DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Tool Call Guard — DeepSeek Harness 插件(DSH Plugin)
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录
← Plugins
T

dsh-tool-call-guard

Tool Call Guard

在传输层中和处理带有无效 JSON 参数的工具调用,避免一次格式错误的模型生成导致与严格的 OpenAI 兼容服务器(如 vLLM)的会话崩溃。

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add github:alchemistwu/dsh-tool-call-guard#bbe53ad2558ec3c2bf6385079b517fd7ff0ba16e
README兼容性版本

兼容性与来源证明

Tool Call Guard 以 dsh-tool-call-guard 发布,当前版本为 0.1.1。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
any
发布来源
github
Registry 更新时间
2026/8/30

版本

0.1.1stable
2026/8/30

相关插件

正在加载相关插件…

最新版
0.1.1
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
未提供
文件数
未提供
Surface
any
许可证
MIT
发布源
github
GitHub
★ 0
周下载
0
最近提交
2026/8/31
查看源码 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题

README

dsh-tool-call-guard

English | 中文

Neutralize tool calls with invalid JSON arguments before they reach the wire — so one malformed model generation cannot brick an entire session.

dsh plugin add dsh-tool-call-guard

Why

Some models occasionally emit a tool call whose arguments string is not valid JSON — most often unescaped inner quotes:

{"queries": [""The Idiots" trailer youtube official"]}

Strict OpenAI-compatible servers (vLLM and friends) are asymmetric about this:

  • Streaming generation path — lenient. The malformed call streams through, the harness persists it into the append-only session log, and the turn appears to succeed.
  • History-replay path — strict. The next request replays the poisoned tool call, the server validates it, and rejects the entire request:
400 {"message": "Assistant tool call function.arguments must be valid JSON.",
     "type": "BadRequestError"}

From that moment, every subsequent request in the session fails. The session is bricked until its log is surgically repaired by hand. The same failure class exists across ecosystems (openai-agents-python #2061, vLLM #41122).

What it does

Intercepts the harness's llm/stream waterfall. For every assistant tool-call block whose arguments fail JSON.parse:

  1. The call becomes an honest text record (wire-only) — the model sees exactly what it emitted and can re-issue a corrected call:
    [A tool call to 'web_search' was removed from history because its arguments
    were malformed JSON. Original arguments as emitted: {"queries": [""The Idiots" …]}]
    
  2. The matching tool result is re-expressed as a plain user message — result content is preserved, and the conversation stays protocol-balanced (no dangling tool_calls entry, no orphan role:"tool" reply — each of those is itself a 400 on strict servers):
    [Tool Result: web_search] 10 results about The Idiots
    

The orphaned-result-as-user-message pattern follows the upstream serializer discussion (deepseek-harness #4668).

Properties

  • Zero overhead for clean history — one JSON.parse per tool-call block; messages array passes through with object identity when nothing is wrong.
  • Append-only log respected — the harness's durable session log is never rewritten; neutralization is applied per-request on the wire only.
  • Provider-agnostic — sits on llm/stream, so every adapter (deepseek, community, custom) is covered.
  • Fail-open — if the guard itself errors, the original request passes through untouched.
  • Zero configuration — install and restart.

Install

dsh plugin --profile web add dsh-tool-call-guard
# or desktop:
dsh plugin --profile desktop add dsh-tool-call-guard

Or from GitHub: dsh plugin add github:alchemistwu/dsh-tool-call-guard.

The package declares a dsh.bundle patch, so the plugin self-registers on install. Restart your dsh web / DSH Desktop host, then start a new session.

Observed in production

First observed with zai-org/GLM-5.3-Flash served by vLLM 0.27 (--enable-auto-tool-choice): one web_search call with unescaped quotes around a film title streamed through fine, was persisted, and permanently poisoned the session with 400 … arguments must be valid JSON on every later turn. This plugin keeps that session alive: the poisoned entry is re-expressed per-request, the session continues working, and the model sees its own mistake in context.

Tests

npm test

Nine tests cover the exact production poison, mixed valid/invalid tool calls, protocol-balance invariants (no invalid tool_calls and no orphan role:"tool" on the wire), degenerate inputs, and per-request state reset.

License

MIT

相关插件

继续浏览 developer-tools 分类下经过校验的插件。

Web App@deepseek-ai/dsh-web-appdsh 浏览器界面捆绑包:位于 dsh-base 之上的 Web 补丁层,加上运行时粘合插件(提供前端 dist、Web 界面提示符、bash 运行时变量和 URL 行)Sdk Minimal@deepseek-ai/dsh-sdk-minimal独立的最小 SDK 配置包:JSON-RPC、一个 DeepSeek 适配器、持久化 Shell 和 JSONL 会话Sdk App@deepseek-ai/dsh-sdk-appdsh SDK 配置包:基于 dsh-base 提供 stdio JSON-RPC 服务和进程生命周期管理Subagent Codex@deepseek-ai/dsh-subagent-codex基于官方 app-server 协议的一次性 Codex 子代理提供程序