yhfgyyf/dsh-guardian-mode
The fifth mode of DeepSeek Harness (DSH): preset id guardian, combining PTC code presentation, independent review, and a human-approved Cordis remediation loop.
catalog 简介 / catalog descriptioncatalog description:Guardian preset for DeepSeek Harness with independent persistent Codex auditing
项目介绍Project Overview
dsh-guardian-mode 是 DSH 的 guardian 预设插件,保留标准模式能力,并以代码呈现、双角色独立审查和人工批准后的 Cordis 修复循环工作。适合需要持续审计、关键变更须确认的会话;审查后端可选 Codex、Claude Code 或 DSH。注意:未接受的修复不会执行,审查状态写入 sidecar,配置模型不受支持时会直接报错。
dsh-guardian-mode is a DSH plugin adding the guardian preset. It keeps standard-mode capabilities while running isolated summarizer and auditor reviews, with Cordis remediation tools exposed only after a human accepts a critical finding. Use it for sessions needing continuous audit and gated self-repair. Reviewer backends can be Codex, Claude Code, or DSH. Caveat: unaccepted feedback is not applied, state is stored in a sidecar, and unsupported configured models fail loudly.
请帮我了解并安装插件:【dsh-guardian-mode】【https://github.com/yhfgyyf/dsh-guardian-mode】
把上面这条消息直接发给当前会话里的 DSH,让它帮你了解并安装。安装命令不一定准确,发给 DSH 更稳。Send this message to DSH in your current session. CLI install commands may not be accurate across systems — DSH will figure it out for you.
或使用命令行安装(适合开发者)Or use CLI install (for developers)
命令行安装CLI Install
dsh plugin --profile web add github:yhfgyyf/dsh-guardian-mode
把 yhfgyyf/dsh-guardian-mode 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-guardian-mode
The fifth mode of DeepSeek Harness (DSH): preset id guardian, combining
PTC code presentation, independent review, and a human-approved Cordis
remediation loop.
An agent on this preset keeps full standard-mode capabilities (shell,
filesystem, web, skills, goals, subagents, workflows, Code Mode tool
presentation). Cordis self-modification tools stay model-hidden during ordinary
work and are exposed temporarily only after the user accepts a critical
remediation. Separately, every session drives two isolated reviewer roles. The
reviewer backend is configurable as Codex, Claude Code, or the host
DSH LLM runtime. The default remains one persistent Codex app-server:
| Role | Default model | Effort | Job |
|---|---|---|---|
| summarizer | gpt-5.6-luna |
medium | incremental trace summary per round |
| auditor | gpt-5.6-sol |
max | independent audit → pass / warning / critical |
Codex and Claude Code keep separate persistent role sessions. The DSH backend
uses direct, tool-free llm.stream() calls instead of starting another DSH
Agent, so it cannot recursively enter Guardian mode. Those calls are stateless,
so Guardian includes the current objective and a bounded tail of sidecar review
memory in every DSH audit.
All unaccepted feedback and reviewer state is written to a sidecar
(${DSH_HOME:-~/.dsh}/guardian/sidecars/<sessionId>.json). Only explicit human
acceptance appends a bounded <guardian-remediation> prompt and capability
lease at the context tail. The model then loads the named skills through DSH's
stable skill tool; prior messages are never rewritten and raw reviewer output
remains private.
Install
# in your dsh profile (profiles/web and profiles/tui use the same pattern)
cd ~/.dsh/profiles/web
pnpm add dsh-guardian-mode@github:yhfgyyf/dsh-guardian-mode
# Recommended stable tool discovery for Guardian and Auto target presets:
pnpm add dsh-progressive-tools@github:yhfgyyf/dsh-progressive-tools
# add both bundles to package.json dsh.profile.bundles (both profiles),
# then restart the profile.
The bundle patch adds one dual-face row:
- insert:
- id: guardian-bundle
name: dsh-guardian-mode
The node half mounts the host guardians service, registers the /guardian
command, and (when a webserver is present) the Remote API. The same row's
browser half (dsh.client) renders the guardian strip in the composer dock.
Using the mode
- Start a session with
--preset guardian(TUI) or pick guardian in the Web preset chip, or/preset guardianon a blank session. /guardian status— round, cadence interval, last verdict, pause state./guardian now— force an audit (out of cadence)./guardian history— recent audits from the sidecar./guardian accept [audit-id]— approve the latest/specified remediation./guardian resume— clear a non-critical-review failure/manual pause.
Reviewer configuration
Configure the guardian-bundle row in the profile's cordis.patch.yml. No
configuration preserves the existing Codex defaults:
- id: guardian-bundle
config:
reviewer: codex
binary: codex
args: [app-server, --stdio]
models:
summarizer: { model: gpt-5.6-luna, effort: medium }
auditor: { model: gpt-5.6-sol, effort: max }
summarizer and auditor are stable, responsibility-based keys; their model
names remain fully configurable. Legacy luna / sol keys are still accepted
and are migrated to the new names at runtime.
Claude Code uses print mode with JSON-schema output, plan permission mode,
safe mode, and an empty tool set. Set Claude-supported model names explicitly:
- id: guardian-bundle
config:
reviewer: claude-code
claudeBinary: claude
claudeArgs: []
models:
summarizer: { model: haiku, effort: medium }
auditor: { model: opus, effort: max }
The DSH backend routes directly through a registered provider. A per-role
provider overrides dshProvider when summary and audit use different routes:
- id: guardian-bundle
config:
reviewer: dsh
dshProvider: deepseek-official
dshMaxTokens: 4096
models:
summarizer: { model: deepseek-v4-flash, effort: off }
auditor: { model: deepseek-v4-flash, effort: high }
Changing reviewer does not translate model names. Guardian fails loudly if
the selected backend does not support a configured model; it never silently
substitutes an audit model.
Behavior
- Cadence: the first audit requires at least two steps and 60 seconds; later audits run every three steps or three minutes, with a 60-second minimum gap. Anomalies audit at the next safe boundary.
- Warning approval: a warning leaves the main Agent running. Acceptance cancels the current turn, appends the approved repair prompt, executes one repair turn, and performs a fresh verification audit.
- Critical approval: critical pauses the main Agent and active Goal first.
Acceptance temporarily exposes Cordis tools and appends a capability lease.
The repair Agent must load
editing-cordis-compositionsthrough the stableskillloader, and loadscordis-plugin-developmentonly for plugin or model-facing-tool work. The original task resumes only after the repair audit is no longer critical. - Three consecutive failures (reviewer unreachable, timeouts, malformed
replies) pause the session with reason
failures. - Every 5 rounds a full objective-alignment audit runs (objective + boundary rules + recent summaries).
- Final audit runs when the session is disposed (or
/guardian nowwith the Remote APIfinal: true). - Fixed capability:
guardian(GUARDIAN_CAPABILITY). The auto router keeps routing only standard / code / minimal / cordis.
Remote API (browser)
Third-party routes, declared by this package:
| Method | Path | Body / query |
|---|---|---|
| GET | /api/guardian/snapshot |
?session=<id> |
| GET | /api/guardian/watch |
?session=<id> (SSE event: guardian) |
| POST | /api/guardian/request-now |
{ sessionId, final? } |
| POST | /api/guardian/accept |
{ sessionId, auditId? } |
| POST | /api/guardian/resume |
{ sessionId } |
The Web dock strip registers at conversation.input.dock order 5 —
rendered between the Todo strip (order 0) and the Goal strip (order 10).
TUI
dsh-tui-app renders an independent color-coded block (pass=green,
warning/critical/paused=red) beside the config row:
a— accept a pending remediation (empty composer only)c— copy feedback while pausedr— resume a non-critical-review pauseEsc/Ctrl+C— stop current work
Development
npm test # unit + integration
npm run check # syntax, package manifest, tests
npm run pack:check # npm pack --dry-run
scripts/build-preset.mjs regenerates presets/guardian/agent.cordis.yml
from the shipped code + cordis compositions (checked-in result, so the
package works standalone). Tests use test/fixtures/fake-codex.mjs and
fake-claude.mjs; no real reviewer login is required. Backend, models, effort,
binaries, CLI arguments, DSH provider route, timeout, and DSH output limit are
configuration rather than constants.
Compatibility
- Never calls
session.deleteor any session-removal API; disposal is observed via the hostsession/disposedevent for a final audit only. - Auto still routes only the original four modes. When the companion auto router supports capability hints, those names are appended after routing and do not alter the original user prompt.
- Images, ordinary skills, goals, subagents, and workflows flow unchanged.
Guardian's two composition skills are progressive, critical-approval-only
additions (see
presets/guardian/agent.cordis.yml). - Persisted messages remain byte-for-byte unchanged. Acceptance only appends
remediation, runtime-catalog, and continuation tail messages, so the prior
message prefix remains eligible for KV-cache reuse. With
dsh-progressive-tools, Cordis restriction changes affect discovery results rather than the model-visible system/tool prefix. Without that companion, DSH normally rebuilds the Code Mode SDK when visibility changes. An actual plugin/system-prompt repair still takes effect through DSH's normal restart/new-task prefix rebuild. - Does not modify the global node_modules; install as a profile bundle.
nexu-io/open-design
freestylefly/awesome-gpt-image-2
anywhere-labs/dsh-desktop
walkinglabs/learn-harness-engineering
awesome-dsh-plugin/awesome-dsh-plugin
MemTensor/MemOS