bwndlct/dsh-session-audit

DeepSeek Harness 的会话执行分析与审计报告——了解你的智能体实际工作方式

Project Overview项目介绍

This is a native plugin built exclusively for DeepSeek Harness (DSH) that performs execution auditing on DSH sessions. It parses session event logs to collect metrics for steps, tool calls, failures, repeated actions, token usage, and verification commands, then outputs a structured, human-readable audit report that can cover the current active session or any historical persisted session by ID, and supports three output formats: plain text, Markdown, and JSON. All analysis runs locally only, it never sends any user data over the network or collects usage telemetry, and you install it by running the DSH plugin add command then manually adding it to your profile bundles list before restarting DSH.

Users can trigger an audit directly by asking the agent in natural language, or use built-in slash commands for more control. Slash commands let you audit the current session, audit a historical session by ID, list all recent persisted sessions, and specify your preferred output format. The plugin uses threshold-based deterministic rules to flag potential issues like consecutive failed tool calls, high failure rates, repeated identical calls, and frequent reads of the same file. It also automatically detects common test, lint, typecheck, and build commands run in shell tools, and reports whether the last observed run succeeded or failed according to session log data.

The plugin requires DSH version 0.1.0-rc.6 or newer, and is released under the open source MIT license. It has some current limitations: it cannot identify verification commands wrapped in custom scripts, does not support cross-session aggregation or time-series context growth analysis, and sub-agent sessions must be audited individually by ID. All of these missing features are planned for future releases, along with HTML reports and a potential web dashboard view. It handles both compressed zstd session logs and uncompressed plain text session logs natively without additional dependencies for decompression or parsing.

这是一个专为 DeepSeek Harness 开发的原生插件,用于对 DSH 会话执行全维度执行审计,可统计步骤、工具调用、失败情况、重复动作、Token 用量,识别并验证 test/build/lint 等命令的执行结果,通过一次工具调用输出清晰可读的结构化审计报告,帮助用户快速掌握会话中 Agent 的实际执行过程和关键潜在问题。

用户可直接通过自然语言让 Agent 调用本插件审计当前会话,也可使用斜杠命令按 ID 审计历史会话、列出最近可审计会话,还能指定文本、Markdown 或 JSON 格式输出。全部分析仅在本地完成,不发起任何网络请求,不调用第三方 LLM API,不收集任何用户隐私数据,审计报告仅作为工具结果保留在当前会话中。

安装后需要手动将插件加入配置文件的 bundles 列表,重启 DSH 后即可正常使用。本插件要求 DSH 版本不低于 0.1.0-rc.6,采用 MIT 许可证开源,可免费使用和修改。子 Agent 会话需要单独按 ID 审计,暂不支持跨会话汇总、上下文增长分析,封装在特殊脚本中的验证命令也无法识别,这些功能都已规划在未来更新中。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 3 stars - very few users, little community feedback星标只有 3,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add dsh-session-audit

把 bwndlct/dsh-session-audit 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-session-audit

看清你的 DeepSeek Harness Agent 这次到底是怎么干活的。

对一个 DSH Session 做 Steps / Tool Calls / 失败 / 重复动作 / Token / 验证命令(test/build/lint)的执行审计,通过一次 session_audit 工具调用输出一份可读的审计报告。

简体中文 | English

DSH Session Audit
──────────────────────────────────────────────

Session
ID              session-d2309fa2-47d3-484a-8357-236e0acdd9aa
Model           glm-5.3
Provider        zai-coding-cn
Duration        51m 42s
Started         2026-08-14T09:08:08.384Z

Execution
Turns           4
Steps           121
Assistant msgs  120
Turn endings    completed×1, interrupted×1, error×1

Tools
Total calls     150
Succeeded       143
Failed          6
Unresolved      1
Failure rate    4.0%

Top tools
  bash                  83  (1 failed)
  write                 26
  edit                  21  (4 failed)
  read                  12

Tokens
Input           349,428
Output          80,415
Cache read      9,243,520
Total           9,673,363

Execution signals
  ⚠ 3 consecutive failed tool calls detected
  ⚠ `bash` called 83 times
  ℹ session has a turn that never closed

Verification
  ✓ pnpm run typecheck  [typecheck]
  ✓ npm test  [test]  (2 attempts, 2 ok)

(来自本机真实会话的报告)

为什么需要

DSH 的 session 日志已经完整记录了"发生了什么"——它是 append-only 的事实源。 但读完一份上千事件的日志,并不能直接回答你真正关心的问题:

跑了多久?多少个 Turn / Step?哪些工具用得最多?在哪里失败? 有没有重复调用?最后验证过没有?

dsh-session-audit 把单个 session 的持久化事件日志折叠成这些答案。 它是 Step / Tool-call Profiler 和失败分析器,不是 Token 仪表盘 (见现有同类插件)。

功能

  • Session 指标 — 时长、Turns、Steps、assistant 消息数、工具调用 总数、按工具分布、成功/失败拆分。
  • Token 用量 — 按 turn:step 折叠 input / output / cache 桶,语义与 官方 session-stats 投影一致;provider 没上报时显示 Unavailable, 绝不估算。
  • 确定性审计信号 — 连续失败、失败率、高频工具、完全相同的重复 调用(对参数 key 顺序不敏感)、重复读取同一文件。纯规则判定,不用 LLM 打分。
  • 验证命令识别 — 识别 shell 工具调用中的 test/build/lint/typecheck 命令(npm test、pytest、cargo test、tsc、eslint……)并报告 实际观察到的结果。
  • 三种格式 — text(默认)、Markdown、JSON(带稳定 schemaVersion)。
  • 当前或历史 Session — 默认审计当前内存中的 session,也可按 id 审计任一持久化 session;支持列出最近的 session。
  • 健壮 — 空会话、畸形事件、未来新增的事件类型、孤儿 result、 崩溃尾部残帧:全部安全处理,并在报告中以数据质量说明呈现。

安装

要求 dsh(@deepseek-ai/dsh)0.1.0-rc.6+。

# npm(发布后)
dsh plugin --profile web add dsh-session-audit

# GitHub
dsh plugin --profile web add github:bwndlct/dsh-plugins/plugins/dsh-session-audit

# 本地开发(link)
dsh plugin --profile web add link:/path/to/dsh-plugins/plugins/dsh-session-audit

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-plugin-store 下一个 Next dsh-delete-message →