Skills Plugins MCP Prompt Model 导航 博客 资讯 我的中心
开发与运行时 #agent-evaluation#cordis#deepseek-harness#self-evolving-agent#terminal-bench#ai-agents

dsh-self-evolving (dsh-self-evolving)

证据优先的自进化控制器:有界生成 Cordis 候选插件,一次性真实 Loader 准入,Harbor 评测,可崩溃恢复的日志化谱系。

timwhitez @timwhitez ⬇ 1 ★ 7 main

安装

dsh plugin --profile web add github:timwhitez/dsh-self-evolving
下载安装清单

需要可复现安装时,可在仓库后追加 #commit 固定提交。

证据优先的自进化控制器:有界生成 Cordis 候选插件,一次性真实 Loader 准入,Harbor 评测,可崩溃恢复的日志化谱系。

该插件未提供要点说明,请参考仓库 README。

agent-evaluationcordisdeepseek-harnessself-evolving-agentterminal-benchai-agents
  1. 安装并启动 DeepSeek Harness:npx @deepseek-ai/dsh web
  2. 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
  3. 用 dsh plugins list 确认已安装,必要时重启 Harness 生效

插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。

代码仓库github.com/timwhitez/dsh-self-evolving/tree/main/packages/dsh-self-evolving
许可证Apache-2.0
主要语言main
下载量1
GitHub 星标7
最近推送2026-08-29
收录日期2026-09-19
分类开发与运行时

事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。

以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。

# dsh-self-evolving

[English](README.md) | [简体中文](README.zh-CN.md)

[![CI](https://github.com/timwhitez/dsh-self-evolving/actions/workflows/ci.yml/badge.svg)](https://github.com/timwhitez/dsh-self-evolving/actions/workflows/ci.yml)
[![Release](https://img.shields.io/badge/release-v0.2.0-2563eb)](https://github.com/timwhitez/dsh-self-evolving/releases/tag/dsh-self-evolving-v0.2.0)
[![License](https://img.shields.io/badge/license-Apache--2.0-0f766e)](LICENSE)
[![Node.js](https://img.shields.io/badge/node-%3E%3D22.19-339933?logo=nodedotjs&logoColor=white)](package.json)
[![pnpm](https://img.shields.io/badge/pnpm-11.7-f69220?logo=pnpm&logoColor=white)](package.json)
[![Tests](https://img.shields.io/badge/tests-291%20unit%20%7C%2036%20E2E-success)](docs/audits/2026-08-15-v0.2-provider-effectiveness.md)
[![npm](https://img.shields.io/npm/v/%40dsh-self-evolving%2Fcore?color=cb3837&logo=npm)](https://www.npmjs.com/package/@dsh-self-evolving/core)
[![npm downloads](https://img.shields.io/npm/dm/%40dsh-self-evolving%2Fcore?color=cb3837&logo=npm)](https://www.npmjs.com/package/@dsh-self-evolving/core)

An evidence-first, crash-resumable self-evolution engine for
[DeepSeek Harness](https://github.com/deepseek-ai/DeepSeek-Harness). It generates bounded Cordis plugin candidates,
runs them through isolated real-Loader admission, evaluates them with Harbor, and preserves an auditable lineage.

> [!IMPORTANT]
> v0.2.0 verifies stable iteration and a measurable fixed-replay engineering effect. It does **not** claim a
> Terminal-Bench score improvement, sealed promotion, leaderboard result, or SOTA performance.

## Why this project exists

Self-modifying agent systems are easy to demo and hard to trust. `dsh-self-evolving` treats every candidate as
untrusted and makes the controller, evaluator, budget, dataset split, and safety policy part of a trusted computing
base. A result is accepted only when its source identity, evidence, cost, lifecycle, and recovery path reconcile.

The project is a standard DSH Cordis plugin/service—not a fork of DSH and not a second controller wrapped around it.

## What is verified

| Capability                                           | Evidence-backed status                                              |
| ---------------------------------------------------- | ------------------------------------------------------------------- |
| Standard DSH/Cordis controller and candidate plugins | Verified with the real Cordis Loader                                |
| Bounded multi-file candidate generation              | Verified through a networkless proposer sandbox                     |
| Official DeepSeek Responses provider                 | Verified with three credential-gated real-provider cases            |
| Deterministic build and isolated capsule admission   | Verified with double builds and offline Loader E2E                  |
| Durable journal, budget, and crash recovery          | Verified with injected process kills and replay audits              |
| Stable K=3 iteration                                 | Verified with three unique admitted descendants                     |
| Fixed-replay engineering effect                      | `ENGINEERING_EFFECT_VERIFIED` for solve; propose remained unchanged |
| Terminal-Bench improvement / sealed / leaderboard    | **Not run; no claim**                                               |

The exact scope and hashes are recorded in the
[v0.2 acceptance audit](docs/audits/2026-08-15-v0.2-provider-effectiveness.md) and
[project status](PROJECT_STATUS.md).

## Architecture

```mermaid
flowchart LR
  E[DEV_OBSERVED evidence] --> P[Networkless proposer]
  P -->|Unix socket; no key| G[Locked official Responses gateway]
  P --> C[Bounded candidate tree]
  C --> B[Trusted deterministic builder]
  B --> L[One-shot real Cordis Loader]
  L --> H[Harbor / Terminal-Bench evaluator]
  H --> N[Fail-closed normalizer]
  N --> J[Hash-chain journal and archive]
  J --> P
  S[Sealed data] -. inaccessible in development .-> H
```

- The controller is the only durable writer.
- Provider credentials stay in a per-trial trusted host broker and never enter Harbor, the proposal sandbox or a
  candidate; evaluation candidates receive only a fixed Unix socket while direct HTTPS is disabled.
- Candidates may change only their declared package; evaluator, scorer, split, route, and safety policy are fixed.
- Every external action is journaled before launch and reconciled exactly once after restart.

See [Architecture overview](docs/architecture-overview.md) and the
[trust-boundary specification](specs/05-safety.md).

## Quick start

### Requirements

- Ubuntu 24.04 x86_64
- Node.js 22.19+ or 24+
- pnpm 11.7.0 through Corepack
- Docker with a working daemon
- Python 3.12, `uv`, and Bubblewrap
- A DeepSeek API key for real model runs; local validation does not require one

### Install the controller bundle from npm

The controller is published on npm as `@dsh-self-evolving/core`. Install it into a headless profile with an
explicit state root and run id — omission fails Config validation by design:

```bash
export DSH_SELF_EVOLVING_STATE_DIR="${XDG_STATE_HOME:-$HOME/.local/state}/dsh-self-evolving/demo-1"
export DSH_SELF_EVOLVING_RUN_ID=demo-1
dsh plugin --profile headless add @dsh-self-evolving/core@0.2.3
```

Prefer this path to use the controller. Use a source checkout for development, self-hosting, or reproducing the
release artifacts.

### Install from source (development)

```bash
git clone https://github.com/timwhitez/dsh-self-evolving.git
cd dsh-self-evolving
corepack enable
pnpm setup:source
```

`setup:source` installs this workspace and materializes the three upstream repositories at the exact commits in
[`provenance.lock.json`](provenance.lock.json). It refuses mismatched or dirty upstream checkouts.

### Initialize and inspect a run

Keep the credential in the trusted shell only:

```bash
export DEEPSEEK_API_KEY='...'
export DSH_STATE_DIR="${XDG_STATE_HOME:-$HOME/.local/state}/dsh-self-evolving/demo-1"

pnpm dsh-self-evolving init \
  --run-id demo-1 \
  --state-dir "$DSH_STATE_DIR" \
  --repo-root "$PWD" \
  --budget-usd 5

pnpm dsh-self-evolving doctor --state-dir "$DSH_STATE_DIR"
pnpm dsh-self-evolving run --state-dir "$DSH_STATE_DIR"
pnpm dsh-self-evolving status --state-dir "$DSH_STATE_DIR"
pnpm dsh-self-evolving audit --state-dir "$DSH_STATE_DIR"
```

Use `resume`, never a second `run`, after interruption. State directories are private evidence and must not be
committed. The complete workflow is in the [Quickstart](docs/quickstart.md).

## Low-cost effectiveness check

The effectiveness gate asks one real proposal to change the preregistered `solve` replay while preserving the
`propose` control replay:

```bash
export DSH_SELF_EVOLVING_EFFECT_RUN_ID='effect-local-1'
export DSH_SELF_EVOLVING_EFFECT_RECEIPT_PATH="$PWD/evidence/effectiveness/effect-local-1.json"
pnpm effectiveness:official
```

An accepted receipt contains hashes, token usage, and estimated cost—but no API key, reasoning text, provider body,
or private trajectory. The checked-in reference receipt estimated USD 0.0176861328 at the frozen price schedule.
That estimate covers the accepted receipt only, not arbitrary retries or a benchmark campaign.

## Verify the checkout

```bash
pnpm format:check
pnpm lint
pnpm typecheck
pnpm test
env -u DEEPSEEK_API_KEY pnpm test:e2e
pnpm provenance:check
pnpm upstream:check
pnpm byteequal:check
pnpm release:check
```

Real-provider tests are opt-in because they incur API charges:

```bash
pnpm test:provider:official
pnpm effectiveness:official
```

## Documentation

| Start here                                       | Purpose                                                              |
| ------------------------------------------------ | -------------------------------------------------------------------- |
| [Documentation index](docs/README.md)            | Find setup, architecture, operation, evidence, and release documents |
| [Quickstart](docs/quickstart.md)                 | Install and run the bounded stable demo                              |
| [Configuration](docs/configuration.md)           | Frozen profiles, limits, provider route, and credentials             |
| [Architecture](docs/architecture-overview.md)    | Components, data flow, and isolation boundaries                      |
| [Evidence guide](docs/evidence-guide.md)         | What each artifact proves—and does not prove                         |
| [Operations](docs/operations.md)                 | Stop, backup, restore, rollback, and uninstall                       |
| [Troubleshooting](docs/troubleshooting.md)       | Fail-closed errors and recovery procedures                           |
| [DSH upstream policy](docs/upstream-policy.md)   | Reproducible pinning and the latest compatibility channel            |
| [v0.2 release gates](docs/v0.2-release-gates.md) | Current acceptance contract and optional post-release scope          |

The normative specifications live in [`specs/00`–`specs/07`](specs/). When documents disagree, precedence is:
frozen run manifest → specifications → operational docs → README → historical discussion.

## Project boundaries

- DSH, Harbor, and Terminal-Bench checkouts are pinned read-only upstreams.
- `pnpm setup:source` installs the accepted DSH pin automatically; a separate scheduled workflow tests current DSH
  `HEAD` without silently rebinding a release.
- Development evidence may guide iteration; concealed and sealed evaluation data may not.
- K=10/K=80 search, sealed confirmation, full-set evaluation, and leaderboard submission are optional post-release
  profiles and are not part of the v0.2 acceptance claim.
- This repository does not authorize financial trading or real-world order execution.

## Ecosystem

- Published on [npm](https://www.npmjs.com/package/@dsh-self-evolving/core) as `@dsh-self-evolving/core`.
- Listed in [awesome-dsh-plugin](https://github.com/awesome-dsh-plugin/awesome-dsh-plugin) (merged).
- Listed in [AdamPlatin123/awesome-dsh-plugins](https://github.com/AdamPlatin123/awesome-dsh-plugins) (merged).
- Listed in [0xsline/awesome-deepseek-harness](https://github.com/0xsline/awesome-deepseek-harness) (merged).
- Announcement: [DeepSeek Harness Discussion #2547](https://github.com/deepseek-ai/deepseek-harness/discussions/2547).
- Discoverable through the GitHub [`dsh-plugin`](https://github.com/topics/dsh-plugin) and `dsh` topics.

## Contributing and security

Read [CONTRIBUTING.md](CONTRIBUTING.md) before opening a pull request. Changes to protocols, trust boundaries,
provider routes, splits, metrics, or retry semantics require an ADR and a fresh run lineage.

Do not report credential leaks, sandbox escapes, or concealed-data exposure in a public issue. Follow
[SECURITY.md](SECURITY.md) and use GitHub private vulnerability reporting after publication.

Community participation follows the [Code of Conduct](CODE_OF_CONDUCT.md).

## License

Licensed under [Apache License 2.0](LICENSE). DeepSeek Harness, Harbor, Terminal-Bench, and their dependencies retain
their respective licenses and trademarks.

数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

提交后我们会发送一封确认邮件,点击邮件里的链接才会开始收信。

完全免费,取消任意时间。我们不会发送垃圾邮件。