979569650/dsh-typesafe
TypeSafe Jev (System One decision model) as a decision layer for DeepSeek Harness: typed decisions, confidence-gated routing, a cost meter, and an automatic prompt-injection guard over untrusted tool results.
Project Overview项目介绍
dsh-typesafe is a native Cordis plugin built specifically for DeepSeek Harness (DSH), wiring the external TypeSafe Jev decision service into a DSH session as a thin reasoning layer. It registers three model-facing tools — typesafe_decide (1–200 typed questions per call mixing noul / choice / score), typesafe_route (classify with full distribution and a min_confidence escalation flag), and typesafe_screen (prompt-injection screening with harm scoring) — together with a behavioural prompt section, an automatic tools/post-execute guard over web_fetch / web_search / read_page and the fetch MCP results, and a /typesafe command that prints call count, input tokens and estimated cost. Installation is via the DSH plugin manifest; lib/index.js is the entry that hooks into the settings namespace, credentials store, prompt service, tool registry, and guard pipeline.
The intended workflow is to keep the reasoning model for genuinely open-ended judgement and offload the narrow, enumerable decisions to Jev, then let the agent audit its own output against Jev's calibrated probabilities. The README documents a concrete field test: triaging 28 Chinese support tickets, where the old prompt wording left the plugin unused (0 calls, 64% uncertain rate reported anyway), while a rewrite that replaces capability description with recognition triggers — placing the section at promptOrder 700 inside the behavioural-rule band — produced 1 call with 28 questions and a self-overruling keyword audit. The tool is aimed at power users who want cheaper per-call decisions, routable confidence, and an independent second signal from a different architecture rather than another same-family LLM reviewer.
Dependencies are minimal: a TypeSafe Jev API key, the local Cordis runtime that ships with DSH, and the platform's settings and tool services. Hard limits from the README: Jev only went GA in September 2026 so pricing and rate limits are documented as dynamic, the public benchmark sits at 67.8% versus 74.1% for the best LLM comparator, English is the primary training language and CJK is weaker, input is text-only with no image/audio/video, and all vendor-reported speed and cost multipliers are not independently verified. First-run caveats: configure the API key through the localized settings card (asserted identical across languages by test/i18n.mjs), do not shorten guard samples below guardMinChars or they will exercise the length filter instead of the classifier, and run test/runtime.mjs beside a live DSH — it composes a real Cordis app with the real registry to assert the three tools, settings round-trip, prompt render, and end-to-end guard firing.
dsh-typesafe 是为 DeepSeek Harness(DSH)打造的原生 Cordis 插件,把外部的 TypeSafe Jev 判定服务接入到 DSH 会话中。它在模型工具层新增三个工具——typesafe_decide、typesafe_route 和 typesafe_screen,并附带一段行为级提示词、tools/post-execute 钩子实现的 prompt injection 防护,以及一个 /typesafe 成本仪表。安装后通过 DSH 的插件清单与 lib/index.js 入口装载,凭证写入由 settings 命名空间统一管理。
典型工作流是:让推理模型负责复杂判断,把那些机械、可枚举的选择交给 Jev 完成,再由 Jev 输出带置信度的概率分布供模型复核。文档用一个 28 张工单分诊的现场实验证明:旧版提示词无法让 agent 主动调用,新版改为"识别触发器"写法后,agent 开始用 Jev 审计自己的关键词规则。目标用户是希望降低长上下文 token 消耗、并希望获得独立第二信号的 DSH 高级用户。
依赖项只有 TypeSafe Jev 的 API 凭证、本地 Cordis 运行时与 DSH 的 settings/tools 服务。限制方面需注意:Jev 2026 年 9 月才 GA,公开基准准确率 67.8%,英语优于中文,仅支持文本输入,且性能对比数据来自厂商自报。首次运行前请配置 API Key、检查 settings 卡片的中英文本地化键值一致,并在测试环境先验证 prompt injection 防护。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-typesafe(979569650/dsh-typesafe)
仓库:https://github.com/979569650/dsh-typesafe
本站详情页:https://www.yhbd.top/plugins/979569650-dsh-typesafe/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 2 · 最近提交 2026-09-22 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:979569650/dsh-typesafe
把 979569650/dsh-typesafe 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-typesafe
TypeSafe Jev as a decision layer for DeepSeek Harness.
A reasoning model should not spend its context and its tokens on judgements that are narrow, enumerable, and mechanical. Jev answers exactly those — cheaply, with calibrated probabilities — and, being a different architecture, gives a genuinely independent second signal where a same-family LLM reviewer would just agree with itself.
This plugin wires that into DSH: three tools, a short prompt section that tells the agent when the trade is worth making, an automatic prompt-injection guard over untrusted tool results, and a cost meter so "cheaper" is a number you can check instead of a claim you have to trust.
What it does
| Piece | What it adds |
|---|---|
typesafe_decide |
Ask Jev 1–200 typed questions about one piece of content in a single call. Mix noul (yes/no probability), choice (pick one + full distribution), and score (rubric). |
typesafe_route |
Route content to one of a fixed set of destinations, returning the choice, every probability, and a confidence. min_confidence turns uncertainty into an explicit escalation flag. |
typesafe_screen |
Screen untrusted text for prompt injection and for how much harm acting on it would cause. |
| Prompt section | Three concrete rules telling the agent when Jev beats a reasoning call, and when it does not. Without this the tools exist but go unused. |
| Automatic guard | A tools/post-execute hook that screens results from web_fetch, web_search, read_page and the fetch MCP tools before the model reads them. Fail-open. |
/typesafe |
Session call count, input tokens, and estimated cost. |
| Localized card | The Settings card ships Chinese and English and follows Settings → General → Language. |
Measured results
Real calls against jev-latest, not vendor claims:
| Check | Result |
|---|---|
| Three primitives in one call | urgency 0.98; routing technical 0.81; frustration 1.04/2 |
| Latency / cost per call | ~800 ms, $0.0000173 |
| Guard on a real injection string | blocked, injection 0.99, harm 2.34 |
| Guard on benign policy text | clear — no false positive, injection 0.01, harm 0.06 |
| Chinese input | urgency 0.98, anger 1.9/2 — usable despite the docs calling CJK weaker |
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
slywalker2006/dsh-passwords
ice-kele/dsh-llm-guardian
edison7009/EchoBird
Han-1413141/dsh-cost-meter
Ychris12138/dsh-usage-stats
wink-run/tokenbank
JingbiaoMei/Tokdash
songoao25/dsh-bottom-info-bar