Introduction

DeepSeek Harness (DSH) provides a rich plugin ecosystem that allows agents to invoke various tools. However, the decision to invoke tools remains in the hands of the agent, and agents often skip checks when they are confident, hurried, or trapped in loops. This failure of “self-management” occurs precisely when oversight is needed most.

The Strict Gate plugin aims to convert this optional behavior into an enforced Harness policy. It does not rely on the agent’s self-discipline. Instead, it uses policy-driven intervention, blocking, and inspection to ensure that code changes on critical paths conform to the required specifications.

Plugin Positioning

  • Name: catsenior507/dsh-policy-strict-gate
  • Maintainer: catsenior507
  • Category: admin-security
  • License: MIT
  • Core Value: Transform strict_check and failure logs from “tools” available to the agent into enforced “policies” of the Harness.

Core Features

This plugin includes three independently operating check gates that can be configured individually or disabled:

  1. Repeated Failure Intervention
    During a session, once the same failure signature reaches the threshold (default: 3 times), a notification is triggered, including the failure category, remediation suggestions, and operational directives. It is then resent after each specified cooldown interval (default: 3 times) to prevent long loops from overwhelming the context.

  2. Critical Path Protection Gate
    Writes to paths protected by glob rules are intercepted until the corresponding Lean specification for the path is accepted. Rejections carry diagnostic information, and a “repair write” may bypass the interception (successful repair writes are counted).

  3. Automatic Post-Write Syntax Checking
    After each accepted write, an immediate language syntax check is performed (such as py_compile, node --check, etc.). Diagnostics are passed into the next context step, capturing issues at the moment an erroneous edit occurs.

Installation and Activation

Installing this plugin requires Node.js 20 or later. The plugin itself has no build steps and no external dependencies.

  1. Install the Plugin
    dsh plugin --profile web add github:catsenior507/dsh-policy-strict-gate
  1. Install the Dependency Tool
    Critical path and syntax checks depend on the strict-check tool:
    dsh plugin --profile web add github:catsenior507/dsh-tool-strict-check
  1. Restart and Verify
    After installation, restart the DSH host program and check the status:
    strict_gate_status action=status

Configuration

The critical path gate is disabled by default because the glob list reflects the code structure of a specific project, which the plugin cannot automatically infer.

Add the plugin configuration to the host’s cordis.patch.yml configuration file. The following uses the web profile as an example:

- insert:
    - id: policy-strict-gate
      name: '@dsh-external/dsh-policy-strict-gate'
      config:
        criticalPaths:
          - 'src/core/**'
          - 'src/**/*.spec.lean'
        protectedTools: ['write', 'edit']
        repeatThreshold: 3
        repeatCooldown: 3
        postWriteSyntax: true
        maxDiagnostics: 5

Diagnostics and Inspection

The strict_gate_status command can be used to view gate status, compiled glob rules, and counter information.

  1. View Overall Status
    strict_gate_status action=status
  1. Check Protection Status for a Specific Path
    Confirm whether a path is protected and which rule protects it:
    strict_gate_status action=targets path=<a file>

The counters include the following metrics: number of observed failures, number of repeated notifications sent, number of critical path rejections, number of passed repair writes, and number of specification checks performed by the gate.

Notes

  • Prerequisite Dependency: dsh-tool-strict-check must be installed to enable critical path and syntax checking features.
  • Optional Loading: strict-check is optional at load time. If it is missing, the plugin disables these two checks while retaining repeated failure intervention.
  • No Build: The published JavaScript source code is the runnable code and does not require a prepare script.
  • Zero Dependencies: Both dependencies and peerDependencies are empty.

Summary

Strict Gate is a mandatory code quality assurance policy. By intercepting repeated failures, protecting critical paths, and performing immediate syntax checks, it brings risk control in code generation under unified Harness management, making it suitable for project workflows that require strict standards.

  • Catalog Page: https://www.skillhub.cn/plugins/catsenior507/dsh-policy-strict-gate
  • Source Code: https://github.com/catsenior507/dsh-policy-strict-gate