2nd dokployH
Find a file
Tianyi Cui bb9ae2ba99 docs(bash): reframe stdin/env — the scrub is the security control, not a trust boundary
Address review: the "trusted-plugin surface" framing overstated the security
story. A model driving the `bash` tool already has equivalent power to set env
vars and feed stdin through ordinary shell syntax (`FOO=bar cmd`, heredocs), so
the `env`/`stdin` seam fields grant it no new capability — and they cannot
exfiltrate the harness's ambient credentials, because the credential SCRUB in
dsh-bash-local (which strips *KEY*/*SECRET*/*TOKEN* from process.env before the
child sees it) is the actual control, and it works regardless of these fields
(tool-call args are static JSON, never shell-evaluated).

So drop the "dangerous / trusted-plugin boundary" language across the RFC, the
three bash-package READMEs, the bash/src/types.ts JSDoc, and docs/bash.md (both
the type-equiv blocks — kept 1:1 with source — and the prose). The reality that
remains: the `bash` tool doesn't EXPOSE env/stdin as parameters because they'd
be redundant with shell syntax; the fields exist for in-process plugins (the
hooks bridges) to pass a JSON payload + CLAUDE_* vars cleanly. The guard test is
kept but reframed: it catches a future `...args` spread that would silently
forward model input into the post-scrub env merge, NOT a trust wall. No code or
behavior change.
2026-07-02 04:08:24 +08:00
.agents/skills docs(rfc): classify RFCs by kind via path-encoded subdirectories 2026-06-20 22:29:45 +08:00
.claude docs: accuracy sweep, architecture restructure, two ADRs, review skill 2026-06-13 22:05:34 +08:00
.github/workflows ci: remove gitlab mirror workflow 2026-06-29 18:04:11 +08:00
docs docs(bash): reframe stdin/env — the scrub is the security control, not a trust boundary 2026-07-02 04:08:24 +08:00
examples docs(compaction): flag missing snapshot coverage with a FIXME 2026-07-02 00:29:33 +08:00
packages docs(bash): reframe stdin/env — the scrub is the security control, not a trust boundary 2026-07-02 04:08:24 +08:00
scripts Merge remote-tracking branch 'origin/master' into compact-basic-refactor 2026-07-01 23:29:20 +08:00
vendor Use explicit ts specifiers for declarations 2026-06-22 06:11:00 +08:00
.gitignore Merge origin/master into codex/fix-stdio-readline-terminal 2026-06-23 16:27:49 +08:00
AGENTS.md Merge remote-tracking branch 'origin/master' into compact-basic-refactor 2026-07-01 23:29:20 +08:00
CLAUDE.md Initialize repo with README, AGENTS.md, and CLAUDE.md symlink 2026-06-10 22:58:56 +08:00
eslint.config.mjs fix: make constraints, lint and md-links happy 2026-06-22 01:38:44 +08:00
knip.json Add the ACP subagent backend: out-of-process delegation (PR3) 2026-06-22 10:47:02 +08:00
lefthook.yml feat(acp-example): snapshot harness, normalizers, wiring, and handshake scenario 2026-06-19 03:36:12 +08:00
LICENSE Initialize repo with README, AGENTS.md, and CLAUDE.md symlink 2026-06-10 22:58:56 +08:00
package.json Use explicit ts specifiers for declarations 2026-06-22 06:11:00 +08:00
pnpm-lock.yaml Merge remote-tracking branch 'origin/master' into compact-basic-refactor 2026-06-30 09:13:15 +08:00
pnpm-workspace.yaml Reorganize packages into a modular hierarchy 2026-06-20 22:55:20 +08:00
README.md feat: migrate to pnpm 2026-06-16 14:55:37 +08:00
tsconfig.base.json feat(tool-todo): add the model-facing todo_write tool 2026-06-29 10:30:52 +08:00
tsconfig.build.json Merge remote-tracking branch 'origin/master' into compact-basic-refactor 2026-06-30 09:13:15 +08:00
tsconfig.json Merge remote-tracking branch 'origin/master' into compact-basic-refactor 2026-06-30 09:13:15 +08:00
tsdown.config.ts Merge remote-tracking branch 'origin/master' into feat/adr0016-type-build-check 2026-06-22 00:35:51 +08:00
vitest.config.ts Merge remote-tracking branch 'origin/master' into feat/adr0016-type-build-check 2026-06-22 00:35:51 +08:00
vitest.e2e.config.ts Merge remote-tracking branch 'origin/master' into feat/adr0016-type-build-check 2026-06-22 00:35:51 +08:00
vitest.snapshot.config.ts feat: one tsconfig.json and different rules 2026-06-19 23:35:47 +08:00

DeepSeek Harness

Monorepo for the DeepSeek Harness group.

Projects

  • DeepSeek Code — DeepSeek's coding agent product.

Development

This monorepo is built on the Cordis framework (vendored as source under vendor/), microkernel-style: everything is a plugin.

pnpm install
pnpm run test          # vitest
pnpm run demo:echo     # runnable echo-agent example (no API key needed)
pnpm run demo:coding   # the real DeepSeek coding agent (needs DEEPSEEK_API_KEY)

For humans, start with the development guide for local setup, hooks, environment variables, and quality gates, then read the architecture design before package work. Local context lives in packages/ and vendor/.

For agents, follow AGENTS.md.