Introduction¶
DeepSeek Harness (DSH) embraces the principle of “everything is a plugin”. When maintaining multiple projects over a long period, iterating on SKILL.md can easily introduce regressions or cause loss of existing capabilities. Manual evaluation and upgrades are expensive and risky. The DSH Evolution Lab plugin uses an automated, isolated evaluation workflow to turn recurring project experience into verifiable candidate skills, addressing the security and consistency challenges in skill maintenance.
Plugin Positioning¶
DSH Evolution Lab is a plugin for the self-evolution of Proof-carrying Skills. It is maintained by JayDong9130 and belongs to the workflow tool category. Its core function is to convert recurring project experience into isolated SKILL.md candidate files, compare baseline and candidate versions in isolated DSH processes, run held-out test cases, and perform atomic skill promotion or rollback without human approval queues.
Installation¶
The plugin currently supports DSH 0.1.0-rc.6 and Node.js 22/24. It supports web and headless profiles. A version number must be specified during installation.
Run the following command in your terminal to install it into the corresponding profile (for example, web):
npx @deepseek-ai/dsh@0.1.0-rc.6 plugin --profile web add dsh-evolution-lab@0.3.1
After installation, restart the DSH Web service and refresh the page for changes to take effect.
Core Features¶
V1 of the plugin focuses on evolving a single Markdown skill and has the following characteristics:
- Isolated evaluation: Evaluates baseline skills and candidate skills in separate DSH processes, avoiding interference.
- Canary testing: Runs held-out test cases to verify candidate performance on unseen data.
- Atomic operations: Skill promotion or rollback is atomic, with no human approval queue. Ineligible candidates are rejected automatically.
- Security boundary: The plugin cannot generate Cordis plugins, scripts, tools, workflows, sandbox rules, approval policies, or changes to DSH source code. It is limited to Markdown skills only.
- Privacy protection: Sensitive identifiers are pseudonymized using HMAC signing. Data is stored in the local
.dsh/evolutiondirectory and subjected to a secondary leakage scan.
Enabling a Project¶
In a profile where the plugin is installed, open a conversation belonging to a Git project. An “Enable auto evolution” control (injected via a DSH additive slot) appears in the conversation header.
Click the control once. The plugin atomically creates the .dsh/evolution/config.yaml configuration file and enables the project. If the configuration file already exists and is invalid, the plugin refuses to overwrite it and reports an error. For Headless mode or users who need to review configuration manually, the file can be created manually. Example content:
version: 1
enabled: true
engine:
kind: native
provider: deepseek
model: deepseek-chat
collection:
includeSubagents: false
maxTrajectoryBytes: 131072
minClusterSize: 3
minEvidenceWeight: 20
evaluation:
minTasks: 3
maxParallel: 2
timeoutMs: 600000
requiredPassRateDelta: 0.05
maxCostRatio: 1.20
maxDurationRatio: 1.50
canary:
minTasks: 2
requiredPassRateDelta: 0
promotion:
automatic: true
monitorIntervalMs: 86400000
rollbackAfterConsecutiveFailures: 2
Typical Usage¶
The plugin manages the skill evolution workflow through command-line instructions:
/evolution status: View configuration, current version, queue status, evaluation readiness, and monitoring health./evolution run: Enqueue an evolution cycle. This command cannot skip evidence collection or security checks./evolution eval init: Generate an initial runnable task package and README under.dsh/evolution/evals/./evolution history [skill]: View immutable candidate records, promotion records, and rollback records./evolution rollback <skill>: Restore the specified skill to the latest verified previous version./evolution enable//evolution disable: Toggle the local enabled state of the project.
Lifecycle and Security Boundaries¶
The evolution workflow follows a strict order to ensure that every step is verifiable:
- Submit session events.
- Local dual filtering (Red Hat).
- Extract intent atoms and perform evidence-weighted clustering.
- Generate isolated skill candidates.
- Immutable security scan.
- Isolated validation of baseline and candidate.
- Run held-out test cases.
- Write proofs before atomic activation.
- Periodic probe monitoring.
- Automatically roll back on regression.
No human approval means there is no pending approval queue. It also does not imply unrestricted modification. Unsafe, insufficiently evaluated, outdated, or privacy-violating candidates are rejected automatically, and there is no forced override flag.
Data Privacy¶
Raw DSH session logs remain owned by the main DSH program. Evolution Lab stores only bounded, pseudonymized envelope data under .dsh/evolution. Sensitive identifiers are pseudonymized using HMAC. A secondary leakage scan is performed before data is persisted or submitted to the engine. HMAC keys are stored in mode 0600 in the $DSH_HOME/evolution-lab directory and are never stored inside the project code repository.
Use Cases and Notes¶
- Use cases: Developers who need to maintain many
SKILL.mdfiles in a DSH environment and want automated quality assurance. - Note: DSH is in developer preview. The plugin currently evolves only a single Markdown skill (V1) and does not modify DSH core configuration or source code. Confirm that the source code and license meet project requirements before installation.
For more details, refer to SkillHub or the GitHub repository.