jackie-cqz/dsh-jev-plugin ↗★ 8
dsh-jev-plugin
DeepSeek Harness tools for TypeSafe Jev (System One) decisions. 适合需要调用TypeSafe API进行系统决策的用户。
同名パッケージの別リポジトリ
インストール
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:jackie-cqz/dsh-jev-pluginドキュメント
README 全文を読む ↗Configuration
| Field | Default | Description |
|---|---|---|
apiKey | — | TypeSafe API key; takes precedence over apiKeyEnv |
apiKeyEnv | TYPESAFE_API_KEY | Environment variable used when apiKey is unset |
baseURL | https://api.typesafe.ai/v1 | API root; trailing slashes are removed |
model | jev-latest | Default model; tools can override it per call |
timeoutMs | 10000 | Call timeout in milliseconds |
retry.maxAttempts | 3 | Maximum attempts, including the first |
retry.baseDelayMs | 500 | Initial backoff in milliseconds |
retry.maxDelayMs | 5000 | Maximum delay between attempts |
maxStateChars | 64000 | Maximum serialized state length; 0 disables the limit |
confidence.approveAt | 0.8 | Confidence threshold for automatic acceptance via verdictFor |
confidence.escalateBelow | 0.5 | Escalate below this confidence; must not exceed approveAt |
policy.enabled | false | Enable the circuit breaker and minimum call interval |
policy.failureThreshold | 5 | Consecutive failures before opening the circuit |
policy.openMs | 30000 | Time before allowing a probe call |
policy.minIntervalMs | 200 | Minimum interval between calls |
cache.enabled | false | Cache responses for identical model, state, and questions |
cache.maxEntries | 100 | Maximum cache entries; LRU eviction |
cache.ttlMs | 60000 | Cache entry lifetime |
guard.enabled | false | Enable the tools/pre-execute risk gate |
guard.tools | [] | Tools to check; empty means all tools |
guard.question | Built-in risk question | Question submitted to Jev |
guard.levels | ["low","medium","high","critical"] | Ordered risk labels; 2–10 entries |
guard.denyAt | 3 | Deny at or above this score |
guard.askAt | 1 | Request approval at or above this score |
guard.escalateOnLowConfidence | true | Request approval below confidence.escalateBelow |
guard.reviseAt | Highest level index | Reject with revision guidance; equal to denyAt by default, leaving no revision band |
guard.onError | "allow" | Gate failure behavior: fail-open (allow) or fail-closed (deny) |
rules.enabled | false | Enable synchronous offline denial rules; no API key needed |
rules.tools | [] | Tools to check; empty means all tools |
rules.deny | [] | Additional case-insensitive denial regexes; invalid patterns fail at load time |
review.enabled | false | Enable tools/post-execute review; may rewrite completed tool results |
review.blockAt / review.onError | 0.8 / "accept" | Correction probability threshold and error behavior |
routing.enabled | false | Route models on agent/request using request complexity and routing.models |
context.enabled | false | Enable context pruning on agent/pre-step |
context.maxDrops / context.shadow | 0 / false | Drop limit (0 means unlimited); shadow mode reports without changing context |
intent.enabled | false | Decision logic exists, but instruction injection is not connected; enabling this does not inject messages |
quotaCooldownMs | 900000 | Cooldown after 402, independent of policy.enabled; 0 disables it |
enableDecide / enableEvaluate | true | Register the corresponding tool |
telemetry.log | false | Emit a sanitized structured record for each call |
telemetry.sampleRate | 1 | Sampling fraction from 0 to 1 |
telemetry.errorRateAlert | 0.5 | Error rate threshold for degraded health |
telemetry.alertMinCalls | 10 | Minimum sample size before reporting health |
Validate gate thresholds for your workload: scores and confidence can vary. Changing guard.levels clamps default thresholds into range; explicitly configured out-of-range values fail validation. Start context pruning in shadow mode before allowing it to remove messages.
Oversized state is rejected, never truncated, so a decision cannot silently use incomplete input. Policy, caching, and the risk gate are disabled by default. Intent injection remains unavailable because the host lacks a pre-step message channel that records plugin authorship.
Prefer an environment variable over storing the key in cordis.patch.yml:
export TYPESAFE_API_KEY="..."
PowerShell:
$env:TYPESAFE_API_KEY = "..."
If storing a key in configuration, use the secret role and restrict file permissions. The plugin redacts API keys from tool output, error messages, and logs.