PerryLink/jevcore--packages-dsh ↗★ 72

jevcore-dsh

TypeSafe Jev as a first-class Cordis service and three model-visible tools for DeepSeek Harness — offline by default, egress disclosed, never default-on. 适合需要离线、确定性合成或通过API调用TypeSafe决策服务的用户。

パッケージ
jevcore-dsh
互換性
未検証
Harness ピア範囲
>=0.1.2-rc.1 <0.2.0 || >=0.1.5-alpha.1 <0.2.0 || >=0.1.6-0 <0.2.0
Cordis ピア範囲
^4.0.2
バージョン
0.4.1
ライセンス
Apache-2.0
最終更新
2026/09/24

インストール

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:PerryLink/jevcore#9b50597fb5a42de6f825752f21c3209875c221eb&path:packages/dsh

ドキュメント

README 全文を読む ↗

Configuration

KeyDefaultMeaning
providermockmock (offline, deterministic, synthetic), live (TypeSafe), or openrouter
apiKeyRefTYPESAFE_API_KEYCredential reference for the live route
openRouterApiKeyRefOPENROUTER_API_KEYCredential reference for the openrouter route
baseURLhttps://api.typesafe.aiAPI root for the live route. Non-HTTPS is refused except on loopback
openRouterBaseURLhttps://openrouter.ai/apiAPI root for the openrouter route. Same rule
modeljev-latestSent with every request. On the OpenRouter route the bare default works; typesafe/ needs a versioned id such as typesafe/jev-1.13, and typesafe/jev-latest is not accepted
logLevelwarnsilent | warn | info | debug
minConfidence0.7Below this, an answer is not acted on
minProbability0.6Below this, a decision is not acted on
maxStateCharsper featureReplaces the state cap for every feature. 0 means "keep the declared cap"
gates.safetyfalseJudge tool calls before dispatch
gates.contextfalseWithhold large, uninformative tool results

The declared state caps are 16,000 characters for the three tools and 8,000 / 6,000 for the safety and context gates. maxStateChars replaces all of them, and the startup report shows the effective value rather than the declared one, so what it prints is what is enforced.

Gates accept a bare boolean (safety: false) or an object with onUndecided: ask (default), allow, or deny.

An unknown value is rejected at load with a message naming the key, rather than being silently ignored — a config typo should not quietly change the privacy posture.

Enabling the safety gate where nothing can answer

The gate answers allow, deny, or ask, and ask is its answer both for a raised hazard and for an undecided verdict. An ask needs an approval channel: a deployment that composes no approval service cannot escalate to a human, and the harness resolves the ask to a refusal instead of running the call. The gate matches by tool-name fragment, and its list includes pwsh, bash, git, write and edit, so an operator who enables it there watches ordinary shell commands and file edits fail. Enable it where a channel can put the question to a human, and read docs/approval.md for what provides that channel.