PerryLink/jevcore--packages-dsh ↗★ 72
jevcore-dsh
TypeSafe Jev as a first-class Cordis service and three model-visible tools for DeepSeek Harness — offline by default, egress disclosed, never default-on. 适合需要离线、确定性合成或通过API调用TypeSafe决策服务的用户。
Install
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:PerryLink/jevcore#9b50597fb5a42de6f825752f21c3209875c221eb&path:packages/dshREADME
Read the full README ↗Configuration
| Key | Default | Meaning |
|---|---|---|
provider | mock | mock (offline, deterministic, synthetic), live (TypeSafe), or openrouter |
apiKeyRef | TYPESAFE_API_KEY | Credential reference for the live route |
openRouterApiKeyRef | OPENROUTER_API_KEY | Credential reference for the openrouter route |
baseURL | https://api.typesafe.ai | API root for the live route. Non-HTTPS is refused except on loopback |
openRouterBaseURL | https://openrouter.ai/api | API root for the openrouter route. Same rule |
model | jev-latest | Sent with every request. On the OpenRouter route the bare default works; typesafe/ needs a versioned id such as typesafe/jev-1.13, and typesafe/jev-latest is not accepted |
logLevel | warn | silent | warn | info | debug |
minConfidence | 0.7 | Below this, an answer is not acted on |
minProbability | 0.6 | Below this, a decision is not acted on |
maxStateChars | per feature | Replaces the state cap for every feature. 0 means "keep the declared cap" |
gates.safety | false | Judge tool calls before dispatch |
gates.context | false | Withhold large, uninformative tool results |
The declared state caps are 16,000 characters for the three tools and 8,000 / 6,000 for the safety
and context gates. maxStateChars replaces all of them, and the startup report shows the effective
value rather than the declared one, so what it prints is what is enforced.
Gates accept a bare boolean (safety: false) or an object with onUndecided: ask (default),
allow, or deny.
An unknown value is rejected at load with a message naming the key, rather than being silently ignored — a config typo should not quietly change the privacy posture.
Enabling the safety gate where nothing can answer
The gate answers allow, deny, or ask, and ask is its answer both for a raised hazard and for
an undecided verdict. An ask needs an approval channel: a deployment that composes no approval
service cannot escalate to a human, and the harness resolves the ask to a refusal instead of running
the call. The gate matches by tool-name fragment, and its list includes pwsh, bash, git,
write and edit, so an operator who enables it there watches ordinary shell commands and file
edits fail. Enable it where a channel can put the question to a human, and read
docs/approval.md for what provides that channel.