During task execution, DSH (DeepSeek Harness) agents often stop naturally or falsely claim completion without actually running the repository’s tests, builds, lint, or type checks. dsh-completion-gate is a DeepSeek Harness plugin that acts as a boundary, preventing the agent from closing a task without machine-verifiable evidence.
The plugin is maintained by AGSQ11 and is licensed under MIT. It combines two mechanisms—premature-stop protection and a production-readiness gate—to ensure that a task can only end when the work is truly complete and has been machine-verified.
Core Features¶
Premature-Stop Protection¶
When the model stops naturally and the latest output contains strong signals of unfinished work, the plugin intervenes. Such signals include, but are not limited to, expressions such as “Now I need to inspect…”, “Next I will run…”, and “I still need to…”.
The plugin schedules a new agent.followup() call, requiring the agent to continue the unfinished task. An example recovery message is:
PREMATURE STOP RECOVERY:
Continue the unfinished task.
Execute the pending investigation or implementation now.
Do not summarize or claim completion yet.
This recovery chain is bounded by prematureStopMaxContinuations to prevent infinite loops.
Production-Readiness Gate¶
Once code changes occur, the root agent must provide machine evidence and a structured final review before the turn is allowed to close normally. The plugin supports automatic detection of check commands for common projects:
| Ecosystem | Detection / check commands |
|---|---|
| Node.js | package scripts (test, build, lint, typecheck) |
| Python | pytest, Ruff, Mypy |
| Go | go test ./..., go vet ./... |
| Rust | cargo test --all-targets, cargo check --all-targets |
| Any project | Custom checks |
If requireTests is enabled, projects with no detected executable test command are treated as blocked.
Workspace Fingerprint¶
Completion evidence is bound to a SHA-256 fingerprint of the current repository state. The fingerprint includes:
- the session baseline Git HEAD;
- commits created during the session;
- staged changes;
- unstaged changes;
- untracked files.
This means a clean tree does not prove that the agent made no changes (the code may already have been committed). If the code changes after checks or attestation, the fingerprint changes and the previous evidence becomes invalid.
New Code Alerts¶
The plugin scans newly added lines of code for TODO, FIXME, HACK, and XXX, as well as specific security regression patterns (such as hardcoded credentials, disabled TLS verification, chmod 777, and similar issues). This serves as a regression alert, not a replacement for SAST tools.
Completion Attestation¶
Machine checks cannot prove all requirements. Before final completion, the agent can invoke the completion_gate tool to provide an attestation bound to the current workspace fingerprint.
Example:
{
"action": "attest",
"reviewed_files": [
"src/engine.ts",
"tests/engine.test.ts"
],
"review_summary": "Reviewed the complete diff, error paths, state transitions and backwards compatibility.",
"acceptance_criteria": [
{
"criterion": "Risk sizing uses ATR",
"evidence": "Unit tests cover ATR-derived risk sizing and the full test suite passes."
},
{
"criterion": "Existing behavior remains compatible",
"evidence": "Regression tests and typecheck pass; changed call sites were reviewed."
}
],
"unresolved_issues": []
}
Control Center Configuration¶
Navigate to Settings → Completion Gate in the DeepSeek Harness interface. The Control Center serves both as a runtime dashboard and a persistent configuration editor.
Behavior Settings¶
- Enable Completion Gate: the master switch.
- Mode:
Strict: when the gate fails, blocks normal completion and guides the agent to remediate.Advisory: collects evidence, but failures do not force additional steps.
- Gate subagents: defaults to
false. Only the root agent has final production-readiness authority. Subagents are allowed to complete their delegated tasks normally. - Premature-stop guard: recovers from natural stops.
- Max recovery follow-ups: safety limit for a single premature-stop recovery chain.
Machine Evidence Settings¶
- Auto-detect checks: automatically detect project checks.
- Require tests/build/lint/typecheck: require them to be executed when available.
- Block new TODO/FIXME markers: block the addition of such markers.
- Security regression scan: scan for security patterns.
Execution Limits¶
- Check timeout: maximum execution time for a single command.
- Stored command output: maximum amount of sanitized failed output retained for each check.
Custom Checks¶
Any custom checks can be added in the UI. Configuration example:
Name: integration-tests
Category: test
Command: npm run test:integration
Required: yes
Typical Usage¶
When using autonomous orchestration or Phoenix model failover, it is recommended to keep gateSubagents as false. If a project requires strict subagent governance, it can be explicitly enabled in the Control Center.
The plugin runs with the permissions of the current DSH process. The source code and license should be reviewed before installation.
Summary¶
dsh-completion-gate provides evidence-based production-readiness checks. Through premature-stop protection and gating mechanisms, it effectively prevents agents from ending tasks in an incomplete or unverified state.
Plugin directory: https://www.skillhub.cn/plugins/AGSQ11/dsh-completion-gate
Source repository: https://github.com/AGSQ11/dsh-completion-gate