zcx369658780/governed-workflow-for-dsh 预览 preview

zcx369658780/governed-workflow-for-dsh

Plugin插件 Native原生 ⭐ 2 MIT Subagents & Orchestration子代理与编排

面向DeepSeek Harness代理的基于策略强制、以证据为先的受管工作流。

Project Overview项目介绍

dsh-governed-workflow is a community plugin for DeepSeek Harness that adds task authority, lifecycle, and independent review boundaries to coding agents. It collapses free-form vibe coding into GitHub Issue authority, allows protected mutations such as bash, write, and edit only while a task is RUNNING, then freezes changes in terminal states for separate review. Best suited to multi-file, long-running projects with real release or data risk. Note: this is a V0.9 Developer Technical Preview, the IH-1 installer is not yet on main, and it is not a full OS sandbox.

dsh-governed-workflow 是面向 DeepSeek Harness 的社区插件,为 Coding Agent 增加任务权限、生命周期和独立验收边界。它将 vibe coding 收敛为:先由 GitHub Issue 给出 authority,仅在 RUNNING 期间允许 bash/write/edit 等受保护修改,进入终态后冻结并交独立 Reviewer。适合多文件、长会话、有真实上线或数据风险的项目。注意:当前为 V0.9 Developer Technical Preview,IH-1 安装脚本尚未合并到 main,且尚未提供完整 OS 沙箱。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:zcx369658780/governed-workflow-for-dsh

把 zcx369658780/governed-workflow-for-dsh 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

Governed Workflow for DSH

中文

1. 插件简介

dsh-governed-workflow 是一个面向 DeepSeek Harness 的独立社区插件,用来给 Coding Agent 增加一层明确的任务权限、生命周期和独立验收边界。

它把一个常见的 vibe-coding 流程从“给 Agent 一句话,然后让它自由修改”收敛成:先由 GitHub Issue 给出任务 authority,只有进入 RUNNING 后才允许受保护的修改,完成或阻塞后冻结修改并交给独立 Reviewer / Owner。

当前版本为 V0.9 Developer Technical Preview;已验证基线为 @deepseek-ai/dsh@0.1.0-rc.6,包名为 dsh-governed-workflow。本项目不隶属于 DeepSeek,也不代表 DeepSeek 官方背书。

2. 具体功能

工作流

GitHub Issue Authority
        ↓
     OBSERVE
        ↓
      ADMIT
        ↓
       RUN
        ↓
BLOCK / COMPLETE
        ↓
      REVIEW
  • GitHub Issue Authority:可以从公开 GitHub Issue 中读取机器可解析的 authority block;Builder 不应从旧聊天记录、分支存在或自己的计划中推断任务权限。
  • Lifecycle 状态机:任务按 AUTHORITY_OBSERVED → TASK_ADMITTED → RUNNING → BLOCKED/COMPLETED → REVIEW_PENDING 推进,非法迁移 fail closed。
  • RUNNING-only Mutation Guard:当前受保护的 DSH mutation tools 为 bash、write、edit;没有 accepted authority 或状态不是 RUNNING 时拒绝执行。
  • 模型侧治理工具:提供只读的 governance_status,以及受限动作集的 governance_transition。
  • 终态冻结:进入 BLOCKED、COMPLETED 或 REVIEW_PENDING 后重新禁止受保护修改。
  • 独立验收边界:Builder 不能自行 ACCEPT、merge、关闭已接受任务或创建/激活后续任务;最终决定留在 Builder Runtime 之外。
  • 治理证据:authority 观察与 lifecycle transition 会记录为受限治理证据,方便审查和回放。

这种工作流的取舍

优势:任务边界更清楚,能减少长会话中的 scope drift 和误修改;什么时候可以改、什么时候必须停止比较明确;对需要真实验收、回滚和审查的项目更友好。

劣势:比自由式 vibe coding 多了 Issue、状态迁移和 Review 的流程成本,因此会牺牲一部分速度;当前实现也不是完整 OS sandbox——allowedPaths 文件系统硬隔离、Git 命令语义、GitHub merge/close API 等仍不是 Runtime 强制边界。

更适合:中等及以上规模、多文件、长会话、多阶段交付、需要运行命令/修改真实代码、上线或数据风险较高的 vibe-coding 项目,例如 App、后端服务、研究工具、自动化系统和长期维护仓库。

不太适合:一次性小脚本、几分钟的 throwaway prototype、完全可丢弃的实验;这类任务的治理成本可能高于收益。

3. 安装方式

IH-1 正在把安装方式收敛为一个可维护、可 clean-room 验证的安装脚本。当前候选脚本已经是:

scripts/install-dsh-governed-workflow.mjs

候选调用方式为:

node scripts/install-dsh-governed-workflow.mjs --profile governed --ref <40位 Git commit SHA>

该脚本要求显式提供 DSH Profile 和 immutable source ref,不会默认安装浮动的 main。当前候选实现会执行固定 GitHub source install,并在安装后自动运行:

dsh --profile governed --dump-config

用于确认 Governed Workflow 的五个默认组件已经加载,同时不会自动启用可选的 GitHub Issue network-authority bootstrap。

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev semantic-search 下一个 Next dsh_cardian →