141w/dsh-quorum ↗★ 0

dsh-quorum

Mechanism-enforced discipline layer for DeepSeek Harness agent teams: role cards, quorum termination, evidence-gated reports and cost budgets. 适合需要对多Agent协作进行机制化约束、成本控制和纪律管理的复杂任务。

Package
dsh-quorum
Compatibility
Unverified
Version
0.2.0
License
MIT
Last updated
Oct 4, 2026

Install

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:141w/dsh-quorum

Configuration

Everything lives in the bundle's cordis.patch.yml, so a user can override it from their own profile patch without touching this package. Note that patch layers replace the whole config of a row, they do not deep-merge — override it by restating every key you need.

A malformed row is refused at activation with a quorum:-prefixed message naming the key at fault. That is deliberate: agent/created dispatches in serial mode, so a TypeError inside the listener lands on the session-creation path, and the opposite failure (budget: {}, which makes every threshold comparison false) used to leave the budget silently nonexistent.

roles:
  lead:      { shape: ship, writeScopes: [], maxMembers: 4 }
  reviewer:  { shape: scout, allow: [read, read_image, grep, glob, list] }
  fixer:     { shape: ship, writeScopes: ["src/", "tests/"] }
defaultRole: { shape: scout, allow: [read, read_image, grep, glob, list] }
budget:      { maxBilledTokens: 2000000, softTier: 0.7, hardTier: 0.9 }
quorum:      { requires: all, timeoutMs: 300000, pollMs: 30000 }
debug:       { logExemption: false }
  • A role is bound to a teammate's durable Team name, not to whatever the prompt says about it.
  • writeScopes: [] means unrestricted, not forbidden. A relative scope is workspace-relative.
  • Unlisted teammates get defaultRole, which is scout: a role nobody declared is not implicitly trusted to modify the checkout.
  • A scout card may not be granted bash or pwsh — a shell can write any path, so such a card would claim a guarantee the mechanism cannot keep. It is refused at activation.
  • pollMs must stay ≥ 10000 — upstream's change-wait rejects shorter timeouts.
  • Billed tokens are input + output + cacheRead + cacheWrite — the runtime's own disjoint sum, which equals its totalTokens. Measured on 449 real calls; the cache terms are 96.9% of the total, so a budget set without them is off by orders of magnitude, not by a rounding error. See docs/M1-usage-accounting.md.
  • The budget bounds the tool surface, not the bill. It is checked when a tool executes, which is the only point this plugin can refuse anything. Reasoning between two tool calls still bills, so a team that has crossed a tier keeps spending while it wraps up — measured at 3.8x the nominal budget (228,639 against 60,000). Set maxBilledTokens against the work you want done, not as a hard spending ceiling.