979569650/dsh-typesafe

TypeSafe Jev (System One decision model) as a decision layer for DeepSeek Harness: typed decisions, confidence-gated routing, a cost meter, and an automatic prompt-injection guard over untrusted tool results.

Project Overview项目介绍

dsh-typesafe is a native Cordis plugin built specifically for DeepSeek Harness (DSH), wiring the external TypeSafe Jev decision service into a DSH session as a thin reasoning layer. It registers three model-facing tools — typesafe_decide (1–200 typed questions per call mixing noul / choice / score), typesafe_route (classify with full distribution and a min_confidence escalation flag), and typesafe_screen (prompt-injection screening with harm scoring) — together with a behavioural prompt section, an automatic tools/post-execute guard over web_fetch / web_search / read_page and the fetch MCP results, and a /typesafe command that prints call count, input tokens and estimated cost. Installation is via the DSH plugin manifest; lib/index.js is the entry that hooks into the settings namespace, credentials store, prompt service, tool registry, and guard pipeline.

The intended workflow is to keep the reasoning model for genuinely open-ended judgement and offload the narrow, enumerable decisions to Jev, then let the agent audit its own output against Jev's calibrated probabilities. The README documents a concrete field test: triaging 28 Chinese support tickets, where the old prompt wording left the plugin unused (0 calls, 64% uncertain rate reported anyway), while a rewrite that replaces capability description with recognition triggers — placing the section at promptOrder 700 inside the behavioural-rule band — produced 1 call with 28 questions and a self-overruling keyword audit. The tool is aimed at power users who want cheaper per-call decisions, routable confidence, and an independent second signal from a different architecture rather than another same-family LLM reviewer.

Dependencies are minimal: a TypeSafe Jev API key, the local Cordis runtime that ships with DSH, and the platform's settings and tool services. Hard limits from the README: Jev only went GA in September 2026 so pricing and rate limits are documented as dynamic, the public benchmark sits at 67.8% versus 74.1% for the best LLM comparator, English is the primary training language and CJK is weaker, input is text-only with no image/audio/video, and all vendor-reported speed and cost multipliers are not independently verified. First-run caveats: configure the API key through the localized settings card (asserted identical across languages by test/i18n.mjs), do not shorten guard samples below guardMinChars or they will exercise the length filter instead of the classifier, and run test/runtime.mjs beside a live DSH — it composes a real Cordis app with the real registry to assert the three tools, settings round-trip, prompt render, and end-to-end guard firing.

dsh-typesafe 是为 DeepSeek Harness(DSH)打造的原生 Cordis 插件,把外部的 TypeSafe Jev 判定服务接入到 DSH 会话中。它在模型工具层新增三个工具——typesafe_decide、typesafe_route 和 typesafe_screen,并附带一段行为级提示词、tools/post-execute 钩子实现的 prompt injection 防护,以及一个 /typesafe 成本仪表。安装后通过 DSH 的插件清单与 lib/index.js 入口装载,凭证写入由 settings 命名空间统一管理。

典型工作流是:让推理模型负责复杂判断,把那些机械、可枚举的选择交给 Jev 完成,再由 Jev 输出带置信度的概率分布供模型复核。文档用一个 28 张工单分诊的现场实验证明:旧版提示词无法让 agent 主动调用,新版改为"识别触发器"写法后,agent 开始用 Jev 审计自己的关键词规则。目标用户是希望降低长上下文 token 消耗、并希望获得独立第二信号的 DSH 高级用户。

依赖项只有 TypeSafe Jev 的 API 凭证、本地 Cordis 运行时与 DSH 的 settings/tools 服务。限制方面需注意:Jev 2026 年 9 月才 GA,公开基准准确率 67.8%,英语优于中文,仅支持文本输入,且性能对比数据来自厂商自报。首次运行前请配置 API Key、检查 settings 卡片的中英文本地化键值一致,并在测试环境先验证 prompt injection 防护。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:979569650/dsh-typesafe

把 979569650/dsh-typesafe 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-typesafe

TypeSafe Jev as a decision layer for DeepSeek Harness.

A reasoning model should not spend its context and its tokens on judgements that are narrow, enumerable, and mechanical. Jev answers exactly those — cheaply, with calibrated probabilities — and, being a different architecture, gives a genuinely independent second signal where a same-family LLM reviewer would just agree with itself.

This plugin wires that into DSH: three tools, a short prompt section that tells the agent when the trade is worth making, an automatic prompt-injection guard over untrusted tool results, and a cost meter so "cheaper" is a number you can check instead of a claim you have to trust.


What it does

Piece What it adds
typesafe_decide Ask Jev 1–200 typed questions about one piece of content in a single call. Mix noul (yes/no probability), choice (pick one + full distribution), and score (rubric).
typesafe_route Route content to one of a fixed set of destinations, returning the choice, every probability, and a confidence. min_confidence turns uncertainty into an explicit escalation flag.
typesafe_screen Screen untrusted text for prompt injection and for how much harm acting on it would cause.
Prompt section Three concrete rules telling the agent when Jev beats a reasoning call, and when it does not. Without this the tools exist but go unused.
Automatic guard A tools/post-execute hook that screens results from web_fetch, web_search, read_page and the fetch MCP tools before the model reads them. Fail-open.
/typesafe Session call count, input tokens, and estimated cost.
Localized card The Settings card ships Chinese and English and follows Settings → General → Language.

Measured results

Real calls against jev-latest, not vendor claims:

Check Result
Three primitives in one call urgency 0.98; routing technical 0.81; frustration 1.04/2
Latency / cost per call ~800 ms, $0.0000173
Guard on a real injection string blocked, injection 0.99, harm 2.34
Guard on benign policy text clear — no false positive, injection 0.01, harm 0.06
Chinese input urgency 0.98, anger 1.9/2 — usable despite the docs calling CJK weaker

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-v4-anchor 下一个 Next dsh-voice-chat →