Introduction¶
In DeepSeek Harness (DSH) debugging and testing workflows, model-generated tool call parameters sometimes contain invalid JSON (for example, unescaped inner quotes). Such issues may be handled loosely in the streaming path, but when replaying conversation history against strict servers such as vLLM, they trigger 400 errors and can “break” the entire session. This article introduces the dsh-tool-call-guard plugin, which neutralizes these invalid tool calls before transmission to prevent session corruption.
Plugin Overview¶
dsh-tool-call-guard is an admin-security plugin for DSH, maintained by alchemistwu. It intercepts DSH’s llm/stream waterfall and neutralizes tool calls whose arguments fail JSON.parse validation, ensuring session continuity.
- Plugin name: dsh-tool-call-guard
- Maintainer: alchemistwu
- Category: admin-security
- License: MIT
Core Features¶
- Interception and neutralization: Intercepts DSH’s
llm/streamwaterfall and neutralizes tool calls with invalid JSON arguments. - Plain-text logging: Records neutralized tool calls as plain text, preserving the original content so the model can reissue a corrected call in context.
- Protocol balancing: Rewrites matching tool results as plain user messages, avoiding orphaned
tool_callsorrole:"tool"entries and preventing subsequent request failures caused by protocol imbalance. - Zero overhead: For clean histories, adds only a single
JSON.parseoperation, leaving the message array objects unchanged. - Append-only respect: Respects DSH’s append-only logging mechanism; it does not rewrite persisted session logs and only neutralizes at the transport layer.
- Provider-agnostic: Based on the
llm/streaminterface, covering all adapters (DeepSeek, community adapters, etc.). - Fail-open: If the Guard itself encounters an error, the original request passes through, without disrupting normal flow.
- Zero configuration: Ready to use after installation.
Installation and Activation¶
Add the plugin using the official installation command:
dsh plugin add dsh-tool-call-guard
After installation, you must restart the DSH host (dsh web or DSH Desktop) for the plugin to take effect.
Typical Scenario¶
When the model issues an invalid JSON argument similar to the following format:
{"queries": [""The Idiots" trailer youtube official"]}
The plugin performs the following actions:
1. Intercepts the tool call block.
2. Converts it into a plain-text log entry, informing the model that its arguments are invalid.
3. Converts the corresponding tool result into a user message to keep the conversation protocol balanced.
This allows the session to continue, preventing 400 errors caused by invalid arguments from blocking subsequent requests.
Notes¶
- Restart required: After installation, the DSH host must be restarted for the plugin to take effect.
- Fail-open behavior: The plugin is designed to fail open; if an error occurs in the Guard’s internal logic, the original request passes through unchanged, without blocking requests.
- License: The code is licensed under the MIT License.
Summary¶
dsh-tool-call-guard gives DSH the ability to repair invalid tool call arguments at the transport layer. It is especially suitable for scenarios that require interacting with strict OpenAI-compatible servers (such as vLLM). With zero configuration and fail-open behavior, it increases session robustness without changing the existing log structure.