Introduction¶
DeepSeek Harness (DSH) provides a rich plugin ecosystem that allows agents to invoke various tools. However, the decision to invoke tools remains in the hands of the agent, and agents often skip checks when they are confident, hurried, or trapped in loops. This failure of “self-management” occurs precisely when oversight is needed most.
The Strict Gate plugin aims to convert this optional behavior into an enforced Harness policy. It does not rely on the agent’s self-discipline. Instead, it uses policy-driven intervention, blocking, and inspection to ensure that code changes on critical paths conform to the required specifications.
Plugin Positioning¶
- Name:
catsenior507/dsh-policy-strict-gate - Maintainer: catsenior507
- Category: admin-security
- License: MIT
- Core Value: Transform
strict_checkand failure logs from “tools” available to the agent into enforced “policies” of the Harness.
Core Features¶
This plugin includes three independently operating check gates that can be configured individually or disabled:
-
Repeated Failure Intervention
During a session, once the same failure signature reaches the threshold (default: 3 times), a notification is triggered, including the failure category, remediation suggestions, and operational directives. It is then resent after each specified cooldown interval (default: 3 times) to prevent long loops from overwhelming the context. -
Critical Path Protection Gate
Writes to paths protected by glob rules are intercepted until the corresponding Lean specification for the path is accepted. Rejections carry diagnostic information, and a “repair write” may bypass the interception (successful repair writes are counted). -
Automatic Post-Write Syntax Checking
After each accepted write, an immediate language syntax check is performed (such aspy_compile,node --check, etc.). Diagnostics are passed into the next context step, capturing issues at the moment an erroneous edit occurs.
Installation and Activation¶
Installing this plugin requires Node.js 20 or later. The plugin itself has no build steps and no external dependencies.
- Install the Plugin
dsh plugin --profile web add github:catsenior507/dsh-policy-strict-gate
- Install the Dependency Tool
Critical path and syntax checks depend on thestrict-checktool:
dsh plugin --profile web add github:catsenior507/dsh-tool-strict-check
- Restart and Verify
After installation, restart the DSH host program and check the status:
strict_gate_status action=status
Configuration¶
The critical path gate is disabled by default because the glob list reflects the code structure of a specific project, which the plugin cannot automatically infer.
Add the plugin configuration to the host’s cordis.patch.yml configuration file. The following uses the web profile as an example:
- insert:
- id: policy-strict-gate
name: '@dsh-external/dsh-policy-strict-gate'
config:
criticalPaths:
- 'src/core/**'
- 'src/**/*.spec.lean'
protectedTools: ['write', 'edit']
repeatThreshold: 3
repeatCooldown: 3
postWriteSyntax: true
maxDiagnostics: 5
Diagnostics and Inspection¶
The strict_gate_status command can be used to view gate status, compiled glob rules, and counter information.
- View Overall Status
strict_gate_status action=status
- Check Protection Status for a Specific Path
Confirm whether a path is protected and which rule protects it:
strict_gate_status action=targets path=<a file>
The counters include the following metrics: number of observed failures, number of repeated notifications sent, number of critical path rejections, number of passed repair writes, and number of specification checks performed by the gate.
Notes¶
- Prerequisite Dependency:
dsh-tool-strict-checkmust be installed to enable critical path and syntax checking features. - Optional Loading:
strict-checkis optional at load time. If it is missing, the plugin disables these two checks while retaining repeated failure intervention. - No Build: The published JavaScript source code is the runnable code and does not require a
preparescript. - Zero Dependencies: Both
dependenciesandpeerDependenciesare empty.
Summary¶
Strict Gate is a mandatory code quality assurance policy. By intercepting repeated failures, protecting critical paths, and performing immediate syntax checks, it brings risk control in code generation under unified Harness management, making it suitable for project workflows that require strict standards.
- Catalog Page: https://www.skillhub.cn/plugins/catsenior507/dsh-policy-strict-gate
- Source Code: https://github.com/catsenior507/dsh-policy-strict-gate