Foreword¶
During operation, DeepSeek Harness (DSH) agents generate a large number of external write operations. Local code checkpoints (such as Git worktrees) can restore code, but they cannot retract comments, emails, deployments, or payments that have already been sent. The DeepSeek Harness paper mentions two solutions: one is delayed output until commit, and the other is defining domain-specific compensation strategies. This plugin implements a stronger general-purpose approach—delayed output until commit—without relying on external systems to provide atomic transaction capabilities.
What is this¶
dsh-action-outbox is a persistent batch review outbox plugin designed for DeepSeek Harness, maintained by JimChen-g. It allows DSH agents to locally stage specific tool calls before executing tool side effects, perform full inspection, editing, and review, and finally commit them in one batch.
The plugin’s core value is: zero target dispatch during staging, and side effects are only truly executed after explicit approval and commit.
Core features¶
The plugin provides the following capabilities:
- Web sidebar outbox: Provides a visual batch review interface, displaying full parameter JSON, tool source, fingerprint, hash, and byte count, with support for copy and download.
- Editing and replacing: Provides the
action_outbox_replacetool, allowing the name, arguments, or summary of staged tools to be modified before review. Any modification invalidates the previous summary and hash. - Fault-tolerant handling:
- Fail-closed long-form review: Truncated review cards cannot authorize commit on their own; the full outbox must be opened for confirmation first.
- Crash-safe recovery: A process crash during commit changes the state to
recovery_required; operations that did not receive a persistent success receipt are marked asambiguousand will not be retried automatically.
- Persistence and restart: Staged batches are persisted as state files with 0600 permissions. After restart, drafts automatically become
needs_reapproval, requiring re-checking of the current policy and tools. - Demo guidance: Built-in “Copy safe demo prompt” provides a safe local file-write demo path.
Install and enable¶
Install using the prebuilt tarball (no build rights required at install time):
curl -LO https://github.com/JimchengChina/dsh-action-outbox/releases/download/v0.3.0/dsh-action-outbox-0.3.0.tgz
npx @deepseek-ai/dsh plugin --profile web add ./dsh-action-outbox-0.3.0.tgz
Or install from the Git tag:
dsh plugin --profile web add github:JimchengChina/dsh-action-outbox#v0.3.0
The plugin is self-activated by cordis.patch.yml; the browser side only contributes to the official sidebar.footer.action and shell.overlay slots.
Typical usage¶
The agent workflow generally includes the following steps:
- Call
action_outbox_begin({ label })to start a new batch. - Call
action_outbox_stage({ tool, arguments, summary? })to stage one or more tool calls. - Optionally call
action_outbox_unstage({ action_id })oraction_outbox_replace({ action_id, ... })to adjust them. - Call
action_outbox_review()to review. - Check the full batch in the Web interface’s “Batch Review Outbox”. If the review preview is truncated, first view and confirm it in full in the outbox.
- After editing in the outbox, click “Run fresh review”. After the review passes, the button changes to “Next: copy exact commit prompt”. Copy the prompt and paste it into the conversation. Outbox review alone does not directly write to chat history.
- Call
action_outbox_commit({ expected_digest: digest, approval_nonce })to commit, or callaction_outbox_discard()to discard.
Important note: Do not let the agent only use the “latest review result”. The latest review visible to the model may be an old result from the conversation history. You must paste the exact commit prompt generated by the outbox, or ask the agent to first call action_outbox_review and immediately call action_outbox_commit.
Configuration and security semantics¶
Configuration example¶
The plugin supports controlling behavior through a config file:
- id: action-outbox
name: dsh-action-outbox
config:
include: ['github_*', 'slack_*', 'deploy_*']
exclude: ['github_get_*', 'github_list_*']
enforce: ['github_create_*', 'github_update_*', 'slack_send', 'deploy_*']
requireApproval: true
rejectDuplicateActions: true
persistPending: true
stateFile: ''
maxPendingMs: 1800000
maxActions: 20
maxArgumentBytes: 65536
resultPreviewChars: 2000
approvalPreviewChars: 4000
include/exclude: Control which tools can be staged or excluded.enforce: Enforce outbox routing and reject direct calls.persistPending: Enabled by default; persists uncommitted drafts and recovery receipts.stateFile: Specifies the state file path; defaults to$DSH_HOME/action-outbox/state.json.
Security semantics¶
- Zero target dispatch: Staging and editing only update local bounded state and do not call target tools.
- Full visibility: The outbox retains the full canonical JSON. Compact cards report truncation and cannot be used as the sole approval interface.
- TOCTOU protection: Checks digest, one-time nonce, live policy, tool identity, and fingerprint at critical boundaries.
- Revocability: Staging, unstaging, and replacing clear all previous reviews, confirmations, and nonces.
- Re-authorization on restart: After restart, pending drafts are restored only to
needs_reapprovaland get a new nonce.
Applicable scenarios and notes¶
This plugin is suitable for developers who need human intervention and review of DSH agent external side effects in a Web environment.
Before use, ensure you understand the plugin’s “Fail-closed” mechanism. Before commit, the discard operation guarantees that no staged target has been executed. All changes produce different authorization states, even if the caller retains the old digest or nonce.
The plugin is licensed under MIT.
Conclusion¶
dsh-action-outbox provides DeepSeek Harness with a rigorous “review first, commit once” workflow mechanism. Through persistent outbox and complete crash recovery mechanisms, it solves the pain point of irreversible external writes by agents.