DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Tool Result Guard — DeepSeek Harness 插件(DSH Plugin)
← Plugins

dsh-tool-result-guard

Tool Result Guard

DeepSeek Harness (DSH) 的零损失工具结果裁剪:超大的工具结果会先溢写到文件,然后使用被省略区段的精确偏移量和恢复定位器进行裁剪。一个 dsh-plugin。

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add dsh-tool-result-guard@0.1.0
README兼容性版本

兼容性与来源证明

Tool Result Guard 以 dsh-tool-result-guard 发布,当前版本为 0.1.0。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
any
发布来源
npm
Registry 更新时间
2026/8/22

版本

0.1.0stable
2026/8/22

相关插件

正在加载相关插件…

最新版
0.1.0
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
未提供
文件数
未提供
Surface
any
许可证
MIT
发布源
npm
GitHub
★ 0
周下载
0
最近提交
2026/8/22
查看源码 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录

相关插件

继续浏览 developer-tools 分类下经过校验的插件。

Web App@deepseek-ai/dsh-web-appdsh 浏览器界面捆绑包:位于 dsh-base 之上的 Web 补丁层,加上运行时粘合插件(提供前端 dist、Web 界面提示符、bash 运行时变量和 URL 行)Sdk Minimal@deepseek-ai/dsh-sdk-minimal独立的最小 SDK 配置包:JSON-RPC、一个 DeepSeek 适配器、持久化 Shell 和 JSONL 会话Sdk App@deepseek-ai/dsh-sdk-appdsh SDK 配置包:基于 dsh-base 提供 stdio JSON-RPC 服务和进程生命周期管理Subagent Codex@deepseek-ai/dsh-subagent-codex基于官方 app-server 协议的一次性 Codex 子代理提供程序

README

dsh-tool-result-guard

English | 中文

Zero-loss tool-result pruning for the DeepSeek Harness (DSH). A dsh-plugin.

Oversized plain-text tool results are spilled to a file first, then replaced with a bounded head/tail preview whose position-0 marker carries the exact elided span and the spill locator. The model can always recover the middle; nothing is ever dropped without a durable copy.

[pruned: kept chars [0, 4096) + [28976, 30000) of 30000; the elided middle
[4096, 28976) is NOT lost — full output saved at: /tmp/dsh-spill/.../bash.txt.
Recover any elided span with the read tool (offset/limit), grep, or sed on that file.]

<head: first 4096 chars>

[... middle elided ...]

<tail: last 1024 chars>

Why

DSH ships two built-in mechanisms:

mechanismtriggerbehavior
dsh-spill-policyresult > maxInlineBytes (default 50000 bytes) at post-executefull text to ctx.spillStore, bounded preview + locator returned — zero-loss
dsh-compaction-tool-result-prunertext > 8192 chars, only when compaction pressure qualifieshead 4096 + [... tool result middle pruned ...] + tail 1024. The original event stays in the append-only session log for replay, but the model gets no locator, no offsets, and no tool to read the log — the middle is unrecoverable for the model

The gap: results between ~8K chars and 50K bytes that survive until compaction are pruned with no model-facing recovery path. This plugin closes the gap by pruning earlier (at tools/post-execute), always spilling the full text first, and embedding the exact elided span [head, total-tail) plus the locator in the marker.

If you install this plugin, the built-in pruner finds nothing over 8K chars on the surface and becomes a no-op; you may keep or remove its row. Same for spill-policy (its cap is never reached). Keeping both is harmless.

Install

One command:

dsh plugin --profile web add dsh-tool-result-guard

Restart DSH. Done — it now applies to every agent preset in that profile. Remove with dsh plugin --profile web remove dsh-tool-result-guard.

Tune the budgets by id in your profile's ~/.dsh/profiles/web/cordis.patch.yml:

- id: tool-result-guard
  config:
    thresholdChars: 16384
Alternative: preset-level install without pnpm (single agent preset instead of the whole profile)
npx dsh-tool-result-guard install --preset my-preset --from standard

copies the shipped standard preset to ~/.dsh/.agent-presets/my-preset/, drops dsh-tool-result-guard.js beside its agent.cordis.yml, and appends the plugin row; start a new session on my-preset. Patch an existing user preset with --preset <id> (no --from), undo with remove --preset <id>, print the snippet with --print. Manual equivalent — copy index.js next to the preset's agent.cordis.yml and append:

- id: tool-result-guard
  name: './dsh-tool-result-guard.js'

Config

Unknown keys fail at load. All budgets are Unicode code points (surrogate pairs never split).

KeyDefaultMeaning
thresholdChars8192Prune when the flattened plain-text result exceeds this many code points.
headChars4096Leading code points kept inline.
tailChars1024Trailing code points kept inline.
excludeTools["read"]Tools whose results always pass through. read is excluded by default to prevent a read spill file → prune → read again loop. Add e.g. ["read", "subagent", "memory_search"].
spillDir(unset)Override the local fallback spill directory (default: a private dir under the OS temp dir).

headChars + tailChars must be below thresholdChars so the marker always fits.

Behavior contract

  • Fail-open. No session owner, no reachable spill backend, a write failure, or a replacement that wouldn't be smaller/in-budget → the original inline result is kept, unchanged. A prune never hides output and never turns a successful call into an error.
  • Spill first, prune second. The full text is durable (via the deployment's ctx.spillStore when loaded, else a private per-process local directory) before the middle leaves the model-facing result.
  • Pass-through. Non-accept decisions, value replacements, nested composite sub-calls, excluded tools, results containing non-text blocks (images are never touched), and at/under-threshold results are returned byte-identical.
  • Composable. Runs as a prepended tools/post-execute waterfall listener and delegates via next(), so tool-owned projection and other hooks run first; their replaced content is what gets pruned. additionalContexts survive.
  • Idempotent. A replacement is always within thresholdChars, so a second pass never re-prunes.

How the model recovers the middle

The marker names the spill file and the exact char span. Models recover with read (offset/limit), grep -n, or sed -n 'X,Yp' on that file — the read exclusion prevents recovery reads from being pruned themselves.

Development

npm test          # node:test, zero dependencies

License

MIT