EvilIrving/dsh-repro

Minimal, secret-scrubbed, replayable problem bundles for DeepSeek Harness sessions (/repro).

Bundle 已验证 MIT TypeScript 未知
Bundle 已验证

已收录

1

Dev

Bundle 已验证

版本未知
语言TypeScript
许可证MIT
在 GitHub 查看

预览

第 1 个预览,共 2 个:EvilIrving/dsh-repro
第 2 个预览,共 2 个:EvilIrving/dsh-repro

功能介绍

/repro 导出最小可复现问题包:去 secret 的会话日志、失败命令与 git diff。

适合

  • 需要把会话历史、失败命令和当前 Git diff 汇总为紧凑支持或缺陷报告包的开发者。
  • 需要保留可回放事件结构,同时把凭据形态的值脱敏而不是删除事件的工作流。
  • 希望通过 `/repro` 导出、且不把问题包内容注入模型上下文的团队。

不适合

  • 希望插件自身直接回放问题包的用户;v1 仅负责导出,不提供回放 CLI。
  • 要求输出写入必须经过 `ctx.fs` 的沙箱部署;v1 直接使用 `node:fs/promises` 写文件。
  • 必须内联大型 spill 产物的复现流程;插件只保留其定位引用。

README

dsh-repro

Export a minimal, secret-scrubbed, replayable problem bundle for the DeepSeek Harness.

Awesome DSH Plugin

/repro reads the current session’s complete canonical log through sessionPersistence.inspect, scrubs secrets value by value, collects failed commands and a git diff, and writes a repro-<sessionId>.json manifest.

Install

dsh plugin --profile <name> add github:EvilIrving/dsh-repro

Or, from a checkout:

dsh plugin --profile <name> add ./dsh-repro

The bundle patch inserts one plugin row (dsh-repro); it needs the commands and sessionPersistence services, which the base profile already mounts.

What the bundle contains

interface ReproManifest {
  formatVersion: number          // 1
  header: SessionHeader          // cwd, lineage, delegation depth
  events: SessionEvent[]         // complete, secret-scrubbed canonical log
  failedCommands: string[]       // `name <arguments>` for each errored tool call
  gitDiff: string                // empty when git or a repo is unavailable
  versions: Record<string, string>
}

The events array is the full canonical log (contiguous from seq 0), so it can later be replayed via ctx.sessions.create(id, { seed }); secrets are redacted, not dropped, which preserves replay balance.

Secret scrubbing (fail-closed)

redactValue walks the detached JSON log and:

  1. redacts any object key matching the harness’s credential pattern (/KEY|PASSWORD|SECRET|TOKEN/i) whole;
  2. redacts any string beginning with a known token prefix (sk-, ghp_, xoxb-, Bearer , …);
  3. redacts any high-entropy run (long base64/hex/token-shaped sequence).

Both prefix and entropy thresholds are Config-driven. The default is fail-closed: a string that looks credential-shaped is redacted rather than passed through. This mirrors session-telemetry’s waterfall shape (rewrite an outbound copy, never the canonical log) while supplying the value-level rules the telemetry seam deliberately ships without.

Config

export interface Config {
  tokenPrefixes: string[]
  minHighEntropyLength: number  // default 20
  gitDiffMaxBytes: number       // default 256 KiB
  gitGraceMs: number            // default 5000
}

Dependencies

  • commands and sessionPersistence are hard dependencies (inject).
  • subprocess is optional (ctx.get): git diff degrades to an empty string when it is absent or the cwd is not a repository.

Model Experience

Request context and condition
What the model sees

A single slash command /repro [output directory]. Its result is a one-line success message naming the written bundle path; the bundle contents are never injected into the model context.

Token effect

Zero-direct effect; the command result is a single short text line.

KV Cache effect

Append-only: the command lifecycle events (command/run, command/done) append to the log and never rewrite earlier tokens.

Known Limitations and Deferred Work

  • Bundle write bypasses the sandboxed ctx.fs seam — v1 uses node:fs/promises directly; routing the write through ctx.fs (so a sandboxed deployment constrains the output path) is deferred.
  • Replay CLI is out of scope — dsh repro run <bundle> is a separate process-level seam (boot/cmdline + cmdlineArgs), not /repro; v1 only exports.
  • No oversized-artifact inlining — spill artifacts are referenced by locator, never inlined; any file-byte inlining would need a size policy.

常见问题常见问题

在启用了 DSH 的终端中执行已验证命令 dsh plugin --profile default add github:EvilIrving/dsh-repro。命令会解析公开 package 元数据,并保持插件与本页展示的目录身份一致。