeek Harness

该插件未提供要点说明,请参考仓库 README。

auditdeepseekdeepseek-harnessdsh-pluginsupervisorai-agents
  1. 安装并启动 DeepSeek Harness:npx @deepseek-ai/dsh web
  2. 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
  3. 用 dsh plugins list 确认已安装,必要时重启 Harness 生效

插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。

代码仓库github.com/docjlm/dsh-supervisor
许可证MIT
主要语言main
下载量1
GitHub 星标0
最近推送2026-08-19
收录日期2026-09-19
分类安全与权限

事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。

以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。

# DSH Supervisor

DSH Supervisor is a lifecycle supervision and acceptance-control plugin for [DeepSeek Harness (DSH)](https://github.com/deepseek-ai/deepseek-harness). It records deterministic facts continuously, asks isolated audit subagents for semantic review only at high-value checkpoints, and applies bounded intervention policies before a task can be accepted.

It complements, rather than replaces, specialist subagents: audit agents provide independent depth, while the Supervisor owns state, evidence, deduplication, intervention, recovery, and the final acceptance gate.

> DSH Supervisor is an early `0.1.x` release. Use it as an additional control layer, not as a substitute for sandboxing, backups, code review, or deployment controls.

[中文文档](./README.zh-CN.md) · [Architecture](https://github.com/DocJlm/dsh-supervisor/blob/main/docs/architecture.md) · [Security policy](https://github.com/DocJlm/dsh-supervisor/blob/main/SECURITY.md) · [Changelog](https://github.com/DocJlm/dsh-supervisor/blob/main/CHANGELOG.md)

## What it does

- Creates an append-only, versioned acceptance contract from user requirements and supplies this authority policy to audit components: latest user instruction → latest acceptance contract → repository rules → execution plan → audit advice.
- Records file, tool, validation, agent, and checkpoint facts without calling a model for every event.
- Runs deterministic guards for failures, risky external operations, and likely credential exposure.
- Selects up to three isolated audit roles at semantic checkpoints: requirements, architecture, testing, security, UI, or documentation/data.
- Produces one deduplicated correction package per checkpoint and routes it as an emergency stop, next-step steer, queued correction, or report-only finding.
- Tracks findings with stable `SUP--` IDs and the `open`, `fixed`, `rejected`, `waived`, and `unresolved` lifecycle.
- Performs a blind final audit from the original request, latest contract, current contract/revision-bound final evidence, and current validation evidence—not from the main agent's explanation or hidden reasoning.
- Persists a redacted JSONL ledger and a human-readable Markdown report, and exposes a polling, read-only Web panel.

New ideas are report-only by default. They do not expand task scope unless the latest user instruction adopts them or they directly satisfy the existing acceptance contract.

## Requirements

- Node.js `22.19+` or `24+`
- `pnpm` available on `PATH` for the DSH plugin installer
- `@deepseek-ai/dsh@0.1.0-rc.7` or a compatible `0.1.x` build
- A DeepSeek-compatible audit credential supplied through the DSH credential service, `DEEPSEEK_API_KEY`, or an explicitly configured key file

## Install

Install the host plugin and its Web client into the Web profile:

```sh
dsh plugin --profile web add dsh-supervisor@0.1.0
```

The package bundle patch inserts the `dsh-supervisor` service. Restart the affected DSH host/Web process after installation if it is already running.

## Configure credentials

Prefer the DSH credential service. Environment variables are the next choice:

```sh
# POSIX shells
export DEEPSEEK_API_KEY="your-api-key"
```

```powershell
# PowerShell
$env:DEEPSEEK_API_KEY = "your-api-key"
```

For a local, uncommitted key file, point the bundle configuration at a path through an environment variable:

```powershell
$env:DSH_SUPERVISOR_API_KEY_FILE = "C:\private\deepseek-api-key.txt"
```

The file should contain only the key (surrounding whitespace is ignored). Never commit the key, the file, or a literal machine-specific path. Credential resolution order is: DSH credential service → configured environment variable → configured key file.

The default patch is equivalent to:

```yaml
- insert:
    - id: dsh-supervisor
      name: dsh-supervisor
      config:
        enabled: true
        model: deepseek-v4-pro
        reasoningEffort: high
        apiKeyEnv: DEEPSEEK_API_KEY
        apiKeyFile: !!js process.env.DSH_SUPERVISOR_API_KEY_FILE
        includeRecentReasoning: false
        maxAuditRoles: 3
        maxAuditRetries: 3
        auditDeadlineMs: 300000
        allowAuditDegradedForLocal: true
```

Important defaults:

| Setting | Default | Meaning |
|---|---:|---|
| `includeRecentReasoning` | `false` | Raw execution-agent reasoning is not collected. Explicit diagnostic opt-in stores it as redacted, untrusted checkpoint evidence; it remains outside final blind-audit input and the Markdown report. |
| `maxAuditRoles` | `3` | Maximum audit roles selected at one checkpoint. |
| `maxAuditRetries` | `3` | Infrastructure retries after the first audit attempt. |
| `auditDeadlineMs` | `300000` | One monotonic five-minute window including attempts, queueing, and backoff. |
| `auditAttemptTimeoutMs` | `90000` | Per-attempt ceiling, also capped by the remaining audit window. |
| `auditBackoffMs` | `5000, 15000, 30000` | Retry delays for audit infrastructure errors. |
| `allowAuditDegradedForLocal` | `true` | Allows a local-only task to close with an explicit degraded warning after deterministic validation passes. |
| `sameClassHardLimit` / `totalHardLimit` | `2` / `5` | Circuit breakers for model-driven hard intervention; deterministic safety guards remain active. |

`SupervisorConfig` supports per-task and per-role model routing, call budgets, and Token budgets. The dispatcher checks budget headroom before a role batch or retry, reserves concurrent output allowances, and forwards each available output ceiling to supported providers. Call budgets are enforced per recorded backend call. Token budgets are a concurrency-safe output reservation plus a soft total-usage ceiling: input and separately reported reasoning Tokens are known only after a call, so that call can take the reported total above the configured limit; later calls are then blocked. Role-specific provider/model routes apply to DSH subagents; the direct fallback uses the top-level DeepSeek model configuration.

`validationScriptNames` controls validation-command recognition and `package.json` script discovery. The Host discovers scripts when a root run opens and refreshes them immediately before completion or completion recovery. Every configured script that is then present is required; no script name, including `check`, is assumed to aggregate the others. Repository-script evidence must use the exact foreground form ` run

数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

提交后我们会发送一封确认邮件,点击邮件里的链接才会开始收信。

完全免费,取消任意时间。我们不会发送垃圾邮件。