Skip to content
dsh.fish
Bundle

dsh-verify-gate

Engineering verify gate for DeepSeek Harness: configured commands are authority; dirty receipts block conclude.

Source
blueWhalei
License
MIT
Updated
Updated 20 days ago

Readme

# dsh-verify-gate

English | [中文](README.zh.md)

An open-source DeepSeek Harness plugin that requires the agent to run the workspace’s verification commands before it can conclude that work is done.

Pass/fail is decided only by process exit codes. A successful run writes an auditable receipt. After that, any successful mutating tool (for example edit, write, or bash) invalidates the receipt, so verification must pass again before conclude.

## Install

Local path:

```sh
dsh plugin --profile web add /absolute/path/to/verify-gate
```

Or from GitHub (the repo includes the built `lib/` entry points):

```sh
dsh plugin --profile web add github:blueWhalei/dsh-verify-gate
```

Restart Web, open the target workspace, then:

1. Run `/verify run`, or have the model call `verify_run`
2. Call `verify_conclude` only after every command exits 0

## How commands are chosen

Resolution order:

1. Non-empty `config.commands` always wins
2. Otherwise auto-detect (on by default) requires **exactly one** common workspace marker:
   - `package.json` with `scripts.test` → pick the package manager from the lockfile / `packageManager`, then run `<pm> test`
   - `go.mod` → `go test ./...`
   - `Cargo.toml` → `cargo test`
3. If nothing matches, or more than one ecosystem matches → fail with an error that asks you to set `commands`, instead of guessing

For Python, Java, and other stacks with many local conventions, set `commands` explicitly.

## Custom config

Change config only when the default is wrong. Put this in the profile’s `cordis.patch.yml` (it replaces that plugin’s entire `config`):

```yaml
- id: dsh-verify-gate
  name: dsh-verify-gate
  config:
    commands:
      - id: test
        run: pytest -q
    autoDetect: true
    sandboxMode: danger-full-access
```

`sandboxMode` defaults to `danger-full-access` so package managers can use a global store. If you tighten the sandbox, confirm the verify commands still run for real.

## Everyday entry points

| Goal | Entry |
|---|---|
| Run verification | `verify_run` or `/verify run` |
| Inspect gate status | `verify_status` or `/verify` |
| Conclude | `verify_conclude` (needs a green, non-dirty, non-expired receipt) |

Receipts are stored under `<workspace>/.dsh/verify-receipts/`. Most application repos should ignore that directory.

## License

MIT

Install

dsh plugin --profile web add github:blueWhalei/dsh-verify-gate

Profile: web

  • This package builds from source on install. pnpm will ask you to allow its build script — that is permission to run the package’s code on your machine, outside the agent sandbox. Only allow sources you trust.
  • This source has no pinned commit, so a later push upstream changes what installs. Prefer pinning a commit.
Source