jackchen13755/dsh-jev-lens ↗★ 0
@dsh-external/dsh-jev-lens
Jev quality bench for DeepSeek Harness: shadow-accounted dangerous-command judging, injection screening for fetched content, canary A/B drills, and an optional gate mode — with the ledger, the report and the settings card needed to judge whether any of it is worth keeping. 适合对安全要求极高,需要拦截危险命令和敏感信息外泄的沙箱环境。
설치
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:jackchen13755/dsh-jev-lens配置
| 项 | 默认 | 说明 |
|---|---|---|
mode | shadow | off 什么都不做 / shadow 只判定记账 / warn 额外把提醒注入下一轮 / gate 危险命令升级或拦截 |
model | jev-1.13.0 | 钉死版本,不用 jev-latest:测量队列不能自己漂 |
redact | true | 外发前替换家目录、邮箱、token、JWT、私有网段后缀(.internal/.corp/.lan/.local) |
redactExtra | [] | 你自己的正则(字符串数组),追加在默认脱敏之后。公司内网域名这类东西只应写在你的本地配置里,不该进公开默认值 |
judgeCommands / judgeTools | true / [bash] | 对哪些工具调用做破坏性判定(pwsh/run_code 可加) |
batchedQuestions | true | 同一次请求里追加第二问「可恢复性」(并行,几乎不加延迟),只用于放宽 revise,绝不放松 block |
screenTools | fetch_page web_fetch web_search | 哪些工具的返回内容要过筛查 |
lowThreshold / highThreshold | 0.5 / 0.7 | guard 的分档阈值(中文问句标定) |
warnThreshold | 0.75 | 达到才附警告 |
backgroundTimeoutMs / screenTimeoutMs / gateTimeoutMs | 8000 / 1200 / 4000 | 三条硬上限 |
sessionCallLimit / dailyCallLimit | 300 / 2000 | 花钱上限 |
gate 模式的判定映射:allow → 放行;revise → ask(升级给人确认);block → deny(拦截并把原因交回模型)。可恢复的命令(第二问 <0.5)只会被放宽一档,永不静默执行。
问句逐字取自 shipped 插件(dsh-jev-guard 的中文原句、dsh-jev-tools 的英文原句)——换了措辞,数字就不能和真插件对比。每条账本记录都带问题指纹,不同指纹的 p 不允许混着算。这条写在 src/questions.ts 里。