xiaozhuyuqing/dsh-repeat-guard
我们发现部分模型(尤其是deepseek v4.1 flash)很容易在长上下文时进入复读状态。 dsh社区中称呼这种情况为“唱歌”,典型的表现如下所示: 如果在预设或者AGENTS.md中约束使用中文思考,则会变成如下的场景: 配合deepseek v4.1 flash高达 300tok/s 的恐怖输出速率,模型可能会以极为可观的速度消耗token,而不产生任何有效输出。
catalog descriptioncatalog 简介 / catalog description:Tell your deepseek-v4.1-flash: "shut up! Stop looping!"
Project Overview项目介绍
dsh-repeat-guard is a native plugin built specifically for DeepSeek Harness (DSH) that addresses the repetitive-output ("singing") and unnecessary long-reasoning problems observed in models such as "deepseek v4.1 flash" once the context window grows past roughly 300k tokens. It watches reasoning-delta chunks, checks whether a whitelisted short sentence stands alone as its own paragraph in the reasoning stream, and when that pattern fires it forcibly interrupts the current generation, trims the remaining fragment, and emulates a clean turn boundary. A continuation prompt is then injected to restart the agent-loop so the model moves straight into the next tool invocation instead of looping filler lines.
The plugin is aimed at DSH power users and developers who routinely run fast-throughput models over very long contexts and who notice tokens being burned without producing useful work. After installing via dsh plugin --profile web add dsh-repeat-guard, the user opens Settings → 复读打断 (Repeat Interrupt) to configure the whitelist of trigger sentences, the consecutive-hit threshold, the continuation prompt, and the inline-repetition toggle, then saves the changes; the new config takes effect immediately without a restart. The "累计拦截" (cumulative interrupts) counter and its reset button let users audit how often the guard fired, and each interruption appends a user-visible summary so it is obvious the plugin is working.
Dependencies are minimal: the plugin only needs a DSH host at version 0.1.7 or above, because from 0.2.0 onward the host validates peer declarations on load and reads configuration through the entry Config model rather than the older schema; hosts between 0.1.0-rc.8 and 0.1.6 must instead install dsh-repeat-guard@0.1.5. There are no additional runtime requirements, the license is MIT, and first-run caveats such as that inline repetition detection is mainly relevant for qwen 35B rather than deepseek, that the whitelist must be configured before any interception will happen, and that injected prompts visibly increase the step count are documented in the README.
dsh-repeat-guard 是面向 DeepSeek Harness(DSH)的原生插件,专门解决"deepseek v4.1 flash"等模型在长上下文窗口中出现的复读与无意义长思考问题。它逐 chunk 监听 reasoning-delta,检测思考过程中是否出现白名单内的短句单独成段,一旦命中则强制中断当前轮次、掐断后续片段并伪装为正常结束,然后向模型注入续跑提示词以恢复 agent-loop,使模型直接进入工具调用阶段。安装方式为在终端执行 dsh plugin --profile web add dsh-repeat-guard,0.2.0 及以上版本要求 DSH 0.1.7 及以上宿主,旧版 0.1.0-rc.8 至 0.1.6 需安装 0.1.5。
该插件主要面向在长上下文场景下使用"deepseek v4.1 flash"等高吞吐模型的开发者与重度 DSH 用户。典型工作流是用户在设置面板中查看"复读打断"项,配置白名单短句、连续命中阈值与续跑指令,保存后立即生效;插件在后台持续监听并在触发时向用户展示拦截摘要,便于用户判断插件是否正常工作。插件还能在 DSH 的"累计拦截"项下查看并清零记录,配置变更无需重启即可应用。
依赖方面,插件仅依赖 DSH 宿主运行,自身不引入额外运行时,但要求宿主为 0.1.7 及以上以加载 bundle-manifest 与 entry Config 表单;旧版宿主需降级安装 0.1.5 兼容版本。配置上,"行内重复检测"主要为 qwen 35B 等存在行内复读问题的模型设计,deepseek 自身无此问题。用户需要注意的是,首次运行需在设置面板手动确认白名单与阈值,否则插件不会主动拦截任何内容;拦截段会以注入提示词的形式展示给用户,因此对话步骤数会明显增多。许可证为 MIT。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-repeat-guard(xiaozhuyuqing/dsh-repeat-guard)
仓库:https://github.com/xiaozhuyuqing/dsh-repeat-guard
本站详情页:https://www.yhbd.top/plugins/xiaozhuyuqing-dsh-repeat-guard/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 4 · 最近提交 2026-10-02 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 4 stars - very few users, little community feedback星标只有 4,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add dsh-repeat-guard
把 xiaozhuyuqing/dsh-repeat-guard 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-repeat-guard
解决大模型用你的token唱歌的糟糕问题
我们发现部分模型(尤其是deepseek v4.1 flash)很容易在长上下文时进入复读状态。
dsh社区中称呼这种情况为“唱歌”,典型的表现如下所示:
Let me do it.
Let me run.
Let me go.
Let me do it.
...
如果在预设或者AGENTS.md中约束使用中文思考,则会变成如下的场景:
好。
做。
开始。
做。
嗯。
做。
我必须开始工作了。
好。
做。
...
配合deepseek v4.1 flash高达 300tok/s 的恐怖输出速率,模型可能会以极为可观的速度消耗token,而不产生任何有效输出。
这通常是比较隐蔽的,尤其是在用户没有注意模型的思考过程的时候。用户实际上只会看到思考过程快速闪过很短的句子,回答好像很正常。
在上下文长度达到 300k 以上的时候,该现象会变得十分频繁。
不仅如此,我们也观察到deepseek v4.1 flash有着在已经思考到需要工具调用的时候输出一个短句,接下来又进入另一个方向的复杂思考过程的倾向。如下所示:
我已经收集到了足够的信息,接下来开始操作。先修改xxx文件。
做。
但是我还发现仓库里有其它的内容。注意到用户提到xxxxx
...
显然这不是我们想要的行为。既然模型已经清楚下一步的工作是什么,就应该直接开始工具调用。
我们还注意到上述问题只出现于思考过程而不出现于回答内容。
此插件的功能
此插件致力于解决上述模型复读和无端长思考的问题。它会持续检测模型的输出,如果思考过程出现了一个白名单中的短句且单独成段,且模型在输出这个短句后既然有继续思考的意图,我们就会强行中断对话,并发送一句提醒,让模型直接开始下一轮的输出。
例如
[深度思考]
直接检查服务器状态和崩溃日志。
关键:先看最新日志和 crash-reports。
执行。 <--打断
[复读拦截]
你上一段思考退化成了碎片复读(反复输出"好。"一类的空话),已被系统截断。
请直接继续执行下一步,不要再输出任何确认语、寒暄或空话。
[深度思考]
直接调用工具,检查服务器状态和崩溃日志。
[tool calls]
ssh -o ConnectTimeout=10 -o BatchMode=yes ...
...
工作原理
逐 chunk 观察 reasoning-delta,检查思考文本。
独立段命中白名单时,向模型传递中断请求,掐断模型输出的片段,并补充结束标志,伪装成正常结束的思考过程。
向模型发送一条注入提示词,以恢复agent-loop。
用户会通过注入提示词这个步骤看到大模型被中断的过程,因此步骤可能会变得很多。这是不得不付出的代价。
虽然我们可以将下一步思考的过程接到上一轮打断的位置以伪装成什么都没发生过的样子,但是一方面这种做法有风险,另一方面不是很有利于缓存命中。更何况,这也能帮助用户判断插件是否在正常工作。
可配置选项
在 设置 → 复读打断 里查看,保存后生效,无需重启。
| 项 | 含义 |
|---|---|
| 累计拦截 | 掐断次数(有清零按钮) |
| 拦截短句 | 触发打断的白名单,需要加上标点 |
| 连续命中次数* | 连续命中的阈值,如果为2就需要连续出现两个短句才触发 |
| 行内重复检测* | 打开后"好。好。好。"这种挤在一行里的重复也算命中。 |
| 续跑指令 | 截断后推给模型的提示词 |
| 折叠行摘要 | 注入段用户可见的简要信息 |
* 连续的意思是中间没有长段。如果配置成2就只会拦截循环,默认配置连一个短句后的分支思考过程也会拦下。
*deepseek不存在行内重复问题,这个选项是为 qwen 35B 这样的模型准备的。
安装到 dsh
dsh plugin --profile web add dsh-repeat-guard
兼容性:
0.2.0起要求 dsh 0.1.7 及以上——0.1.7 起宿主会在装载前校验插件的 peer 声明,配置表单也换成了 entry Config 模型,旧写法在那上面不再工作。 插件用到的宿主接口在 0.2.0 上没有变化(llm/stream的 waterfall 形态、agent.steer、agent/turn-stopping的重读机制、settings与客户端configForms的形状均逐字相同),因此0.2.2起 peer 范围不再设上限。 写法是>=0.1.7-0 || >=0.2.0-0而不是>=0.1.7-0:按 semver 规则,预发布版本只被 「版本号相同的预发布比较器」接受,单写>=0.1.7-0会漏掉0.2.0-rc.x;||里那一段 专门给 0.2 的预发布开口,0.1.7 及更早的正式版仍由前一段覆盖。 dsh0.1.0-rc.8~0.1.6请装0.1.5:dsh plugin --profile web add dsh-repeat-guard@0.1.5
许可
MIT,见 LICENSE。
Minglink/dsh-infinite-gen-4
kenryu42/cc-safety-net
hyhmrright/brooks-lint
toby-bridges/api-relay-audit
hashgraph-online/hol-guard
SeaOf0/dsh-redteam-model
howmp/dsh-pentest
saya-ch/dsh-mobile