DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Odai Dsh Agent — DeepSeek Harness 插件(DSH Plugin)
← Plugins

odai-dsh-agent

Odai Dsh Agent

独立维护的 odai 治理模式 preset,按任务需要提供治理与协作,可作为默认总控。

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add odai-dsh-agent@0.2.33
README兼容性版本

兼容性与来源证明

Odai Dsh Agent 以 odai-dsh-agent 发布,当前版本为 0.2.33。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
web
发布来源
npm
Registry 更新时间
2026/9/20

版本

0.2.33stable
2026/9/20
0.2.32stable
2026/9/18
0.2.31stable
2026/9/14
查看其余 14 个版本
收起版本
0.2.30stable
2026/9/11
0.2.29stable
2026/9/11
0.2.28stable
2026/9/10
0.2.27stable
2026/9/9
0.2.26stable
2026/9/7
0.2.25stable
2026/9/5
0.2.23stable
2026/9/4
0.2.22stable
2026/9/4
0.2.21stable
2026/9/4
0.2.20stable
2026/9/3
0.2.19stable
2026/9/2
0.2.18stable
2026/9/1
0.2.17stable
2026/9/1
0.2.16stable
2026/9/1

相关插件

正在加载相关插件…

最新版
0.2.33
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
1.7 MB
文件数
232
Surface
web
许可证
MIT
发布源
npm
GitHub
★ 115
周下载
531
安全扫描
✓ v0.2.33 扫描通过
最近提交
2026/9/18
查看源码 ↗项目主页 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录

README

odai dsh agent

odai-dsh-agent installs a selectable, session-scoped Odai Agent preset for DeepSeek Harness (dsh). It is independent from the profile-wide odai-dsh-plugin: the preset install does not activate global governance. In an interactive terminal, the command separately offers to add the same package's Control Center to the Web profile and performs that profile change only after confirmation.

The installed preset is self-contained:

$DSH_HOME/.agent-presets/odai/
  agent.cordis.yml
  preset.yml
  odai-governance.mjs
  runtime/*.mjs
  skills/odai/**
  .odai-agent.json

Odai owns its source composition and existing capability set, with a scoped runtime in default auto mode. The current source installer targets exactly dsh@0.1.5-rc.2, using the native persona prefix/suffix interface and publishing the LF-normalized managed preset. Standard is an upstream reference, not a required composition: release checks load Odai against the real SDK and verify scoped tool/prompt behavior rather than requiring text equality with Standard.

Host-owned persistence, sandbox, approval, registries, and base controller selection remain in the selected DSH profile. Ordinary requests stay on that controller. Responsibility words are optional signals rather than commands: evidence-grounded task-state gaps route at any step, the gap tool records rather than claims a route start, terminal decisions consume the proposal, an incomplete reviewer proposal waits for changed native evidence, and an identical planner/controller model remains inline without another model call. After planner handback, the controller resumes implementation only when the current user task authorizes it; plan-only, new-task, expanded-scope, and unknown authorization remain non-implementing. Reviewer children require a current hash-addressed schema 3 evidence packet whose diff is newer than the last write and whose latest successful test or read-only check follows the last write; viewing a diff does not itself invalidate an earlier successful check. The packet binds to the authenticated direct-user task when available, excludes all prior-task session events, records its boundary in route evidence, and fails closed if an explicit task binding cannot be resolved uniquely. An incomplete packet keeps the current controller route, reports why native evidence was excluded, suppresses unchanged repeat notices, and reassesses the pending proposal after decisive evidence changes without claiming independent acceptance or terminating the authorized task. Every route is resolved before provider I/O; deterministic invalid persisted mappings are backed up and exact-match removed, while recoverable provider failures preserve them. Frontend route failure becomes an explicit local controller fallback without a routed receipt. execute remains an explicit comparison mode and observe changes no model or child while retaining fail-closed high-impact protection. Configured compaction streams are buffered so partial failed output cannot contaminate the inherited-route retry or replace original history.

DSH 0.1.5-rc.1 provides native bidirectional send_message between adjacent continuable parent/child Agents. Odai retains the controller's native collaboration tools; its read-only children expose only their allowed tools and return bounded results through the responsibility mechanism. DSH owns durable child identity, cold resume, admission, and explicit invalid/unavailable-target failures; Odai does not replace an invalid id or treat delivery as responsibility acceptance.

The preset includes the same local long-term semantic memory runtime as the Plugin. Default auto mode performs no hidden model call: it automatically captures only high-confidence durable statements from the direct-human message authenticated by the latest open-turn session event, keeps ambiguous or conflicting candidates inert, and recalls only bounded active global/project records as untrusted historical context. Matching direct intent, or the compact capability gateway on a later step, exposes the controller-only odai_memory tool for inspection, search, confirmation, correction, physical forgetting, exact-phrase clearing, and auto/off mode changes. Recognized secrets, contact identifiers, health/crisis content, temporary instructions, hypotheses, quotes, and code are rejected; the current user and project authority always override memory. State lives at $DSH_HOME/odai/memory/store.json, outside .agent-presets, so install, update, and uninstall preserve it. An invalid or symlinked store fails closed. The matcher is not a replacement for protecting the underlying DSH session history from sensitive input.

Non-crisis care and crisis safety are separate. references/care.md owns fatigue, anxiety, self-doubt, rumination, shame, fear of mistakes, negativity, reduced agency, and user-controlled 阿岱/欧黛 styles without diagnosis, scoring, persistence, or model routing. references/human-safety.md owns sustained or worsening low mood, hopelessness, burden, self-harm, suicide, and immediate danger; any credible current inclination triggers timely care and a direct safety check even without a plan, while plan, means, and action determine urgency.

Human-safety continuity is an independent explicit-consent store at $DSH_HOME/odai/human-safety-continuity.json, not a hidden health profile and not semantic memory. odai_human_safety_continuity accepts only the authenticated current direct user's request to save, inspect, export, correct, remove, or physically clear user-authored care preferences, signals they want noticed, support they say helps, and safety-plan steps. Added or replacement text must occur exactly in that message; credentials and contact details are rejected, and entries persist until the user removes or physically clears them. New controller sessions receive the minimal historical record only when the current conversation independently makes care, crisis support, or record management relevant, never as proof of current risk, diagnosis, or a score; children cannot inspect it or receive its prompt data.

Ordinary requests retain the complete canonical governance plus compact responsibility and capability-discovery tools. Low-frequency control and care schemas are exposed per agent only for matching direct intent; uncommon wording can request the specialized capability on the next step, and unsupported hosts fall back to the complete tool catalog instead of dropping behavior.

Install

With DSH already installed, run the single Agent package command below. The package already contains the canonical skill and shared runtime; it does not require the Plugin or a separate skill installation:

npx odai-dsh-agent install

The installer checks dsh -V; the current 0.2.33 candidate accepts only 0.1.5-rc.2, while published 0.2.32 retains its exact rc.1 contract. It records the detected version in the managed manifest and publishes Odai's own composition. In an interactive terminal it classifies the Control Center profile as absent, current, registry-upgrade, local-link, partial-drift, newer, or unknown-source. Every add, upgrade, replacement, or repair is shown at [Y/n]; Enter, y, or yes confirms, while EOF, n, no, and other text leave the profile unchanged. Non-interactive and --json installs never infer consent: automation can use --with-control-center or --without-control-center explicitly, with --profile <name> selecting a profile other than web.

DSH_HOME is honored. An explicit location can be supplied without changing the environment:

npx odai-dsh-agent install --dsh-home /path/to/dsh-home

Open a new DSH session and select Odai from the Agent preset picker. Existing sessions retain the preset they were composed with.

The installer copies through a mode-tightened staging directory and atomically publishes the preset. Lifecycle operations reject symlinked managed parents or source roots, serialize per preset with an owner-token operation lock, and revalidate the exact manifest revision after atomically moving an update or uninstall target to a unique quarantine path. Unverified quarantine content is retained and reported, never recursively deleted. Updates verify every previously managed file first, refuse to overwrite local edits, and always change the composition generation key so new sessions in a running DSH process do not reuse stale runtime code. Normal install, update, and uninstall do not scan, merge, rewrite, or block on historical session logs. DSH 0.1.5-rc.1 refuses historical v0 logs containing unknown Odai events even when marked ignorable. The old flag-only repair entry is retired and performs no writes; installing the current preset does not claim those old sessions have been migrated.

DSH classifies this as a trust: user preset. User presets have the same privileges as shell access, so install only reviewed package versions; the installer repeats this trust notice in both plain and JSON output.

Control Center

The optional profile entry ships inside odai-dsh-agent; it is not a third package. It adds one Chinese Control Center launcher to DSH Web with a real current-turn responsibility graph, session evidence timeline, structured event inspector, and routing controls for the four optional responsibilities. The controller remains host-managed and read-only. Routing writes use the same validated, locked, atomic routing action as the conversation tool and apply on the next user turn. Configured models alone are never displayed as execution evidence. A separate native-collaboration summary shows observed controller subagent/subagent_fork tool receipts from the loaded session evidence, including errors and unknown turn attribution. These receipts are not named-role model verification or child completion evidence; the summary shows the latest five calls and leaves the rest in the timeline.

The main install prompt is the recommended entry. These lifecycle commands remain available for inspection, recovery, and automation:

npx odai-dsh-agent control-center install [--profile web]
npx odai-dsh-agent control-center status [--profile web]
npx odai-dsh-agent control-center uninstall [--profile web]

A Control Center profile change requires one normal DSH Web process restart. Removing it does not remove the Agent preset, routing configuration, or session evidence. Status is current only when the dependency is the installer package's exact registry version, the resolved package reports that same version, the bundle entry occurs exactly once, and the shipped bundle patch plus host/runtime/client artifacts exist. Standalone Control Center install checks the supported DSH version before running the package manager; status and removal remain available for recovery. A stale file: or link: dependency is reported with its concrete source and can be replaced only after explicit consent. Profile operations serialize through an owner-token lock. If a DSH package-manager command fails without changing profile bytes, the installer reports the unchanged state; if bytes changed, it does not run a destructive inverse command or overwrite a possible concurrent successor. It preserves the current state and retains before/after recovery evidence under $DSH_HOME/odai/control-center-backups/ for explicit repair.

Responsibility models

The Agent ships no researcher, planner, reviewer, or frontend model mapping. It stays quiet when an unconfigured responsibility is not needed. If a real task gap needs one, Odai says which responsibility is missing, confirms that no route ran, and asks for the provider, model, and optional reasoning effort in natural language. For example:

证据调查用 provider-r/model-research,推理档 high。
规划用 provider-x/model-plan,推理档 high。
验收改用 provider-z/model-review,推理档 max。
前端制作用 provider-f/model-frontend,输出上限 4096。
规划职责改成 child,前端职责保持 same-turn。
研究和验收职责改成 same-turn。

The controller calls odai_routing_config to persist that explicit choice. Researcher, planner, reviewer, and frontend each accept an explicit same-turn or child dispatch override; the controller owns integration, validation, and final delivery. Children remain read-only; explicitly delegated patch preparation returns unapplied proposals, while research, planning, and review keep their narrower contracts. The tool uses separate set-dispatch/reset-dispatch actions, so changing a dispatch override does not remove its model mapping. Researcher activation is task-gated but not price-aware: its mapping enables the narrow trigger and does not guarantee lower cost. The tool repeats that warning whenever a researcher mapping is shown; Odai must use authoritative provider prices and measured usage instead of inventing either. The user does not edit Agent files, YAML, or JSON and does not add trigger terms to later tasks. Mappings live in $DSH_HOME/odai/routing.json, outside the managed preset, so installer updates do not report them as drift. A legacy Executor mapping is ignored without invalidating current responsibilities and is removed on the next configuration write. Audit evidence likewise lives under $DSH_HOME/odai/session-evidence/ instead of using private DSH session-event types, so changing or removing the preset cannot make a session unreadable. Changes apply from the next user turn. Whenever routing or explicit mapping management needs it, runtime resolves a fresh merged effective-mapping snapshot, with persisted mappings preferred over deployment mappings; the full snapshot enters the model prompt only for mapping-management intent and remains authoritative over stale compaction text. The tool also exposes the latest current-session actual route receipt; configured targets alone never prove that a responsibility ran. If reasoning effort is omitted, the target provider/model uses its own default rather than inheriting the source controller's setting. Plugin and Agent read the same stores when both are deliberately present.

Researcher and frontend are optional evidence/production upgrades whose missing mappings keep the original route without claiming success. A researcher child is limited to a bounded multi-source repository question; technical facts available through controller tools are investigated directly instead of manufacturing a role call. Planner and reviewer are independent optional responsibilities; if a needed one has no mapping, high-impact work fails closed and remains read-only, while lower-impact work continues only where it does not depend on the missing responsibility. Same-turn routes and child outputs require actual request-header evidence. Same-turn researcher, planner, and reviewer are read-only and must return through odai_responsibility_return to the controller, which resumes any authorized implementation. Missing handback restores and continues the controller instead of treating the read-only text as final delivery. Deterministic invalid persisted mappings are backed up and exact-match removed; credentials, quota, rate-limit, server, timeout, and transport failures preserve configuration and fall back only for the current call. Matching responsibilities use odai_responsibility_gap to honor configured models, dispatch, and evidence gates. A generic subagent is not a responsibility route. Exceptional manual planner/frontend children use the native tool's description prefix odai-planner: or odai-frontend: and require a matching actual-route receipt; researcher/reviewer require managed evidence validation. Local child routing receipts reach the parent's Control Center under the corresponding role, without claiming task completion. Odai never chooses a model or price on the user's behalf.

Controller output policy

The Agent defaults to soft concise output and shares three controller output modes with the Plugin. A user can naturally ask to inspect or change the mode; odai_output_config persists an explicit override in $DSH_HOME/odai/output.json:

ModePolicyBehavior
normalconcise: false, no maxTokensuse the host's normal presentation and controller budget
soft concise (default)concise: true, no maxTokensshorten only the final user-facing presentation without relaxing required results, evidence, risks, blockers, or verification
economy (optional)concise: true, positive maxTokensadd a provider output-ceiling request; default to 500 when the user names economy without another value, or use the user's supplied positive value

Natural requests include use normal output, use soft concise output, enable economy mode, and set economy mode to 1200 tokens. Removing the persisted override restores soft concise. Existing pre-mode stores that combined concise: false with a ceiling remain readable for compatibility, but new named-mode changes cannot create that legacy combination. The selected mode is stable within one turn and changes from the next user turn.

An economy ceiling only tightens an existing lower host request value and is not a locally enforceable hard billing boundary. A provider may count hidden reasoning inside it, exceed or ignore it, or end before useful final text, especially at a high reasoning effort; strict compliance must be checked from per-request usage. Odai enables economy only when requested and never invents a non-default custom value. The mode does not alter child-agent role budgets, compaction, checkpoints, or other internal context; an incomplete token-capped compaction fails closed instead of replacing history.

An authenticated 这个会话放开上限 directive removes only Odai's controller ceiling before the current request and for the rest of that session, without changing the shared output store or exposing the persistent configuration tool; 这个会话恢复输出上限 restores shared-policy inheritance. After a verified ordinary-controller max-tokens stop, the immediately following pure 继续 receives one ceiling-free recovery turn. Existing lower host limits, responsibility overrides, other sessions, and revised or new tasks remain unchanged.

A same-provider/model compaction inherits controller reasoning while keeping its independent summary budget. Odai leaves prompt-cache retention unset by default; ODAI_COMPACTION_CACHE_RETENTION can explicitly select short, long, or none. provider-default means Odai adds no retention, while any explicit incoming retention remains authoritative; configured retention still applies when host routing has already supplied reasoning. Custom preset compositions can set the same value through runtime compaction.cacheRetention. The first controller request after a landed summary still rebuilds the changed summary prefix.

Compaction model

The default compaction-summary model is inherit, which preserves the conversation's current provider/model behavior. A user can explicitly set a separate target and optional reasoning effort in natural language, such as 压缩模型用 provider-x/model-summary,推理档 high; odai_compaction_config persists those explicit values in $DSH_HOME/odai/compaction.json. Removing the target restores inheritance. Agent and Plugin share the store when both are deliberately present.

The target applies only to future compaction summary requests. It does not change the controller, researcher, planner, reviewer, frontend, ordinary conversation, summary output budget, or cache-retention policy. An explicitly configured reasoningEffort overrides reasoning only for those summaries. When omitted, existing behavior remains: same-route summaries can inherit controller reasoning, while a cross-model target removes only reasoning proven by equality with the durable controller route and preserves a distinct preselected effort. Configured, inherited, and fallback requests receive one provider-neutral integrity suffix preserving the full objective, unfinished requirements, unknown action outcomes, current facts, and exact continuation-critical values; duplicate Agent/Plugin runtime instances add it only once. Odai never chooses the provider, model, or reasoning effort on the user's behalf. An invalid store is reported by the tool while runtime requests inherit safely until set or remove repairs it. The configured stream is buffered until a valid terminal result. Partial failed chunks are discarded before one retry with the untouched inherited request; deterministic invalid persisted targets are backed up and exact-match removed, transient failures preserve them, and DSH retains original history until a complete summary lands.

Skill sources

The Agent keeps the managed preset's complete skill copy as its bundled default, so existing installations do not change behavior. When the user explicitly asks to show, set, or reset the Odai skill source, the controller uses odai_skill_source_config and stores the choice in $DSH_HOME/odai/source.json, outside the managed preset:

  • bundled: use the skill shipped with this Agent release.
  • auto: allow a compatible current-project .dsh/skills/odai or .agents/skills/odai bundle, then DSH custom roots and newer user installs under $DSH_HOME/skills/odai or $DSH_AGENTS_HOME/skills/odai (default ~/.agents/skills/odai), with bundled fallback.
  • user: ignore project roots and require a compatible custom or user-level bundle. An unusable source produces an explicit bundled fallback diagnostic so it can be repaired through the same tool.

An independent install must be a complete directory bundle containing SKILL.md, manifest.json, and every manifest-declared file. The runtime checks SemVer 2.0.0 skillVersion, an exact supported runtimeContract, complete-file SHA-256 integrity, and same-version content conflicts. Prompt governance and routing role contracts are selected atomically for one agent turn; project sources are scoped by that session's cwd, and changes are reconsidered on the next user turn. Explicit deployment skillPath or ODAI_SKILL_PATH remains highest priority and requires a DSH restart.

This candidate reads manifest schema 3 / runtime contract 7. SKILL.md remains the complete entry and sole source of the shared core; declared presets combine that core, the delegation boundary, the specialist contract, and required references. The copied preset carries its own static package-import boundary and uses its packaged trusted compiler, never code from a selected external bundle. Older schema/contract candidates are skipped or fall back with a diagnostic without rewriting their files; an incompatible explicit skillPath fails fast. Custom bundles need the new module and preset topology, and obsolete active evolution is not automatically migrated.

Controlled skill evolution

Explicit user governance refinements live in $DSH_HOME/odai/skill-evolution, outside .agent-presets/odai. Agent install, update, repair, and uninstall therefore leave them intact; the Plugin reads the same default store when both surfaces are deliberately installed. This overlay is independent of the selected bundled/auto/user source. A custom governance.evolutionRoot is a deployment override and must match across Agent and Plugin to remain shared.

odai_skill_evolution can propose exact replacements only in existing governance Markdown: SKILL.md, assets/task-state.md, assets/routing-roles/*.md, and references/*.md. Manifest changes, executable/runtime files, undeclared paths, symlinks, stale hashes, and untracked edits are rejected. Candidates store immutable base/result snapshots and content-addressed provenance. The first propose call writes nothing and returns PROPOSE ODAI EVOLUTION <proposal-digest>, bound to the complete proposed input. Retrying that exact proposal writes a candidate only when the current open turn's latest direct-human message contains exactly one text block equal to the phrase, byte for byte.

propose and rebase never activate. Validation returns a phrase bound to the exact generation. Any SKILL.md or references/dao.md change, including additive preamble or core-section text, is breaking; so is any replacement that does not preserve its old text. These require ACTIVATE BREAKING ODAI EVOLUTION <generation-id> instead of the standard activation phrase. Model text and arguments, synthetic messages, multi-block or whitespace-altered text, stale confirmations, and other action or generation phrases cannot authorize writes. Audit evidence is derived from the authenticated session event, not supplied by the model. The tool stays discoverable without an unconditional evolution system-prompt section.

An active generation survives package updates. When its base differs from the newly bundled upstream, Odai keeps the active result visible with rebaseRequired; clean rebases produce another inactive candidate, while conflicts preserve base/ours/theirs evidence and do not change the pointer. Rebase is generation-bound. Rollback and deactivation phrases also bind the current active generation, preventing stale pointer authorization. rollback is limited to a previously active validated generation. Child agents cannot use this tool. Stop DSH before updating the Agent and restart it so the process loads the new bundled bytes. Explicit skillPath/ODAI_SKILL_PATH bypasses evolution, and ODAI_DISABLE_EVOLUTION=1 provides an emergency startup bypass without deleting state.

Status and uninstall

npx odai-dsh-agent status
npx odai-dsh-agent status --json
npx odai-dsh-agent uninstall

status reports absent, installed, or drifted. Update and uninstall fail closed when managed files were changed or unmanaged files were added. Normal preset removal does not inspect or rewrite historical sessions and does not accept --yes; the legacy Plugin repair command is retired and cannot migrate those logs. Uninstall also refuses while agent-presets.default still names odai; select another default first so the next session cannot fail on a missing preset. Stop DSH before install, update, or uninstall so preset files are not being loaded concurrently.

Plugin versus Agent

Choose either package or install both when their scopes are useful:

  • odai-dsh-plugin: profile-wide governance for every preset in that profile.
  • odai-dsh-agent: selectable Odai governance for sessions using this preset.
  • both: supported even when users arrive at the combination independently; Plugin provides the single Control Center surface while the Agent preset remains selectable.

When both are present, a process-shared per-agent/per-turn skill snapshot keeps prompt governance and role contracts identical, the compatibility-safe evidence store deduplicates tool and route records, host RPC registration is reference-counted, and denials remain monotonic. Removing either package leaves the other package and shared routing/evidence stores usable. Neither package installs or changes the provider-neutral odai-cli.

Development

Shared runtime, canonical governance, and Control Center client sources live in dsh/runtime/src/, skills/odai/, and dsh/client/src/; Agent installer sources live in dsh/agent/src/. npm pack generates the preset's runtime/ and skills/ directories plus the package's client/ directory, then removes those generated copies:

npm --prefix dsh/agent test
npm --prefix dsh/agent run verify:dsh
npm --prefix dsh/agent run pack:dry-run

The DSH verification uses a temporary home and one isolated Web process. It creates standard and Odai sessions, proves the canonical prompt appears only for Odai, dispatches odai_routing_config through the live Odai session and checks its persisted mapping, and proves the child write guard does not leak into the standard preset.

相关插件

继续浏览 agents-orchestration 分类下经过校验的插件。

Headless@deepseek-ai/dsh-headlessdsh one-shot bundle:基于 dsh-base 的直接核心 Agent/Session 运行器,不包含 Host、HTTP 或浏览器层Experimental Agent Team Web Profile@deepseek-ai/dsh-experimental-agent-team-web-profile用于 Agent Teams Remote 和 UI 插件的实验性 Web 配置层Subagent Codex@deepseek-ai/dsh-subagent-codex基于官方 app-server 协议的一次性 Codex 子代理提供程序Subagent Claude Code@deepseek-ai/dsh-subagent-claude-code基于官方 Agent SDK 的一次性 Claude Code 子代理提供方