MrWeiCodes/dsh-loop-guard 预览 preview

MrWeiCodes/dsh-loop-guard

为 DeepSeek Harness(DSH)提供的思考循环守护插件:模型陷入「只想不做」的退化循环时自动打断并注入纠正提示,任务继续往下走,不必再手动中止

Project Overview项目介绍

This is a purpose-built plugin exclusively for DeepSeek Harness (DSH) that protects against AI reasoning loop degeneration. DSH’s native guard policies only handle issues related to tool calls, so they cannot catch cases where the model gets stuck in a loop of repetitive reasoning without ever making a tool call. When this happens, the session stays stuck in a “thinking” state indefinitely, and the only way to stop it is for the user to manually abort the process. This plugin hooks into the LLM stream processing pipeline, uses four layers of detection to identify the degenerative loop, and cuts the stream from inside to end the turn normally.

After installation, the plugin works out of the box with no additional configuration required. All default parameters have been calibrated against thousands of real-world reasoning calls to ensure that there are zero false positives on normal, non-repetitive and even appropriately repetitive outputs like code, tables, or logs. When a loop is cut, the current turn ends normally, all existing reasoning and tool call results are saved, and a short reminder prompt is injected to guide the model back to the original task. In most cases, users do not need to manually restart the session or re-enter their instructions.

The plugin requires DSH version 0.1.2-rc.1 or newer to work, and offers three different installation methods to suit different user environments. The simplest method is to ask DSH’s AI assistant to install it directly by sharing the repository URL; you can also install it via the DSH CLI from GitHub, or manually clone and build it on your local machine. It is open-source under the permissive MIT license, and includes an offline analysis tool that runs the same detection logic on past session JSONL files to check if a loop should have triggered a cut.

dsh-loop-guard 是专门为 DeepSeek Harness (DSH) 开发的原生思考循环守护插件。DSH 自带的防护规则仅针对工具调用相关异常,无法检测模型陷入纯推理退化、只重复思考不调用工具的死循环,这类异常会导致回合一直停留在「思考中」状态,只能由用户手动中止。本插件接管 LLM 流输出,通过检测规则识别退化循环,并在检测到后从流内部切断,让回合正常结束。

本插件安装完成后开箱即用,无需额外配置,默认参数已经过真实场景标定,能保证对正常长推理、合理重复输出(如表格、代码、日志)零误报。检测到退化循环并切断后,当前回合正常收尾,已产生的推理会落盘保存,已执行的工具调用结果也会保留,同时会注入一条纠正提示引导模型回到原任务,大多数情况下无需用户手动重启会话。

本插件要求 DSH 版本不低于 0.1.2-rc.1,支持三种安装方式:最简单的是通过 DSH AI 助手自动安装,也可以通过命令行从 GitHub 安装源码编译,或手动克隆到本地插件目录后构建。项目以 MIT 许可证开源,还附带一个离线分析工具,使用和运行时相同的检测逻辑,可复跑历史会话检查是否应该触发熔断。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 note1 项提示
  • 13 stars - an early-stage project星标 13,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add @mrweicodes/dsh-loop-guard

把 MrWeiCodes/dsh-loop-guard 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-loop-guard — DSH 思考循环守护

为 DeepSeek Harness(DSH)提供的思考循环守护插件:模型陷入「只想不做」的退化循环时自动打断并注入纠正提示,任务继续往下走,不必再手动中止

🌏 中文 | English

dsh · dsh-plugin · plugin · guard · thinking-loop · reasoning · repetition · AI agent · 思考循环 · 死循环 · 推理退化

简介

长上下文 + 高 reasoning effort 下,模型会退化:推理里开始出现低熵重复(好。执行。好。、Write. / Output. / Let me write. / Go. 这种短句轮转),然后停不下来。

麻烦的是 DSH 自带的 guard/ 家族抓不到这种情况——它们都围绕工具调用:

内置 guard 挂载点 能抓什么
guard/timeout-policy tools/execute 工具调用超时
guard/repeat-tool-reminder tools/post-execute 重复的同一个工具调用链

而退化循环的特征恰恰是完全不调工具:只有 reasoning-delta,零 text-delta、零 tool-call-delta。于是:

  • 两个 guard 都不触发;
  • agent-loop 的 turn() 从已完成的消息推导 StepEndReason,流不结束 → step 不 settle → turnEnds 永远为 null → while (true) 永不 break;
  • 回合停不下来,只能由你手动中止——而界面上只显示「思考中」,看起来和认真推理没区别。不点开 thinking 块根本察觉不到它在空转。

本插件接管 llm/stream 瀑布流,按每次模型调用的 chunk 组成做判定,在退化发生时从流内部切断,让回合正常结束。

效果:思考循环被截断,并注入纠正提示

上图是实际运行效果:推理块里反复出现 OK. / Writing. / Let me write. / Go. / Executing. / Now. 的轮转,插件在重复累积到阈值时截断该次调用,并在下方注入一条提示,让模型回到原本的任务。

0.1.7 起聊天区不再显示那条提示

DSH 0.1.7 把「上下文」类消息从聊天区可见行里排除了(isVisibleChatNode,硬编码 kind !== "context"),所以注入的纠正提示在聊天区完全没有——不是被折叠,是压根不渲染。

0.1.6 及更早没有这个过滤,那时它正常显示为「上下文注入」行。

提示没有丢,两处能看到:

位置 看到什么
会话历史 / 轨迹视图 该消息原样列出,带「上下文」标签和完整正文
宿主日志 dsh-loop-guard: breaking a repetitive stream (N repeated chars, ...)

轨迹视图里的样子(上下文 那一行):

轨迹视图中的截断提示

功能特性

  • 五层检测,各管一种形态:纯推理无输出、复述上一步材料、可见输出内部的周期循环、可见输出内部的短语池重排、以及推理内部的短语池重排。后三条互补,见下。
  • 能终止「永不结束的回合」:这是本插件存在的核心理由。退化循环里流永远不结束,任何「调用结束后再判定」的检测都够不到;只有从流内部切一刀才行。
  • 切断后任务继续,不必手动重启:切断只是结束当前这次调用,回合以正常完成收尾,会话照常可用——你原本的任务可以直接往下走。这是它和「卡死到只能手动中止」的根本区别。
  • 在 1% 处就切断:实测一个 330,188 字符的循环在 3,264 字符(1.0%)时被切断;一个 124,070 字符的在 17,888 字符(14.4%)时被切断。原来这两个都要跑满全程、最后靠人手动中止。
  • 误报极低:在真实会话 119 个「有产出」的调用上,零误报;扫描本机全部 735 个会话、40 个触发点,误判 12 个(全是「贴代码改前/改后」),已由集中度护栏挡住——见下。
  • 精确判据:判定用的是逐字周期和跨调用复述,不是时长、也不是比率。
  • 纠正信息指向原任务:切断时注入的提示只说「不要重复,继续完成任务」,不会让模型去"给个结论然后收尾"——后者会让它偏离原本在做的事。
  • 反应不闩锁:一次 steer 常常打不破强循环,所以阈值到了会重新计数、再次开火(上限 maxFires)。
  • 跟随界面语言:注入的提示读宿主 locale 设置,中文环境说中文(默认即中文)。
  • 绝不静默重试:没有模型回退、没有自动重发同一请求——把退化模型再喂一遍比循环本身更糟。
  • 离线分析器:tools/analyze-session.mjs 用插件运行时同一个检测器复跑 session jsonl,回答「这次到底该不该响」。
  • 可观测:切断时写 warn 日志,并注明是哪条规则命中的。

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev embedded-workbench 下一个 Next dsh-turn-fold →