Bundle
dsh-verify-gate
Engineering verify gate for DeepSeek Harness: configured commands are authority; dirty receipts block conclude.
- Source
- blueWhalei
- License
- MIT
- Updated
- Updated 20 days ago
Readme
# dsh-verify-gate
English | [中文](README.zh.md)
An open-source DeepSeek Harness plugin that requires the agent to run the workspace’s verification commands before it can conclude that work is done.
Pass/fail is decided only by process exit codes. A successful run writes an auditable receipt. After that, any successful mutating tool (for example edit, write, or bash) invalidates the receipt, so verification must pass again before conclude.
## Install
Local path:
```sh
dsh plugin --profile web add /absolute/path/to/verify-gate
```
Or from GitHub (the repo includes the built `lib/` entry points):
```sh
dsh plugin --profile web add github:blueWhalei/dsh-verify-gate
```
Restart Web, open the target workspace, then:
1. Run `/verify run`, or have the model call `verify_run`
2. Call `verify_conclude` only after every command exits 0
## How commands are chosen
Resolution order:
1. Non-empty `config.commands` always wins
2. Otherwise auto-detect (on by default) requires **exactly one** common workspace marker:
- `package.json` with `scripts.test` → pick the package manager from the lockfile / `packageManager`, then run `<pm> test`
- `go.mod` → `go test ./...`
- `Cargo.toml` → `cargo test`
3. If nothing matches, or more than one ecosystem matches → fail with an error that asks you to set `commands`, instead of guessing
For Python, Java, and other stacks with many local conventions, set `commands` explicitly.
## Custom config
Change config only when the default is wrong. Put this in the profile’s `cordis.patch.yml` (it replaces that plugin’s entire `config`):
```yaml
- id: dsh-verify-gate
name: dsh-verify-gate
config:
commands:
- id: test
run: pytest -q
autoDetect: true
sandboxMode: danger-full-access
```
`sandboxMode` defaults to `danger-full-access` so package managers can use a global store. If you tighten the sandbox, confirm the verify commands still run for real.
## Everyday entry points
| Goal | Entry |
|---|---|
| Run verification | `verify_run` or `/verify run` |
| Inspect gate status | `verify_status` or `/verify` |
| Conclude | `verify_conclude` (needs a green, non-dirty, non-expired receipt) |
Receipts are stored under `<workspace>/.dsh/verify-receipts/`. Most application repos should ignore that directory.
## License
MIT
Install
dsh plugin --profile web add github:blueWhalei/dsh-verify-gate
Profile: web
With the hub plugin installed, ask your agent to install it by name — it resolves the same plan shown here.
dsh plugin --profile web add github:stvlynn/dsh.fish#path:packages/dsh-plugin-hub
install dsh-verify-gate from the hub
- This package builds from source on install. pnpm will ask you to allow its build script — that is permission to run the package’s code on your machine, outside the agent sandbox. Only allow sources you trust.
- This source has no pinned commit, so a later push upstream changes what installs. Prefer pinning a commit.