leeyoung1/dsh-advisor-plugin
DeepSeek Harness advisor plugin: pair a fast executor with a stronger reviewer model
Project Overview项目介绍
dsh-advisor-plugin is a Cordis plugin built specifically for DeepSeek Harness (DSH), targeting the web profile. It implements the "advisor strategy pattern": a cheap execution model drives the main loop while a stronger reviewer model is consulted at critical junctures, returning plan, correction, or stop signals that the executor must respect. The plugin ships two complementary channels — an explicit zero-argument advisor() tool that forwards the full session and tool inventory, plus an automatic patrol mode throttled by step count and a 90-second wall clock — both designed to mitigate self-verification blind spots, long-horizon drift, and premature completion claims in long-running coding-agent sessions. Installation runs through the official registry via dsh plugin --profile web add dsh-advisor-plugin, or directly from GitHub with dsh plugin add github:leeyoung1/dsh-advisor-plugin; local development uses ./scripts/link-deps.sh to symlink the host's @deepseek-ai/* packages and ./scripts/mount.sh to build and mount the bundle into the local web profile.
The typical workflow begins in the DSH Settings → Plugins panel where the user picks a reviewer provider/model stronger than the executor, optionally sets a reasoning effort, and toggles patrol on. From that moment, the execution model invokes advisor() with no arguments before substantive work, when stuck, or before claiming completion, while the patrol channel snapshots the conversation every N steps and writes session-event cards showing ON-TRACK, CORRECTION (amber), or STOP (red) verdicts that get injected into the next request via agent.inject(). The reviewer never mutates code — it only inspects via read-only search_files and read_file tools before issuing suggestions, making the architecture a clean separation of execution from judgment. Developers who worry about agents "proving themselves right" can also use the /advisor slash command inside any session to inspect the currently bound provider/model and effort tier without leaving the chat.
Dependencies are strict: Node.js ^22.19 or >=24, DSH 0.1.5-rc.1 or 0.1.5-rc.2 (peer range covers 0.1.0-rc.6, 0.1.1-rc.2, 0.1.2-rc.1, 0.1.3-alpha.1, verified on 0.1.1-rc.2); the user MUST supply a usable provider/model or the plugin stays unarmed, registering neither the tool nor the prompt segment so cost stays at zero. An executor blacklist accepts model, provider/model, or provider/model@effort syntax in settings.yaml, and on context overflow the plugin performs a paired safe truncation retry and falls back to the model's default effort when the configured tier is unsupported. Plain npm install will collide with DSH's official package peerDependencies, so users should always go through dsh plugin add. A known DSH Desktop 0.2.1 bundle patch still references the legacy name dsh-advisor; users must remove the old entry, install dsh-advisor-plugin@latest, and clean any residual - id: dsh-advisor line in the profile's cordis.patch.yml. The license is MIT, and the test suite reports 59 cases across 7 files all passing.
dsh-advisor-plugin 是面向 DeepSeek Harness(DSH)的 Cordis 插件,为 web profile 提供"advisor 策略模式":让便宜的执行模型继续推进主线,在关键节点把整段会话与工具清单交给更强的审查模型,回收 plan、correction、stop signal 后继续执行。插件同时提供显式 advisor() 工具调用与按 N 步节流的自动巡逻通道,覆盖开始前、卡住时与宣告完成前三类时机。安装走 dsh plugin --profile web add dsh-advisor-plugin,或从 GitHub dsh plugin add github:leeyoung1/dsh-advisor-plugin 装载;本地开发用 ./scripts/link-deps.sh 链接 DSH 官方 @deepseek-ai/* 包,再用 ./scripts/mount.sh 构建挂载到 web profile,所有审查模型与巡逻参数都在 DSH 设置页的 Advisor 卡片里配置,不需手改 yaml。
典型工作流是执行 Coding Agent 长链路任务时,先在设置页选定强于执行模型的 provider/model 与推理档位,按需启用 patrol;运行中执行模型在关键节点零参数调用 advisor(),或巡逻按步数快照审查,模型返回 ON-TRACK / CORRECTION / STOP 卡片,STOP 时强制执行模型停下向用户报告。审查模型只读搜索,可先 search_files / read_file 核实事实再给建议,绝不直接改状态,适合担心自验证盲区、长程漂移与过早宣告完成的开发者。命令 /advisor 可即时查看当前 provider/model 与可用档位,方便在会话中快速核验配置。
依赖 Node.js ^22.19 或 >=24,目标 DSH 为 0.1.5-rc.1 / 0.1.5-rc.2,peer 覆盖 0.1.0-rc.6、0.1.1-rc.2、0.1.2-rc.1、0.1.3-alpha.1,实测 0.1.1-rc.2 通过;执行模型可在 settings.yaml 里用 model、provider/model、provider/model@effort 三种语法黑名单跳过。未配置审查模型时 advisor 工具与提示段都不注册,零成本;裸 npm install 会撞 DSH 官方包 peer 依赖,仍需走 dsh plugin add。DSH Desktop 0.2.1 bundle patch 引用了旧名 dsh-advisor,需先 remove 再安装 dsh-advisor-plugin@latest 并清理 cordis.patch.yml 残留。许可证 MIT,测试套件 7 文件 59 用例全绿。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-advisor-plugin(leeyoung1/dsh-advisor-plugin)
仓库:https://github.com/leeyoung1/dsh-advisor-plugin
本站详情页:https://www.yhbd.top/plugins/leeyoung1-dsh-advisor-plugin/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 3 · 最近提交 2026-09-11 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 3 stars - very few users, little community feedback星标只有 3,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add dsh-advisor-plugin
把 leeyoung1/dsh-advisor-plugin 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-advisor-plugin
DeepSeek Harness 的 advisor 策略模式插件:让便宜快速的执行模型继续跑主线,在关键节点把整段会话交给更强的审查模型,拿回 plan / correction / stop signal 后继续执行。
dsh-advisor-plugin 解决的是一个结构性问题:同一个模型既写代码又验代码,很容易“证明自己是对的”。长链路 Coding Agent 常见的三类失效——自验证盲区、长程漂移、过早宣告完成——都可以用“独立第二意见”来缓解。
它提供两条互补通道:
- 显式咨询:执行模型零参数调用
advisor(),整段会话与工具清单自动转发给审查模型; - 自动巡逻:每 N 步把会话快照发给审查模型,跑偏时在下一个请求注入纠偏,STOP 时要求执行模型停下向用户报告。
所有审查配置都在 DSH 设置页完成,不需要手改配置文件。
特性
- 总开关:设置页一键启用/关闭;关闭时不注册 advisor 工具与升级守则,已保存的模型配置保留。
- 可折叠配置:模型与推理档位、巡逻模式两个区块可分别收起/展开。
- 零参数
advisor()工具:调用即自动转发整段会话,模型不需要组织上下文。 - plan / correction / stop 契约:审查模型只做判断,不碰代码、不直接改状态。
- compaction 感知:转发的是
session.deriveMessages()的真实模型可见面,而不是过期原始历史。 - 稳定的工具清单前缀:按 agent scope 序列化,目标是命中 DeepSeek 前缀缓存。
- 巡逻模式:步数 + 90 秒墙钟节流 +
patrolImmuneTurns冷却 + emission-guard 去重,防止过度打扰。 - 只读调查工具:审查模型可先在工作区内
search_files/read_file核实事实,再给建议。 - 失败隔离:审查调用失败、超时、空正文、上下文溢出都不会炸掉执行模型的 turn。
- 双降级:推理档位不支持时走模型默认档;上下文溢出时做配对安全截断后重试。
- 执行模型黑名单:
disabledForModels支持model、provider/model、provider/model@effort三种语法。 - 未武装零成本:没有配置审查模型时,工具和提示段都不注册。
- 可视化:设置页卡片、
advisor()咨询卡片、巡逻裁决灰/琥珀/红三形态卡片。
架构
src/ # host 半(Node / Cordis 插件)
├── index.ts # apply:组装工具/提示段/门控/巡逻/命令/设置
├── advisor-prompt.ts # 咨询/巡逻两套系统提示 + 干预文本
├── config.ts # schemastery schema + 武装解析 + 黑名单语法
├── tool.ts # 零参 advisor 工具 + 专属卡片 + 结果信封
├── history.ts # 工具清单 + deriveMessages + 尾部规则
├── llm-call.ts # 审查调用 / sessionId 透传 / 降级 / 调查循环 / 回显剥离
├── patrol.ts # 巡逻调度 / 裁决解析 / agent.inject 干预
├── patrol-event.ts # 巡逻裁决写入会话事件
├── emission-guard.ts # 归一化 / 空话过滤 / FIFO 去重
├── settings.ts # settings 命名空间接入与活编辑
├── gating.ts # 按 agent 隐藏 advisor 工具
├── prompt-section.ts # 升级守则提示段
├── command.ts # /advisor 命令
└── client/ # 浏览器半
├── index.ts # 注册设置卡片 / 工具行 / 巡逻卡片
├── controller.ts # 设置暂存编辑 + 模型目录
├── AdvisorCard.tsx # 设置页卡片
├── AdvisorToolRow.tsx
├── PatrolNodeView.tsx
├── patrol-chat.ts
├── locales.ts
└── store.ts
docs/ # 技术文章与架构图
scripts/ # 本地开发辅助脚本
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
mafeis/dsh-net-proxy
esengine/DeepSeek-Reasonix
strukto-ai/mirage