Preface¶
DeepSeek Harness (DSH) treats model-visible context as part of a session or agent lifecycle. A repository context plugin should be inspectable and bounded, rather than silently pouring the entire repository into every prompt. dsh-context-pack aims to address this by providing deterministic, privacy-aware repository context packs.
Positioning¶
This is a plugin maintained by MkaliezZ that provides deterministic, privacy-aware repository context pack functionality. It converts repository context into structured, bounded data packets through DSH native commands and APIs for consumption by model steps.
Core Features¶
The plugin provides the following core capabilities:
- Command-line scanning: Provides the
/context-pack [repository path]command to perform explicit, read-only scans. - Boundary control: Supports budget controls based on file count, total bytes, per-file bytes, and injected bytes.
- Privacy protection: Uses a fail-close strategy to exclude sensitive paths (such as
.env, common credential/key names), and supports text extension allowlists. - Verifiability: Generates SHA-256 hashes for each file and the entire pack, ensuring traceability of context content.
- Security constraints: The plugin makes no network requests at runtime and does not modify source code.
Configuration and Usage¶
The plugin is loaded through DSH’s bundle mechanism. Specify the package name and parameters in the configuration file:
- id: dsh-context-pack
name: '@mkaliezz/dsh-context-pack'
config:
maxFiles: 60
maxTotalBytes: 120000
maxFileBytes: 30000
maxInjectedBytes: 120000
Command-line Invocation¶
Execute the command in the DSH environment:
/context-pack .
The command returns a compact receipt containing the pack hash, number of included files, source byte count, and exclusion count. The model-visible pack is injected separately through DSH’s agent.inject() interface, rather than echoed directly in the command result.
API Invocation¶
The plugin exports the buildContextPack function:
const pack = await buildContextPack('/path/to/repo', {
maxFiles: 60,
maxTotalBytes: 120_000,
maxFileBytes: 30_000,
})
Notes¶
When using this plugin, note the following limitations:
- Not a security tool: It is not a secret scanner or DLP system, nor is it a sandbox.
- Git ignore compatibility: Full
.gitignorecompatibility is not currently available. - Semantic ranking: No semantic relevance ranking is provided.
- Sensitive filename coverage: It cannot guarantee coverage of all sensitive filename patterns.
- Persistence limitations: Version 0.1 does not persist independent context pack lifecycle records (it relies only on DSH’s own command/inbox/session facts).