jackie-cqz/dsh-jev-plugin

Plugin插件 Native原生 ⭐ 8 MIT Approval & Security审批与安全

DeepSeek Harness plugin for TypeSafe Jev: typed decisions, configurable guardrails, and Web UI result cards.

Project Overview项目介绍

dsh-jev-plugin is a DSH-native plugin that lets DeepSeek Harness agents invoke TypeSafe Jev as a structured-decision backend instead of asking the model for free-form text. Versioned at 0.1.0 under the MIT license, it targets DSH 0.1.6-alpha.2 with the declared semver range >=0.1.6-alpha.2 <0.2.0, and is installed as a standalone bundle through dsh.bundle without modifying the DSH repository. The package depends on the cordis peer @deepseek-ai/cordis ^4.0.2 and the runtime peer @deepseek-ai/dsh-tools ^0.1.6-alpha.2, requires Node ≥22, and has CI coverage for Node 22 and 24 on both Ubuntu and Windows.

The plugin exposes Jev's three primitives as DSH tool calls: noul returns a yes/no probability in [0,1], choice returns the selected label together with a probability distribution and confidence score, and score returns an ordered-scale rating with the same distributional metadata. A companion tool, verdictFor, automatically approves when confidence reaches confidence.approveAt (default 0.8) and escalates below confidence.escalateBelow (default 0.5). Because every call yields a typed structured payload rather than conversational prose, the plugin is well suited to DSH users who need deterministic branching, approval gates, or risk scoring inside agent workflows.

Installation can be done locally with dsh plugin --profile jev-dev add /path/to/dsh-jev-plugin or from GitHub via dsh plugin --profile jev-dev add github:jackie-cqz/dsh-jev-plugin#<commit-sha>, after first running dsh --profile jev-dev --from-default-profile web --dump-config once on an unused profile. Configuration fields cover apiKey, apiKeyEnv (default TYPESAFE_API_KEY), baseURL (https://api.typesafe.ai/v1), model (jev-latest), timeoutMs (10000), exponential-backoff retry limits, a maxStateChars cap of 64000, a circuit breaker under policy.enabled with failureThreshold 5 and openMs 30000, an LRU cache block, and a guard.tools/pre-execute risk gate. Documented weaknesses include exact counting, arithmetic, date reasoning, indirect reasoning, double negatives, and long contexts lacking relevant state, with non-English accuracy below English; oversized state is rejected outright rather than truncated. Hooks and Web result cards are implemented but hooks ship disabled, and DSH credentials/Settings integration and intent instruction injection are not yet available, while npm run check:release enforces typechecking, builds, packaging, and tarball install smoke tests before publication.

dsh-jev-plugin 是一个面向 DeepSeek Harness(DSH)的原生插件,版本 0.1.0,以 MIT 协议发布,针对 DSH 0.1.6-alpha.2 声明 >=0.1.6-alpha.2 <0.2.0 的兼容范围。它通过 dsh.bundle 作为独立包安装,无需修改 DSH 仓库源码;cordis 插件依赖为 @deepseek-ai/cordis ^4.0.2,运行时依赖 @deepseek-ai/dsh-tools ^0.1.6-alpha.2,要求 Node ≥22,CI 已覆盖 Node 22/24。

插件把 TypeSafe Jev 的三个原语 noul、choice、score 暴露为 DSH agent 工具:前者返回 0–1 概率的二元判断;choice 输出所选标签、概率分布与置信度;score 在有序量表上打分并附带分布与置信度。配套工具 verdictFor 在置信度≥confidence.approveAt(默认 0.8)时自动通过,低于 confidence.escalateBelow(默认 0.5)则升级处理。所有 Jev 调用输出结构化结果而非自由文本,便于确定性自动化决策流程,目标是需要在 agent 内做可靠类型化判断的 DSH 开发者。

安装方式两种:本地 dsh plugin --profile jev-dev add /path/to/dsh-jev-plugin,或 GitHub add github:jackie-cqz/dsh-jev-plugin#<commit-sha>(需先 --dump-config 用 Web 模板初始化 jev-dev)。配置项覆盖 apiKey、apiKeyEnv(默认 TYPESAFE_API_KEY)、baseURL、model、timeoutMs、重试退避、状态上限、置信度阈值、熔断器(policy.enabled)、LRU 缓存以及 tools/pre-execute 风险门控 guard。已知弱项含精确计数、算术、日期、间接推理、双重否定与超长上下文,非英文准确率低于英文;巨型状态直接拒绝而非截断。已实现 hooks 与 Web cards(hooks 默认关闭),尚未接入 DSH 凭据/Settings 与意图注入。发布检查通过 npm run check:release 进行类型检查、构建、打包与冒烟测试。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 8 stars - very few users, little community feedback星标只有 8,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile jev-dev add github:jackie-cqz/dsh-jev-plugin#v0.1.0

把 jackie-cqz/dsh-jev-plugin 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-jev-plugin

English | 简体中文

A plugin that lets DeepSeek Harness (DSH) agents use TypeSafe Jev (System One) for typed decisions.

Jev returns structured judgments rather than conversational text. This plugin exposes its three primitives as tools:

Primitive Purpose Result
noul Yes/no judgment Probability from 0 to 1
choice Select a label Selected label, probability distribution, confidence
score Rate on an ordered scale Score, probability distribution, confidence

Status

  • Version: 0.1.0.
  • Target DSH: 0.2.0-rc.2; 0.1.7-rc.2 and 0.1.6-alpha.2 remain covered by installation smoke tests. Declared range: >=0.1.6-alpha.2 <0.2.0 || >=0.2.0-rc.2 <0.3.0; other versions have not been individually verified.
  • License: MIT.
  • Standalone package installed through dsh.bundle; no changes to the DSH repository are required.

Compatibility

Component Version or range
Target DeepSeek Harness 0.2.0-rc.2 (also tested: 0.1.7-rc.2, 0.1.6-alpha.2)
@deepseek-ai/cordis (peer dependency) ^4.0.2
@deepseek-ai/dsh-tools (peer dependency) ^0.1.6-alpha.2, ^0.1.7-rc.2 or ^0.2.0-rc.2
Node (plugin) >=22
Node (DSH host) ^22.19.0 or >=24.0.0

Build and test dependencies are locked in package-lock.json. CI is configured for Node 22 and 24; local release checks have passed on Node 24.

Compatibility checks: typechecking, 782 plugin tests and two packaging-parser tests pass on the target runtime. Tarball installation checks cover all three listed DSH versions. Live TypeSafe smoke and scenario checks pass on Windows / Node 24. Chromium acceptance verifies four successful tool calls, nine result bars and replay after reload, using a scripted LLM adapter with real Jev requests. Git-source acceptance is recorded in the release notes.

Development dependencies

@deepseek-ai/dsh-tools@0.2.0-rc.2 declares these peers in addition to Cordis: dsh-agent, dsh-invariants, dsh-llm, dsh-ptc-runtime, dsh-sandbox, dsh-sandbox-policy, dsh-scope, dsh-session, dsh-system-prompt, and dsh-user-approval (all under @deepseek-ai/). Because --legacy-peer-deps does not install peers automatically, they are explicit development dependencies here. The target profile supplies them at runtime.

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev veripower 下一个 Next dsh-kimi-ppt →