Preface

The plugin ecosystem of DeepSeek Harness (DSH) allows developers to extend agent capabilities. During development, models frequently retry failed tool calls, especially operations that depend on external state (such as polling APIs). If the model retries a failed call with exactly the same parameters, it wastes a large amount of latency, network requests, execution resources, and provider costs.

Unlike the official @deepseek-ai/dsh-repeat-tool-reminder, which only provides suggestions without blocking, dsh-tool-failure-circuit-breaker is designed to address this pain point. It intercepts repeated failed calls at the plugin layer and directly prevents the model from sending meaningless retry requests.

Plugin Introduction

This is a security plugin for DeepSeek Harness that prevents an Agent from dispatching another request with exactly identical parameters after a tool call has failed.

  • Name: dsh-tool-failure-circuit-breaker
  • Maintainer: icyaaaww
  • Category: admin-security
  • License: MIT

Installation and Enablement

The plugin is installed via a local path. Before installation, make sure the plugin directory is located in the parent directory of the Harness project.

dsh plugin --profile web add ./dsh-tool-failure-circuit-breaker

Core Features

The plugin works through the following mechanisms:

  1. Blocking repeated failures: The plugin observes authoritative tools/result failure outcomes and, after the configured threshold is reached, rejects the next dispatch with exactly the same parameters.
  2. Pre-execution interception: It listens to the tools/pre-execute event, so rejected retry requests never reach the concrete execution logic of the tool.
  3. Result consistency: Rejections are recorded as normal tool results, ensuring consistency across the model’s history and replay mechanisms.
  4. Isolating failure chains: Failure chains are isolated by “active agent,” using the tool name plus canonical JSON parameters as the key.

Configuration

The plugin inserts a default configuration line during installation. You need to adjust the following parameters according to your business logic:

- id: tool-failure-circuit-breaker
  name: dsh-tool-failure-circuit-breaker
  config:
    maxFailures: 2        # 允许连续失败的最大次数,默认为 2
    include: []           # 需要保护的工具名通配符模式,为空则保护所有工具
    exclude: []           # 需要绕过熔断机制的工具名通配符模式
    errorPreviewChars: 300 # 在拒绝消息中展示的失败信息字符数,默认为 300
  • include: Specifies which tools should have circuit breaker protection enabled.
  • exclude: For tools that need to continue polling with unchanged parameters (for example, checking whether a specific state is ready), use exclude to skip circuit breaker detection.
  • maxFailures: Determines how many identical failures are allowed before blocking is triggered.

Behavior and Limitations

  • State management: Plugin state is stored in memory. When the process or plugin restarts, historical failure records are reset.
  • Parallel calls: If multiple parallel requests are issued simultaneously and all fail, all requests may already have been dispatched before the threshold is reached.
  • Matching precision: It only detects retries with exactly identical parameters and cannot detect retries with similar parameters.
  • Blocking method: Blocking is optional and must be enabled by installing the plugin. Choose exclude rules carefully to avoid intercepting legitimate repeated probes.

Conclusion

By cutting off meaningless retry chains at the tools/pre-execute stage, this plugin effectively reduces the runtime overhead of agents. For Agent scenarios that frequently call external APIs and involve retry logic, it is a practical defensive tool.