EvilIrving/dsh-proof
dsh-proof is an independent read-only acceptance layer: before each top-level turn closes it spawns a read-only verifier subagent, collects its structured verdict, and steers any non-pass gaps back into the driving agent — the harness's missing 'is the agent actually done' gate. It intercepts agent/turn-stopping (serial, awaited before the turn commits), spawns the verifier with a deny list over the inherited tool set (never a whitelist that could hide a newly added read-only tool), blocks recursion via delegationDepthOf > 0 and maxDepth: 0, and steers on fail/insufficient-evidence via agent.inject + agent.steer. A verifier ending with stopReason !== 'completed' or a missing structured result counts as 'no objection', so a failed proof never fails the user's turn. Severity-agnostic config: providerName, maxAttemptsPerTurn, denyTools, verifierPrompt, followupInstruction.
Install
dsh plugin --profile web add github:EvilIrving/dsh-proofREADME EN verified 2026-09-02 (repo EvilIrving/dsh-proof). Install per README: dsh plugin --profile <name> add github:EvilIrving/dsh-proof (or from a checkout). The bundle patch inserts one plugin row; it needs the subagents service (official dsh-subagent providers), which the base profile already mounts. Defaults: providerName 'spawn', maxAttemptsPerTurn 3, denyTools default mutating-tool deny list.
Compatibility
DSH profile with the subagents service mounted; agent/turn-stopping seam; read-only verifier subagent via ctx.subagents.start + toolFilter.deny.
Details
- Repo: EvilIrving/dsh-proof
- Category: Other
- Stars: 1
- Version: git github:EvilIrving/dsh-proof
- Last push: 2026-08-14
- First seen: 2026-08-14
Recent updates
Read-only acceptance gate before turn close; verifier subagent with deny-list narrowing; fail/insufficient-evidence steering; recursion blocked; failed proofs never fail the turn.
FAQ
- Does the verifier modify anything?
- No — it is read-only: spawned with toolFilter.deny over the inherited tool set (write, edit, str_replace_editor, bash, run_code, subagent denied by default), keeping read-only discovery tools available.
- What happens when the verdict is not pass?
- Gap details are injected and a follow-up is steered back to the driving agent; on 'no objection' (stopped early or missing structured result) the turn simply proceeds.
- Which service does it need?
- The subagents service (the official dsh-subagent providers), which the base profile already mounts.
Alternatives
ben7am1n/dsh-review-skills · dongsheng123132/dsh-policy-drift-proof