EvilIrving/dsh-proof

dsh-proof is an independent read-only acceptance layer: before each top-level turn closes it spawns a read-only verifier subagent, collects its structured verdict, and steers any non-pass gaps back into the driving agent — the harness's missing 'is the agent actually done' gate. It intercepts agent/turn-stopping (serial, awaited before the turn commits), spawns the verifier with a deny list over the inherited tool set (never a whitelist that could hide a newly added read-only tool), blocks recursion via delegationDepthOf > 0 and maxDepth: 0, and steers on fail/insufficient-evidence via agent.inject + agent.steer. A verifier ending with stopReason !== 'completed' or a missing structured result counts as 'no objection', so a failed proof never fails the user's turn. Severity-agnostic config: providerName, maxAttemptsPerTurn, denyTools, verifierPrompt, followupInstruction.

Other ★ 1 updated 2026-08-14 — untested
View on GitHub ↗

Install

dsh plugin --profile web add github:EvilIrving/dsh-proof

README EN verified 2026-09-02 (repo EvilIrving/dsh-proof). Install per README: dsh plugin --profile <name> add github:EvilIrving/dsh-proof (or from a checkout). The bundle patch inserts one plugin row; it needs the subagents service (official dsh-subagent providers), which the base profile already mounts. Defaults: providerName 'spawn', maxAttemptsPerTurn 3, denyTools default mutating-tool deny list.

Compatibility

DSH profile with the subagents service mounted; agent/turn-stopping seam; read-only verifier subagent via ctx.subagents.start + toolFilter.deny.

Details

Recent updates

Read-only acceptance gate before turn close; verifier subagent with deny-list narrowing; fail/insufficient-evidence steering; recursion blocked; failed proofs never fail the turn.

FAQ

Does the verifier modify anything?
No — it is read-only: spawned with toolFilter.deny over the inherited tool set (write, edit, str_replace_editor, bash, run_code, subagent denied by default), keeping read-only discovery tools available.
What happens when the verdict is not pass?
Gap details are injected and a follow-up is steered back to the driving agent; on 'no objection' (stopped early or missing structured result) the turn simply proceeds.
Which service does it need?
The subagents service (the official dsh-subagent providers), which the base profile already mounts.

Alternatives

ben7am1n/dsh-review-skills · dongsheng123132/dsh-policy-drift-proof

More plugins in Other

Browse more in Other

Guides for Other plugins