ClawsJoy/dsh-plugins--packages-tool-attribution ↗★ 0

@clawsjoy/dsh-tool-attribution

为 Shell 工具执行注入会话与工具标识变量 适合需要精确追踪 Shell 子进程归属,为可观测性或审计层提供调用链关联的开发者。

包名
@clawsjoy/dsh-tool-attribution
兼容性
待验证
Cordis 依赖范围
^4.0.0
版本
0.1.1
许可证
MIT
最近更新
2026年9月21日

安装

此插件尚未提供可验证的 bundle,或兼容性检查未通过。请先阅读仓库说明。 阅读完整 README ↗

@clawsjoy/dsh-tool-attribution

Publishes DSH_TOOL_CALL_ID and DSH_TOOL_NAME for every shell tool execution, through the public ctx.shellEnv registry.

Why

Upstream DSH (0.1.5-rc.2) does not set those variables for tool subprocesses (verified: no reference in the tree; env inside a tool call shows nothing). Without them a subprocess cannot say which tool call it belongs to, so any egress or observability layer can only guess — and a guessed attribution is worse than none, because it looks authoritative.

What it does

ctx.shellEnv.register({
  name: 'clawsjoy-tool-attribution',
  variables: { DSH_TOOL_CALL_ID: {...}, DSH_TOOL_NAME: {...} },
  resolve: execution => attribute(execution),   // {} when unattributable
})
  • Reads the host's ToolExecution structurally (callId, name, rootCallId) so a host type change cannot break the build;
  • Sanitizes values (trimmed, no NUL/newline, bounded) and publishes nothing when the identity is unusable — the negative control;
  • Touches no subprocess-local/shell-env internals: the registry validates keys and rejects undeclared ones.

Install

dsh plugin --profile web add @clawsjoy/dsh-tool-attribution
- insert:
    - id: tool-attribution
      name: '@clawsjoy/dsh-tool-attribution'

Verification

pnpm test

License

MIT