sandbase-harness
sandbaseai
Local-first, self-hosted AI agent runtime and MCP bridge with sandboxed sessions, memory, credentials, audit/replay, and a local Console.
PROJECT TOPICS
INSTALL REFERENCE
dsh plugin --profile web add github:chenzhiyong1994/dsh-cost-guard
该命令指向仓库当前默认分支;尚无绑定当前 commit 的完整验证结果。
PROJECT README
Know what every DSH task costs while it runs. dsh-cost-guard is a local-only dynamic Cordis plugin for DeepSeek Harness that turns recorded token usage into a compact live cost HUD, per-model totals, and editable pricing.
It observes execution; it never blocks, reroutes, or changes the agent.
Visit the project website → — explore the HUD and pricing screenshots, switch between English and Chinese, and copy the installation prompt. Hosted on GitHub Pages, with automatic deployment from main. See website maintenance and publishing.
[!IMPORTANT] Token counts come from DSH usage events. Currency amounts are local estimates calculated from your configured rates, not authoritative billing data. Provider prices can change—always treat the provider invoice as the source of truth.
The composer dock shows the current or most recent task, model, input/output/cache tokens, model-call count, task estimate, and session total without opening another panel.

Edit model rates, add custom models, apply the official peak/off-peak schedule, inspect per-model totals, and export or import the configuration from Settings → Cost Guard.

The screenshots were captured from an earlier configured instance. Release
v4.3.0ships with the official DeepSeek V4 peak/off-peak schedule enabled by default and uses the current rates described below.
inputTokens, outputTokens, cacheReadTokens, and cacheWriteTokens from DSH session events.Paste this into a DSH conversation:
Install the dynamic Cordis plugin dsh-cost-guard from
https://github.com/chenzhiyong1994/dsh-cost-guard
Read docs/install.md in that repository and follow the online installation.
Before running it, use cordis_inspect_self and confirm both hasHostHalf and
hasClientHalf are true. Then activate it and report the installed plugin ID.
The agent fetches host.js and client.js, defines both halves, verifies the package, and activates it. No build step is required.
For the full online/offline prompt and update procedure, see Installation.
0.1.0-rc.6; internal APIs may change between DSH releases.The v4.3.0 defaults match the official DeepSeek V4 peak/off-peak pricing that took effect on 2026-08-17 (verified against the DeepSeek API pricing page and the official announcement). Rates are CNY per 1M tokens, off-peak (valley) prices:
| Model | Input · cache miss | Output | Input · cache hit |
|---|---|---|---|
deepseek-v4-flash |
¥1.5 | ¥4.5 | ¥0.05 |
deepseek-v4-pro |
¥4.5 | ¥13.5 | ¥0.15 |
default fallback |
¥1.5 | ¥4.5 | ¥0.05 |
Peak hours are 9:00–12:00 and 14:00–18:00 Beijing time, billed at ×2 the off-peak price. Peak/off-peak pricing is on by default; toggle it and edit the windows from the settings page.
Cache-write tokens use the cache-miss input rate because the official table has no separate cache-write item. Legacy names are mapped for convenience: deepseek-chat → Flash and deepseek-reasoner → Pro.
flowchart LR
A["agent/request<br/>capture model"] --> B["session/event<br/>record usage"]
B --> C["Configured rates<br/>calculate estimate"]
C --> D["Turn and model totals"]
E["Startup replay<br/>persisted events"] --> D
D --> F["Private Host RPC"]
F --> G["Composer HUD<br/>Settings panel"]
agent/request and session/event, attributes usage to turns, rolls up subagents, and exposes private RPC handlers.conversation.composer.dock and the configuration UI in settings.section.Open Settings → Cost Guard to manage:
| Section | Controls |
|---|---|
| Model pricing | Cache-miss input, output, and cache-hit input rates; custom models; restore defaults |
| Peak/off-peak pricing | Official windows (9:00–12:00, 14:00–18:00 Beijing) at ×2; enabled by default |
| Session totals | Settled tasks, estimated spend, exchange rate, and per-model totals |
| Backup | Export or import the configuration as JSON |
The USD amount in the HUD is an approximate conversion using the editable CNY/USD rate. All UI text follows the DSH language setting (中文 / English).
Dynamic packages are replaced as a whole. Always submit both files when updating:
host.js and client.js.cordis_define with kind: "existing" and the installed plugin ID, providing both code.host and code.client.cordis_inspect_self; continue only when both halves are present.cordis_run in update mode.See SECURITY.md for reporting guidance.
| Path | Purpose |
|---|---|
host.js |
Dynamic Cordis Host half |
client.js |
Dynamic Cordis Web client half |
docs/install.md |
Copy-paste online and offline installation prompts |
docs/index.html |
Bilingual project homepage on GitHub Pages |
docs/website.md |
Website preview, maintenance, and deployment |
scripts/check.js |
Syntax and release-invariant checks |
CHANGELOG.md |
Release history |
npm run check
host.js and client.js are function-body fragments consumed by cordis_define, so the check compiles them with the JavaScript Function constructor instead of executing them as standalone Node.js programs.
Contributions are welcome—please read CONTRIBUTING.md. If the plugin saves you from token-bill surprises, consider starring the repository so other DSH users can find it.
This plugin depends on internal DSH services and UI slots (sessions, session/event, agent/request, conversation.composer.dock, settings.section, and private Host RPC). They are not guaranteed stable APIs. Include your DSH version when reporting compatibility problems.
CLASSIFICATION EVIDENCE
系统优先读取 GitHub Topics,再与站内分类词典和词根规则比对。当前命中: cost-tracking、token-monitoring。