deepseek-harness
deepseek-ai
DeepSeek Harness: Everything is a Plugin.
PROJECT TOPICS
PROJECT README
Export a minimal, secret-scrubbed, replayable problem bundle for the DeepSeek Harness.
/repro reads the current session's complete canonical log through
sessionPersistence.inspect, scrubs secrets value by value, collects failed
commands and a git diff, and writes a repro-<sessionId>.json manifest.
dsh plugin --profile <name> add github:EvilIrving/dsh-repro
Or, from a checkout:
dsh plugin --profile <name> add ./dsh-repro
The bundle patch inserts one plugin row (dsh-repro); it needs the
commands and sessionPersistence services, which the base profile already
mounts.
interface ReproManifest {
formatVersion: number // 1
header: SessionHeader // cwd, lineage, delegation depth
events: SessionEvent[] // complete, secret-scrubbed canonical log
failedCommands: string[] // `name <arguments>` for each errored tool call
gitDiff: string // empty when git or a repo is unavailable
versions: Record<string, string>
}
The events array is the full canonical log (contiguous from seq 0), so it can
later be replayed via ctx.sessions.create(id, { seed }); secrets are redacted,
not dropped, which preserves replay balance.
redactValue walks the detached JSON log and:
/KEY|PASSWORD|SECRET|TOKEN/i) whole;sk-, ghp_,
xoxb-, Bearer, …);Both prefix and entropy thresholds are Config-driven. The default is
fail-closed: a string that looks credential-shaped is redacted rather than
passed through. This mirrors session-telemetry's waterfall shape (rewrite an
outbound copy, never the canonical log) while supplying the value-level rules
the telemetry seam deliberately ships without.
export interface Config {
tokenPrefixes: string[]
minHighEntropyLength: number // default 20
gitDiffMaxBytes: number // default 256 KiB
gitGraceMs: number // default 5000
}
commands and sessionPersistence are hard dependencies (inject).subprocess is optional (ctx.get): git diff degrades to an empty string
when it is absent or the cwd is not a repository.A single slash command /repro [output directory]. Its result is a one-line
success message naming the written bundle path; the bundle contents are never
injected into the model context.
Zero-direct effect; the command result is a single short text line.
Append-only: the command lifecycle events (command/run, command/done) append
to the log and never rewrite earlier tokens.
ctx.fs seam — v1 uses
node:fs/promises directly; routing the write through ctx.fs (so a
sandboxed deployment constrains the output path) is deferred.dsh repro run <bundle> is a separate
process-level seam (boot/cmdline + cmdlineArgs), not /repro; v1 only
exports.CLASSIFICATION EVIDENCE
系统优先读取 GitHub Topics,再与站内分类词典和词根规则比对。当前命中: 无有效分类标签。