kovey/dsh-engineering-suite--packages-dsh-spec-gate ↗★ 0
dsh-spec-gate
Specification gate for DeepSeek Harness: turn a task into an approved, structured specification (acceptance criteria, file boundaries, negative constraints, test design) before any write tool may run. 适合要求Agent在修改代码前必须先明确需求和边界的严谨开发场景。
같은 패키지 이름의 다른 저장소
설치
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:kovey/dsh-engineering-suite#4a618ac4376c4a075c99c92b69895163bb21b0ce&path:packages/dsh-spec-gate项目级配置(同一个 dsh 进程服务多个仓库)
profile 是上限,每个仓库可以用 .dsh/spec-gate.json 决定自己被管多严:
{ "enforce": false } // 临时/试验仓库:不拦写,其余工具照旧可用
{ "enforceBoundaries": false, "shellPolicy": "strict" } // 边界放宽,但 shell 不可归属就拒绝
{ "writeTools": ["write", "edit", "multi_edit"] } // 这个仓库的写类工具集
- 可覆盖键:
enforce、enforceBoundaries、writeTools、shellTools、shellPolicy、boundaryExemptPaths、requireTestDesign、approval。 - 不可覆盖:
enabled、logFile、rootDir/specsDir/missionsDir(宿主决策),写了会被忽略并记日志。 - 文件本身在信任根里(
.dsh/**只允许派生的specs/*.md被写类工具改写),所以模型不能用write把自己的门禁关掉。 spec_status会显示配置来源:项目级 …/profile与enforce / 边界 / 审批模式。
配置
| 键 | 默认 | 说明 |
|---|---|---|
enabled | true | |
logFile | ~/.dsh/spec-gate.log | 只写文件,绝不写 stdout |
enforce | true | 是否拦截写类工具 |
enforceBoundaries | true | 是否把写操作目标限制在规格的 fileBoundaries 内(支持 src/**、*.json、docs 这类写法) |
boundaryExemptPaths | [] | 额外的放行模式(在规格边界之前判定) |
shellTools | ['bash','pwsh'] | 会被分析写入目标的 shell 工具 |
shellPolicy | 'targets' | targets=能识别就查、查不到放行(记录盲区);strict=不可归属即拒绝;off=不分析 shell |
writeTools | ['write','edit'] | 被视为“写”的工具名 |
exemptTools | [] | 永不检查的工具 |
requireTestDesign | 'auto' | auto = 只有挂了 dsh-test-design-gate 才要求测试设计已通过 |
approval | 'seam' | seam 走人工审批;auto 记录即通过(CI 用) |
rootDir / specsDir / missionsDir | .dsh … | 工件布局 |
prompt.enabled / prompt.order | true / 620 | 系统提示段 |