dsh-repro
by EvilIrving
/repro 导出最小可复现问题包:去 secret 的会话日志、失败命令与 git diff。
/repro exports a minimal, secret-scrubbed, replayable problem bundle: the session log, failed commands, and Git diff.
安装
dsh plugin --profile web add github:EvilIrving/dsh-reproGitHub 源码安装:首次需按提示配置 allowBuilds 构建授权后重试
安装与环境配置指引、插件开发教程见 DSH 中文社区文档 ↗
安装即在你的机器上以你的权限运行第三方代码——它可读写文件、使用凭据、访问网络,DSH 的工具审批不会为插件代码加沙箱。「检测到 manifest」仅代表发现 dsh.bundle / dsh.plugin 清单,不构成兼容性或安全审查;安装前请审阅源码,不熟悉的插件先在不含密钥的环境试用。
README
目录
Export a minimal, secret-scrubbed, replayable problem bundle for the DeepSeek Harness.
/repro reads the current session's complete canonical log through
sessionPersistence.inspect, scrubs secrets value by value, collects failed
commands and a git diff, and writes a repro-<sessionId>.json manifest.
Install
dsh plugin --profile <name> add github:EvilIrving/dsh-repro
Or, from a checkout:
dsh plugin --profile <name> add ./dsh-repro
The bundle patch inserts one plugin row (dsh-repro); it needs the
commands and sessionPersistence services, which the base profile already
mounts.
What the bundle contains
interface ReproManifest {
formatVersion: number // 1
header: SessionHeader // cwd, lineage, delegation depth
events: SessionEvent[] // complete, secret-scrubbed canonical log
failedCommands: string[] // `name <arguments>` for each errored tool call
gitDiff: string // empty when git or a repo is unavailable
versions: Record<string, string>
}
The events array is the full canonical log (contiguous from seq 0), so it can
later be replayed via ctx.sessions.create(id, { seed }); secrets are redacted,
not dropped, which preserves replay balance.
Secret scrubbing (fail-closed)
redactValue walks the detached JSON log and:
- redacts any object key matching the harness's credential pattern
(
/KEY|PASSWORD|SECRET|TOKEN/i) whole; - redacts any string beginning with a known token prefix (
sk-,ghp_,xoxb-,Bearer, …); - redacts any high-entropy run (long base64/hex/token-shaped sequence).
Both prefix and entropy thresholds are Config-driven. The default is
fail-closed: a string that looks credential-shaped is redacted rather than
passed through. This mirrors session-telemetry's waterfall shape (rewrite an
outbound copy, never the canonical log) while supplying the value-level rules
the telemetry seam deliberately ships without.
Config
export interface Config {
tokenPrefixes: string[]
minHighEntropyLength: number // default 20
gitDiffMaxBytes: number // default 256 KiB
gitGraceMs: number // default 5000
}
Dependencies
commandsandsessionPersistenceare hard dependencies (inject).subprocessis optional (ctx.get):git diffdegrades to an empty string when it is absent or the cwd is not a repository.
Model Experience
Request context and condition
What the model sees
A single slash command /repro [output directory]. Its result is a one-line
success message naming the written bundle path; the bundle contents are never
injected into the model context.
Token effect
Zero-direct effect; the command result is a single short text line.
KV Cache effect
Append-only: the command lifecycle events (command/run, command/done) append
to the log and never rewrite earlier tokens.
Known Limitations and Deferred Work
- Bundle write bypasses the sandboxed
ctx.fsseam — v1 usesnode:fs/promisesdirectly; routing the write throughctx.fs(so a sandboxed deployment constrains the output path) is deferred. - Replay CLI is out of scope —
dsh repro run <bundle>is a separate process-level seam (boot/cmdline+cmdlineArgs), not/repro; v1 only exports. - No oversized-artifact inlining — spill artifacts are referenced by locator, never inlined; any file-byte inlining would need a size policy.
原始 README: https://github.com/EvilIrving/dsh-repro/blob/main/README.md ↗
同类插件
查看全部 →
k8e
k8e.sh — 开源 Agentic AI 沙箱矩阵

hol-guard
开源AI代理防病毒:运行时拦截风险工具、秘密访问、提示注入、恶意软件包、MCP服务器、插件和技能。

anolisa
ANOLISA(Agentic Nexus Operating Layer & Interface System Architecture):具备运行时、安全性、可观测性和 Tokenless 响应压缩能力的 Agentic OS,可降低 Token 使用量与成本。

mobius
首个自我演进的开源 Agent OS:连接你的团队、AI agent、设备与算力

deepseek-harness-desktop
DeepSeek Harness Tauri 桌面版 | Only 5mb installer, zero environment setup. Windows / macOS / Linux.

open-managed-agents
开源Claude管理代理API实现和自托管Claude标签式代理运行时。即插即用;在Cloudflare Workers/Durable Objects或Node.js上运行。Apache 2.0。