Introduction

When developing agents in DeepSeek Harness (DSH), you often encounter scenarios that require delayed decision-making: for example, waiting for an asynchronous task to complete, checking service health, or re-evaluating an old plan after the current environment changes. A simple reminder or notification cannot solve the core problem—the agent needs to truly “come back,” make a decision based on the latest evidence, rather than mechanically executing a command from two minutes ago.

dsh-delayed-task is a DSH plugin designed to solve this problem. It provides persistent delayed-task capabilities, supports waking up the agent after a page is closed, and re-evaluates decisions based on current evidence rather than mechanically executing historical plans.

Plugin Overview

dsh-delayed-task is maintained by developer m-guo-2 and is licensed under the MIT License. It stores tasks and authorization information in the DSH storage domain, does not rely on the browser environment, and ensures that background processes can be scheduled normally.

Core Features

Persistence and Wake-up

The plugin stores tasks persistently. As long as the DSH background process is alive, a task can wake up the original session after the page is closed when the task expires. If DSH or the machine stops during the task period, overdue tasks will be triggered after recovery.

Evidence-based Re-evaluation

When a task expires, the agent receives an event prompting it to re-judge based on current evidence rather than mechanically execute historical plans. This avoids blindly executing old instructions when the environment has already changed.

Authorization Modes

The plugin provides two authorization modes:

  1. Re-evaluation Only (default): the agent can only use observational tools (such as read and search) and cannot perform write, delete, or network fetch operations.
  2. Limited Background Execution: the user confirms a bounded grant at creation time, limiting the authorization lifetime, tool allowlist, maximum call count, and so on. Expired or exhausted grants automatically fall back to the Re-evaluation Only mode.

Provided Tools

The plugin provides the following tools to the agent:
* delayed_task_create: create a delayed decision.
* delayed_task_list: view the tasks in the current session.
* delayed_task_cancel: cancel a task.
* delayed_task_revoke_authorization: revoke authorization (keeping the task in re-evaluation-only mode).

Installation and Enablement

Prerequisites:
* Node.js 22.19+
* pnpm 10
* A runnable DSH developer preview

Installation commands:

dsh plugin --profile web add github:m-guo-2/dsh-delayed-task
dsh --profile web --dump-config

It is recommended to install from a pinned commit to ensure safety:

dsh plugin --profile web add github:m-guo-2/dsh-delayed-task#<commit-sha>

Typical Usage

The agent can create a delayed task in the current session and specify a future point in time for re-evaluation.
For example:
* Re-check after 120 seconds whether README.md exists and report whether evidence can be collected read-only.
* Re-check health status a few minutes after deployment.
* Wait for an asynchronous task, CI, or data processing to enter the next state.
* Decide whether to retry based on the latest status after rate limiting or a temporary failure.

Notes

  • Not a cron service: this plugin is not a cron or system notification service; it does not send email or system notifications. Results are saved in the original session.
  • Process dependency: the DSH background process must be alive. Tasks are not executed while the process or machine is down, and they are triggered after recovery.
  • Session management: if the original session no longer exists or the user aborts the delayed turn, the task is automatically canceled.
  • Permission inheritance: if the original session uses danger-full-access, even when a bounded grant is used, the file and process boundaries are not further narrowed.

Summary

dsh-delayed-task provides a mechanism for implementing delayed decision-making in DSH. Through persistent storage and explicit authorization control, it allows the agent to safely re-evaluate after environmental changes, making it suitable for scenarios that require waiting for external states, asynchronous operations, or continuous monitoring.