Introduction¶
In the development of DeepSeek Harness (DSH), subagent delegation is a common way to increase task complexity. By default, this delegation often involves pass-through of the model ID, which can lead to unintended Provider selection or uncontrolled reasoning effort. The dsh-routed-subagent plugin aims to solve this problem. It requires each delegation call to explicitly select a model policy configured via the model parameter and a precise reasoning effort configured via the reasoning_effort parameter. The plugin enforces whitelist routing and rejects arbitrary Provider or Model pass-through.
Features¶
The plugin primarily provides the following capabilities:
- Whitelisted model and reasoning routing: Allows callers to dynamically select models and reasoning effort based on local policy.
- Call validation: Before creating a subagent, the plugin validates the combination of
modelandreasoning_effortbased on local policy andctx.llm.resolveCallConfig(). - Execution mode support: Supports foreground and background execution, controlled by the
run_in_backgroundparameter. - Depth and permission control: Supports configuring maximum delegation depth (
maxDepth) and model policies. Untracked agents with a depth greater than zero do not receive model permissions. - Configuration interface: Provides a complete router configuration settings card.
Installation and Enablement¶
Installing the plugin requires specifying the target Profile.
dsh plugin --profile <your-profile> add github:leonardoxr/dsh-routed-subagent#v0.3.0
You can also install it using a locally packaged file:
dsh plugin --profile <your-profile> add C:/path/to/dsh-routed-subagent-0.3.0.tgz
After installation, the plugin is registered as the routed_subagent tool.
Configuration¶
Configuration is done through the routed-subagent entry in a Profile Patch. Enabling the delegation feature requires both rootModels and models to be configured. If no complete policy is configured, the plugin only exposes the settings card and does not register the delegation tool.
- id: routed-subagent
config:
toolName: routed_subagent
maxDepth: 2
rootModels: [codex-mini, codex-sol]
models:
codex-mini:
provider: openai-codex
model: gpt-5.4-mini
reasoningEfforts: [low, medium]
maxTokens: 16384
description: 'Mechanical edits, lookups, and summarization.'
codex-sol:
provider: openai-codex
model: gpt-5.6-sol
reasoningEfforts: [medium, high, xhigh]
maxTokens: 65536
description: 'Architecture, multi-step reasoning, and hard debugging.'
spawnableModels: [codex-mini]
In the application UI, the router configuration can be edited under Settings → Plugins → Routed subagent. All changes are staged before clicking Save changes; after a successful save, the tool is hot-reloaded and any previously configured recursive permissions are invalidated. Clicking Reset to composition clears all router overrides.
Tool Contract¶
The registered routed_subagent tool accepts the following parameters:
| Field | Required | Description |
|---|---|---|
description |
Yes | Short display label |
prompt |
Yes | Complete, standalone subtask prompt |
model |
Yes | Configured model policy ID allowed in the current caller context |
reasoning_effort |
Yes | Exact effort ID allowed by that policy |
run_in_background |
No | Run via the Harness Jobs service |
Both foreground and background execution echo the effective { id, provider, model, reasoningEffort } selection for auditing.
Configuration Reference¶
The configuration keys, their defaults, and their meanings are as follows:
| Key | Default | Description |
|---|---|---|
toolName |
routed_subagent |
Registered tool name |
enableRunInBackground |
true |
Exposes the run_in_background parameter |
maxDepth |
1 |
Positive integer absolute delegation depth limit |
rootModels |
Required | Non-empty list of policy IDs available to the top-level agent |
models |
Required | Non-empty configured-model whitelist |
models.*.provider |
Required | Registered LLM provider route |
models.*.model |
Required | Exact model ID owned by the provider |
models.*.reasoningEfforts |
Required | Non-empty exact-effort ID whitelist |
models.*.maxTokens |
— | Positive output Token limit |
models.*.description |
— | Short routing trade-off description shown to callers |
models.*.spawnableModels |
[] |
Policy IDs that subagents under this model are allowed to call |
Configuration is strict: unknown fields, duplicate IDs, empty whitelists, unsafe numeric values, and unknown references all cause loading or saving to fail.
Notes and Security¶
- Strict configuration: If the strict validation rules above are not met, the plugin will not load or save properly.
- Permissions and recursion: Untracked agents with a depth greater than zero do not obtain model permissions; subagents can only call models listed in their selected policy’s
spawnableModels. - DNS-rebinding defense: The Harness
/apitrust fence is intended to defend against DNS-rebinding, not to provide authentication. Anyone who can access the server can initiate tasks available to their agents. Do not configure expensive routes inmodelsunless you are willing to bear the cost. - Version differences: The README mentions
v0.3.0, whilepackage.jsonshows version0.3.1. Refer to the official installation commands provided when installing.
Conclusion¶
dsh-routed-subagent provides fine-grained subagent control for DeepSeek Harness. By enforcing whitelist routing and reasoning effort validation, it ensures deterministic task execution. The plugin follows the MIT License and is maintained by leonardoxr.