AI Agent Hub
Back to plugins
🖥️

dsh-supreme

Client Updated 2026.09.12

Run the following command in DeepSeek Harness:

dsh plugin install stadeummwt/dsh-supreme

Paste the following prompt into your AI chat to install this plugin:

Run dsh plugin install stadeummwt/dsh-supreme to add the plugin to your DeepSeek Harness profile; full source at https://github.com/stadeummwt/dsh-supreme

About this plugin

The DSH plugin catalog is full of single-domain tools: a router here, a memory store there, a verifier over there you wire together and trust. dsh-supreme flips that. It bundles seven governance services—cost admission, observability, benchmark evidence, deterministic routing, verification, memory policy, and workflow scoping—into one install, and every hard rule is deterministic code (counting, glob, comparison), never model judgment. UNKNOWN cost means DENY. Unicode-tainted arguments are rejected at the door. Secret sentinels produce zero leaks every run. A denied call cannot be retried in the same shape. Every claim in the README is tied to a command you can re-run; if it cannot be re-run, it is labeled a claim, not a fact.

Routing walks eight hard gates, then weighted scoring, with an RM0 cost-class rule first and an unscored-evidence downweight to stop sandbagging. A thousand decisions cost 0.02 to 0.04 ms and there is no ML dependency anywhere. Observability writes append-only JSONL over official DSH event seams, allowlists fields, scrubs secrets, and fails open so one bad record never drags the pipeline down. Workflow policy pins subagents and the workflow engine inside glob-scoped boundaries where blocked beats allowed, requires a verifier pass to close HIGH-risk tasks, and locks inter-agent channels to a declared directed contact graph—anything off that graph is audited and, when set to DENY, blocked before the fact.

Teams running DSH in production who want an auditable governance floor without stitching six single-domain plugins together and hoping they agree. You get safe production defaults out of the box, composition fragments (core, standard, supreme, lab) to trim scope as needed, zero upstream patches with a pinned commit and a clean worktree verified on every run. No monkey-patching, no vibes-based config checks, no "trust the output"—just deterministic enforcement you can re-run and audit offline.

Use Cases

  • Production DSH deployments that need one auditable governance floor instead of six stitched single-domain plugins
  • Multi-agent collaboration where path scoping, contact-graph locking, and overreach auditing are mandatory
  • Compliance environments that demand UNKNOWN-cost DENY, zero Unicode-taint tolerance, and re-runnable proof for every policy rule

Best For

  • Teams running DeepSeek Harness in production and needing auditable, re-runnable policy enforcement
  • DSH engineers who refuse to trust six single-domain plugins to cooperate by vibes
  • Platform developers who want deterministic code—counting, glob, comparison—in place of model judgment for cost, routing, and safety gates