yoke233/dsh-prime-agent
受Prime Agent启发,为DeepSeek Harness代码模式设计的持久化RLM控制平面
Project Overview项目介绍
This repository is a native plugin built exclusively for DeepSeek Harness (DSH) that delivers an RLM-first control plane. It implements a model-visible persistent TypeScript REPL, where variables, functions, and objects declared in one REPL cell are retained for use in subsequent cells in the same session. It does not expose other DSH tools directly to the model schema, instead preloading them as bindings available for use within the REPL. To install the plugin, you need to configure a required stateDirectory option, and other options will fall back to sensible defaults if not set explicitly.
When a user starts a session with the Prime preset selected, only the repl tool is visible to the model. Users just need to pass a code parameter to execute a REPL cell, and can combine multiple preloaded DSH tools within the REPL to build custom complex orchestration logic for their specific workflows. Non-Prime DSH sessions are completely unaffected by the plugin, and continue to use the official one-shot semantic as normal. The plugin is targeted at advanced DSH users who need custom tool orchestration and persistent variable state across REPL calls.
The plugin is released under the open source MIT license, so it is free to use and modify for any purpose. Plugin state is stored in the configured stateDirectory, and uses cross-process write locks and atomic replacement to ensure data integrity, it also adds permission hardening for stored state. For developers looking to contribute or modify the plugin, you can run built-in npm scripts to handle type checking, unit testing, integration testing, and building. You will need a local Node.js and npm environment set up to run these development scripts.
dsh-prime-agent 是专门为 DeepSeek Harness 开发的原生插件,提供 RLM-first 控制面能力。该插件为 DSH 实现了模型可见的持久 TypeScript REPL,同一个会话中,上一个 REPL 单元声明的普通变量、函数和对象,下一个单元可以直接使用。其他 DSH 工具不会进入模型 schema,而是作为预加载绑定进 REPL 单元,供用户在 REPL 中灵活编排调用各类能力。
用户选择 Prime preset 开启会话后,只会看到一个 repl 工具,只需传入 code 参数即可执行 TypeScript REPL 单元。用户可以在 REPL 中组合调用多个预加载的 DSH 工具,实现复杂的自定义编排逻辑,普通非 Prime 的 DSH 会话不会受该插件影响,仍然使用官方的 one-shot 语义。它适合需要自定义工具编排、持久化变量状态的进阶 DSH 用户使用。
该插件采用 MIT 许可证开源,安装使用时需要配置必填的 stateDirectory 选项,未配置其他选项时会使用预设的默认值。插件的运行状态会存储在指定目录,采用跨进程写锁和原子替换保证完整性,支持权限加固。开发时可使用项目内置的 npm 脚本完成类型检查、测试和构建,需要本地有 npm 环境支持。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-prime-agent(yoke233/dsh-prime-agent)
仓库:https://github.com/yoke233/dsh-prime-agent
本站详情页:https://www.yhbd.top/plugins/yoke233-dsh-prime-agent/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 6 · 最近提交 2026-09-28 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 6 stars - very few users, little community feedback星标只有 6,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add ./dsh-prime-agent https://github.com/yoke233/dsh-tool-monitor/archive/50127e3a82d7baa858b9df1dbea12e547b7e797e.tar.gz
把 yoke233/dsh-prime-agent 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
当前架构 · Prime Agent 学习笔记 · 上游同步手册
dsh-prime-agent 是面向 DeepSeek Harness 的 RLM-first 控制面。选中 Prime preset 的会话只有一个模型可见工具 repl:它的唯一参数是 { code },执行一个持久 TypeScript REPL cell。上一 cell 声明的普通变量、函数和对象,下一 cell 可以直接使用;DSH 的其他工具不进入模型 schema,而是作为 tools、agents、jobs 绑定预加载进 cell。
// 第 1 次 repl
repl({ code: `
const lookup = new Map(records.map(item => [item.id, item]))
const review = async (id) => tools.review_item({ item: lookup.get(id) })
lookup.size
` })
// 第 2 次 repl —— 同一会话的新调用
repl({ code: `await review('a') // Map 和函数都还活着` })
普通会话完全不受影响,继续使用官方 one-shot 语义。
工作原理
- 模型 catalog 只含
repl。Prime declaration 不挂载workflow或ralph;若其他 Host bundle 提供全局workflow,preset policy 会在每个已加入的 Agent context 上同步 inherited-tool restriction,而不修改 Host registry 或其他 preset。其余能力只作为 cell 内预加载的tools、agents、jobs绑定出现;直接从外层调用会被 guard 拒绝。Prompt assembly 从当前 Agent-local catalog 生成 declaration/JSDoc,并把外层 schema 过滤到repl。tools.*向 Realm 返回 canonical value;对象结果未经转换直接成为 completion 时才使用 DSH 官方result.content展示。 - 路由信任 Agent 执行上下文。
repl要求拥有 Agent 会话:插件用可信exec.agent.id从共享realm-identity存储解析该会话稳定的不透明 Realm id,再把程序、本轮租约绑定与取消信号交给 host 侧的ctx.primeRealmRuntime.run(...)。没有握手、没有模型可见的身份工具;缺少可信执行上下文或无法解析 Realm id 时明确失败,绝不降级。 - Host 服务与官方运行时并存。
cordis.patch.yml只是把dsh-prime-agent/runtime作为新 row 插入,官方code-runtimerow 原样保留;非 Prime 会话继续使用官方 one-shot 语义,不存在 fallback。 - Realm 内的绑定经跨 run 稳定的 Proxy 与 per-run binding lease 调用:schema、审批、沙箱、日志、并发和取消仍由 DSH 执行,run 结束立即撤销授权。
- 多个 TUI 进程可共享 Prime 持久状态并同时运行不同 Session;同一 Session 的 live Realm 同时只允许一个进程持有,owner 退出后另一进程以空 namespace 接管。
- Prime 不封装搜索 provider:
tools.grep仍调用 DSH 正式grep。提示词组装按工具名复制 schema;Prime 的pwsh副本移除与外层 TypeScript 正斜杠规则冲突的 native path 句子,各工具 description 只追加自身缺失的关键约束;grep说明普通文本使用字符串,正则语法使用无 flags literal 的.source(例如pattern: /stream\(options\)/.source),并要求 parse error 后修正再重试。生成 SDK 与 Realm interface 都保持 DSH canonicalpattern: string,不扩展公开类型,也不修改 catalog 中共享定义;Host binding seam 只接收 lossless JSON。 - Prime 额外注册本地组合能力
tools.apply_patch({ patch }):对齐 OpenAI Codexapply_patch的 marker/heredoc parser、顺序 hunk、EOF/纯追加和 exact → rstrip → trim → Unicode 归一化匹配语义,并一次预检同文件多 hunk 或多文件 Add/Update;Add 与 Codex 一样允许覆盖已有目标。相对或绝对目标路径原样交给 Agent catalog 中正式的 DSHread/writenested calls,路径解析与授权、sandbox、approval、observation、日志、取消和单文件原子发布仍由 DSH 拥有。每个 REPL nested call 按官方tool/ptc-dispatch-start/tool/ptc-dispatch协议记录,因此官方 Web 与兼容 TUI 都能递归显示;apply_patch投影标准card: 'diff',失败结果走 generic error fallback。edit继续用于一次精确的原位替换;apply_patch负责相关的多 hunk/多文件变更,两者不互相替代。 - Profile 显式安装的 DSH Host MCP client 把 server tools 注册进统一 catalog,repl 单元自动获得对应
tools.*绑定;Prime 不复制 Python kernel-owned MCP runtime。 - Prime preset 挂载 DSH 官方持久 Terminal:POSIX 使用 Bash,Windows 使用 PowerShell;
terminal_open/terminal_send/terminal_read/terminal_signal/terminal_close/terminal_list通过tools.*调用。同行安装的dsh-tool-monitor可对后台terminal_send产生的pty-send-*Job 做逐行 JavaScript 正则订阅。 - Prime preset 不挂载 DSH Plan Mode。默认上下文管理改为可回取历史的工作窗口:旧消息退出窗口后保留目录,模型通过
tools.history_search/history_read回查本 Session 的已记录内容,通过tools.notes_read/notes_write保存任务进度。不会调用模型生成历史摘要;DSH 继续拥有配对、持久化、计量和溢出恢复。非 Prime preset 不受影响。 dsh-prime-agent/context-manager的压力阈值默认 0.8,Prime preset 为deepseek-official/deepseek-v4-flash保留 0.3,并在阈值前 16384 tokens 每个工作窗口至多注入一次 task-note checkpoint 提醒;插件默认关闭该提醒,显式设置checkpointReminderTokens才启用。普通压力处理保留约 16000 tokens 的最近尾部,并按工具配对边界调整。仍保留 base Host compactor 的 TUI 组合中,Prime 会以前置的 Agent-scope pressure pass 先替换窗口;成功后 Host listener 读取到已降压的 surface 并跳过,Prime 失败时才继续走继承的恢复链。模型可先保存笔记,再调用tools.new_context({})请求下一 step 切换;主动切换与溢出恢复使用 DSH 的最小安全尾部策略。/compact也使用同一目录替换方式。preset 不注册 provider、不修改模型窗口容量。- 任务笔记与
refine学习状态分开:笔记是最多 6000 字符的单份当前恢复快照,不是追加式流水账;位于DSH_HOME/prime-agent/context-notes/<Session id 的 SHA-256>.json,带 revision 检查和 Host 写入的updatedAtSessionOffset新鲜度位置,重启后可读,child 有自己的笔记。旧文件读作未知新鲜度并在下一次成功写入时升级。该位置不证明笔记内容正确;后续用户纠正和外部变化仍须核验。历史接口不暴露请求头或私有推理;日志中的 spill locator 与图片附件仍是引用,回取依赖原有 artifact 的保留和访问能力,不能视为无限期保真存储。 tools.*返回值始终遵循 canonicalToolOutputMap,可直接访问read.lines、edit.before/after等字段;对象结果直接成为 completion 时只改变模型展示为官方 content,不改变程序拿到的值。不要对返回值盲目再次JSON.parse。notebook 结构化 preview 中的\\只是 JSON notation;模型自行编写 Windows 路径时优先使用D:/work/project形式,避免额外转义层。工具参数使用 TypeScript 对象字面量;完整 cell 会在执行前解析;语法失败不会执行其中任何代码或 tool call,并报告不含源码片段的 cell 行列与 parser message,模型据此修正后重试。agents.*还带两个无状态子模型调用:agents.query({ prompt, system?, maxTokens? })返回{ text, truncated },agents.queryMany({ prompts, system?, maxTokens? })按输入顺序返回{ replies }。它们对已在 REPL 变量里的文本做一次性模型调用(摘要、分类、抽取、比较),走当前 Agent 的模型路由;与refine一样不注册为 DSH tool、不进入tools.*、不产生 dispatch 日志,但写进生成的agents声明及其 JSDoc。回复只有被显示时才进入对话。预算由插件llm配置约束:单条 prompt 上限 200,000 字符、单批最多 20 条、批内并发 8、maxTokens默认且上限 4096;越界在调用模型前拒绝。批内一项失败后停止领取新请求、取消同批在途请求并等其收尾,再报告失败下标;整批不返回成功项。并发限制按单批计算,多批并行会叠加;它不是会话级费用上限。truncated: true的回复需作为不完整材料处理。需要工具或多步推理的子任务仍用agents.spawn。它们挂在agents下而不是独立全局,是因为向 Realm 注入第五个全局会在两个 Realm 同时销毁时触发 Worker 的 V8 fatal(见架构文档)。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
titanwings/distilly
YuJunZhiXue/dsh-purge
Clearailhc/clearai-dsh
yejiming/MuseAI
superdesigndev/superdesign-skill
Miaotofu01/Study-Mate