2nd dokployH
Find a file
imccyu d12cb45838 workflow: spawn the worker with an empty environment
The documented vm escape reaches process, and the worker inherited the
harness's env - so a buggy or prompt-injected script could read and
exfiltrate ambient credentials (DEEPSEEK_API_KEY et al.) without
touching a single file (ds-review-bot finding on #233).

Spawn with env: {} and a hermetic execArgv on both runtime shapes, the
same stance as dsh-code-runtime-worker and stronger than the scrubbed
env the defensive-patterns rule requires for spawned commands (a shell
needs PATH; this worker needs nothing). Ambient-channel hardening only:
an escapee keeps the process-wide privileges the trust premise already
admits - the genuine sandbox remains an engine swap.
2026-07-09 23:57:43 +08:00
.agents/skills simplify pre-push skill guidance 2026-07-07 19:17:16 +08:00
.claude docs: accuracy sweep, architecture restructure, two ADRs, review skill 2026-06-13 22:05:34 +08:00
.github/workflows ci: add all-checks-passed aggregate job for branch protection 2026-07-08 10:57:25 +08:00
docs Merge remote-tracking branch 'origin/master' into workflow-vm-to-workerthread 2026-07-09 23:48:17 +08:00
examples Merge remote-tracking branch 'origin/master' into workflow-vm-to-workerthread 2026-07-09 23:48:17 +08:00
packages workflow: spawn the worker with an empty environment 2026-07-09 23:57:43 +08:00
scripts Merge remote-tracking branch 'origin/master' into workflow-vm-to-workerthread 2026-07-09 23:48:17 +08:00
vendor Use explicit ts specifiers for declarations 2026-06-22 06:11:00 +08:00
.gitignore ci: cache eslint lane 2026-07-06 03:07:35 +08:00
AGENTS.md Merge remote-tracking branch 'origin/master' into workflow-vm-to-workerthread 2026-07-09 22:36:52 +08:00
CLAUDE.md Initialize repo with README, AGENTS.md, and CLAUDE.md symlink 2026-06-10 22:58:56 +08:00
eslint.config.mjs ci: ignore doc-typecheck temp dirs during lint 2026-07-06 02:04:32 +08:00
knip.json Merge remote-tracking branch 'origin/master' into workflow-vm-to-workerthread 2026-07-09 22:36:52 +08:00
lefthook.yml Merge parallel pre-push gates into CI scheduler 2026-07-06 01:47:13 +08:00
LICENSE Initialize repo with README, AGENTS.md, and CLAUDE.md symlink 2026-06-10 22:58:56 +08:00
package.json Merge remote-tracking branch 'origin/master' into code-mode-tools 2026-07-09 22:58:58 +08:00
pnpm-lock.yaml Merge remote-tracking branch 'origin/master' into workflow-vm-to-workerthread 2026-07-09 23:48:17 +08:00
pnpm-workspace.yaml Reorganize packages into a modular hierarchy 2026-06-20 22:55:20 +08:00
README.i18n.yaml docs: revise graph docs from review 2026-07-05 01:25:58 +08:00
README.md docs: revise graph docs from review 2026-07-05 01:25:58 +08:00
README.zh.md docs: revise graph docs from review 2026-07-05 01:25:58 +08:00
tsconfig.base.json Merge remote-tracking branch 'origin/master' into workflow-vm-to-workerthread 2026-07-09 22:36:52 +08:00
tsconfig.build.json Merge remote-tracking branch 'origin/master' into workflow-vm-to-workerthread 2026-07-09 22:36:52 +08:00
tsconfig.json Merge remote-tracking branch 'origin/master' into workflow-vm-to-workerthread 2026-07-09 22:36:52 +08:00
tsdown.config.ts Merge remote-tracking branch 'origin/master' into feat/adr0016-type-build-check 2026-06-22 00:35:51 +08:00
vitest.config.ts feat: add the worker-thread code runtime (dsh-code-runtime-worker) 2026-07-08 11:07:14 +08:00
vitest.e2e.config.ts Merge parallel pre-push gates into CI scheduler 2026-07-06 01:47:13 +08:00
vitest.snapshot.config.ts feat: one tsconfig.json and different rules 2026-06-19 23:35:47 +08:00

DeepSeek Harness

English | 中文

The DeepSeek Harness SDK is a plugin-based SDK for building agent harnesses.

Development

This monorepo is built on the Cordis framework (vendored as source under vendor/), microkernel-style: everything is a plugin.

pnpm install
pnpm run test          # vitest
pnpm run demo:repl     # REPL agent demo (needs DEEPSEEK_API_KEY)
pnpm run demo:acp      # ACP server agent demo (needs DEEPSEEK_API_KEY)

For humans, start with the development guide for local setup, hooks, environment variables, and quality gates, then read the architecture design and documentation graph index before package work. Local context lives in packages/ and vendor/.

For agents, follow AGENTS.md.