Preface

DeepSeek Harness (DSH) adopts a plugin-based architecture and has a vast ecosystem (more than 13,000 related repositories). dsh-kit provides 8 plugins aimed at addressing “silent failures” that occur when agents operate without inspection. Four of the features fill gaps in the existing plugin ecosystem, while the other four provide better implementations than existing alternatives.

Installation and Runtime Environment

The plugins are pure ESM JavaScript with no build step, so no prepare script or allowBuilds permission is required. The only runtime dependency is @deepseek-ai/schemastery.

The installation commands are as follows:

dsh plugin --profile web add github:FoyonaCZY/dsh-kit
dsh --profile web

To lock the version for supply-chain security, specify a commit hash:

dsh plugin --profile web add github:FoyonaCZY/dsh-kit#<sha>

Node engine requirement: >= 22.

Plugin List

This package contains the following 8 standalone plugins:

  • autoformat: Runs the project formatter on files written by the agent.
  • artifact-guard: Prevents the agent from manually editing lockfiles, build outputs, and generated code.
  • env-drift: Reports environment variables added by the agent but not documented.
  • verify: Runs project checks before completion is reported (such as typecheck).
  • checkpoint: Rolls back the workspace.
  • secret-guard: Removes credentials from tool output.
  • git-context: Provides branch, worktree, and commit information in prompts.
  • notify: Desktop notifications.

Core Feature Details

autoformat

Runs project formatters on files. To avoid interference, formatters only run when the project is already configured. The plugin detects configuration files such as .prettierrc, node_modules/.bin/prettier, and supports tools such as Prettier, gofmt, rustfmt, ruff, black, etc. If a formatter rejects a file, that error is appended to the tool result.

artifact-guard

Prevents the agent from manually editing machine-generated files (such as pnpm-lock.yaml, files under dist/, and generated protobuf bindings). It identifies files through two signals:
1. Path rules: Identifies lockfiles, build outputs, and vendored trees.
2. Content markers: Identifies markers such as @generated, DO NOT EDIT, etc. (only checks the first 20 lines of the file). When an edit is rejected, the system prompts the agent to modify the configuration file instead of editing it directly.

env-drift

Captures environment variables added by the agent but never documented in a template. After a successful file write, the plugin reads template files (defaults: .env.example, .env.sample, .env.template), extracts the variables accessed, and reports missing items to the agent. The system automatically filters runtime variables such as NODE_ENV, CI, PATH, etc.

verify

Runs project checks before a turn ends to ensure the code is actually usable when the agent reports “completion”. It automatically detects the typecheck command by default (preferentially looking for scripts in package.json, otherwise running tsc --noEmit). If the check fails, the turn does not end and the agent continues working. This feature has a maxRounds limit to prevent infinite loops.

Configuration Examples

Disabling a Plugin

Set disabled: true in cordis.patch.yml.

- id: dsh-kit-notify
  disabled: true

autoformat Configuration

Specifies file extensions to format, commands, and detection rules.

- id: dsh-kit-autoformat
  config:
    formatters:
      - extensions: ['.ts', '.tsx']
        command: npx --no-install prettier --write {file}
        detect: ['.prettierrc', 'node_modules/.bin/prettier']
      - extensions: ['.sql']
        command: sqlfluff fix --force {file}
        detect: []
    timeoutMs: 15000
    reportFailures: true

artifact-guard Configuration

Sets rejection behavior and detection markers.

- id: dsh-kit-artifact-guard
  config:
    onArtifact: ask
    detectMarkers: true
    allowPaths: []

env-drift Configuration

Specifies template file paths and ignored variables.

- id: dsh-kit-env-drift
  config:
    templates: ['.env.example', '.env.sample', '.env.template']
    ignore: ['NODE_ENV', 'CI', 'PATH']

verify Configuration

Customizes check commands.

- id: dsh-kit-verify
  config:
    checks:
      - name: typecheck
        command: pnpm typecheck
      - name: unit tests
        command: pnpm test -- --run
    autoDetect: ...

Notes

  • No build step, pure ESM JavaScript.
  • The only runtime dependency is @deepseek-ai/schemastery.
  • Formatters only run when the project is configured.
  • Environment variables are only reported when the project has templates.
  • Node engine requirement: >= 22.