cordis.yml 9.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189
  1. # ACP server and snapshot-record composition. With `DSH_SNAPSHOT=record`, the
  2. # app bin runs the real DeepSeek adapter and the harness harvests its persisted
  3. # log. The bin loads the gitignored root `.env` before this config. This tree has
  4. # no stdout logger or HMR because stdout carries ACP JSON-RPC.
  5. # The DeepSeek adapter. Shipped default: full thinking at max effort on every
  6. # request (wire-only defaults; they never enter the request header).
  7. - id: llm-deepseek
  8. name: '@deepseek-ai/dsh-llm-deepseek'
  9. config:
  10. apiKey: !!js process.env.DEEPSEEK_API_KEY
  11. baseURL: !!js process.env.DEEPSEEK_BASE_URL
  12. thinking: enabled
  13. reasoningEffort: max
  14. defaultContextWindow: 256000
  15. models:
  16. - id: deepseek-v4-flash
  17. - id: deepseek-v4-pro
  18. # The default composition confines bash AND the filesystem tools to the
  19. # workspace and asks before a wider retry. Snapshot runs select
  20. # danger-full-access so the established scenarios remain runner-independent;
  21. # DSH_PERMISSION_MODE provides the same explicit deployment/test override
  22. # outside the snapshot harness. The sandbox default + fallback root live on
  23. # ctx.sandboxPolicy; agent calls resolve both families against the session cwd.
  24. - id: sandbox
  25. name: '@deepseek-ai/dsh-sandbox-local'
  26. - id: sandbox-policy
  27. name: '@deepseek-ai/dsh-sandbox-policy'
  28. config:
  29. mode: !!js "process.env.DSH_PERMISSION_MODE ?? (process.env.DSH_SNAPSHOT === undefined ? 'workspace-write' : 'danger-full-access')"
  30. workspaceRoot: !!js process.cwd()
  31. - id: bash
  32. name: '@deepseek-ai/dsh-bash-sandbox'
  33. config:
  34. timeoutMs: 60000
  35. - id: approval
  36. name: '@deepseek-ai/dsh-user-approval'
  37. config:
  38. policy: !!js "(process.env.DSH_PERMISSION_MODE ?? (process.env.DSH_SNAPSHOT === undefined ? 'workspace-write' : 'danger-full-access')) === 'danger-full-access' ? 'never' : 'ask'"
  39. - id: permission
  40. name: '@deepseek-ai/dsh-permission'
  41. # The ACP server app: the agent-spine-demo spine + JSONL persistence + the ACP bridge.
  42. # Persistence root: $DSH_SNAPSHOT_SESSIONS_ROOT when the snapshot harness sets it
  43. # (so it can harvest / isolate the log), else ./.sessions for the demo.
  44. # Snapshot modes use raw JSONL fixtures; ordinary runs keep the compressed default.
  45. - id: acp-agent
  46. name: '@deepseek-ai/dsh-acp-demo'
  47. config:
  48. provider: deepseek
  49. model: deepseek-v4-pro
  50. persistenceRoot: !!js process.env.DSH_SNAPSHOT_SESSIONS_ROOT ?? './.sessions'
  51. persistenceCompression: !!js "process.env.DSH_SNAPSHOT === undefined ? 'zstd' : 'none'"
  52. workspaceContext:
  53. maxBytes: 65536
  54. # Keep the persona to identity and behavior; tool plugins own tool guidance.
  55. # The loop resolves {{model}} and each ACP session's client-supplied {{cwd}}.
  56. persona: |
  57. You are a coding assistant powered by the {{model}} model. Your working directory is {{cwd}}. Your bash tool runs under a file sandbox — a `[sandbox: file access denied …]` result is policy, not a command bug.
  58. Verify your work by running the code or tests. Keep answers brief and factual.
  59. # Plan mode is additive to the canonical ACP server. The ACP bridge projects
  60. # it onto the protocol picker; sandbox and approval remain independent options.
  61. - id: plan-mode
  62. name: '@deepseek-ai/dsh-plan-mode'
  63. config:
  64. section: |
  65. You are in plan mode. Stay in plan mode until exit_plan_mode succeeds or the user switches the session mode. Imperative language to implement changes means plan the implementation, not execute it. A user's conversational agreement — including an answer confirming something you asked — approves nothing and does not end plan mode; fold the confirmed decision into the plan and submit it through exit_plan_mode.
  66. Explore first. Use non-mutating reads, searches, static analysis, and checks to ground the plan in the actual repository. Do not edit or write files, change configuration, run formatters or code generation that rewrites tracked files, commit, or otherwise carry out the plan. Prefer existing functions and patterns over new machinery.
  67. The tool catalog stays the same across modes for request-cache stability. These plan-mode rules override any later tool description or guidance that suggests using mutation tools; those tools remain listed only to keep the request shape stable. Do not use todo_write to track this planning phase: it tracks implementation after an approved plan, while the plan itself belongs in exit_plan_mode.
  68. Resolve discoverable facts by inspection. Use ask_user_question only for user-owned choices or material ambiguity that inspection cannot answer. Do not ask the user where code lives or how current behavior works when you can find out.
  69. Make the plan decision-complete: state the goal and success criteria; group implementation changes by subsystem; identify public API, schema, and data-flow changes; cover edge cases, failure modes, tests, acceptance criteria, and explicit assumptions. Keep it concise enough to review but detailed enough that another engineer can implement it without making design decisions.
  70. When ready, call exit_plan_mode with the complete plan markdown, starting with a # title. Make exit_plan_mode the only and final tool call in that assistant response: it presents the plan for approval, and implementation begins only in a later step after approval. Do not paste the final plan as a plain reply or ask "should I proceed?" through prose or ask_user_question. If review rejects it, incorporate the feedback and present again. If the review channel is unavailable or aborted, stay in plan mode and ask the user to switch modes manually; do not proceed with implementation.
  71. # Blocking plan decisions and ordinary clarifications share ACP's elicitation
  72. # provider through the model-facing question tool.
  73. - id: tool-ask-user
  74. name: '@deepseek-ai/dsh-tool-ask-user'
  75. # Replay-aware request pressure; the routed adapter supplies model capacity.
  76. - id: token-meter
  77. name: '@deepseek-ai/dsh-token-meter'
  78. # Summarize an older range after measured pressure or a canonical provider overflow.
  79. # Ratios scale against the routed model's context window.
  80. - id: compact-basic
  81. name: '@deepseek-ai/dsh-compact-basic'
  82. config:
  83. thresholdRatio: 0.8
  84. retainRatio: 0.08
  85. maxTokens: 8192
  86. compactionRetries: 1
  87. # Expose fresh-child `spawn` and completed-prefix `fork` through separate tool
  88. # names so multi-child scenarios exercise both transports. These leaves follow
  89. # the app because it provides `ctx.agents` and `ctx.tools`.
  90. - id: subagent
  91. name: '@deepseek-ai/dsh-subagent'
  92. - id: subagent-spawn
  93. name: '@deepseek-ai/dsh-subagent-spawn'
  94. config:
  95. providerName: spawn
  96. - id: subagent-fork
  97. name: '@deepseek-ai/dsh-subagent-fork'
  98. config:
  99. providerName: fork
  100. - id: tool-subagent
  101. name: '@deepseek-ai/dsh-tool-subagent'
  102. config:
  103. provider: spawn
  104. toolName: subagent
  105. maxDepth: 1
  106. - id: tool-subagent-fork
  107. name: '@deepseek-ai/dsh-tool-subagent'
  108. config:
  109. provider: fork
  110. toolName: subagent_fork
  111. maxDepth: 1
  112. # The worker-thread workflow engine fans a model-written JavaScript script's
  113. # `agent()` calls out through the spawn backend; the adjacent tool exposes it to the model.
  114. - id: workflow-workerthread
  115. name: '@deepseek-ai/dsh-workflow-workerthread'
  116. config:
  117. provider: spawn
  118. - id: tool-workflow
  119. name: '@deepseek-ai/dsh-tool-workflow'
  120. - id: tool-ralph
  121. name: '@deepseek-ai/dsh-tool-ralph'
  122. # `todo_write` replaces the logged whole list and surfaces an ACP `plan` update.
  123. - id: tool-todo
  124. name: '@deepseek-ai/dsh-tool-todo'
  125. # Identical repeat calls trigger advisory context, never a block, at the default
  126. # thresholds [3, 5, 8]. Only the repeat-tool-guard snapshot scenario reaches them.
  127. - id: repeat-tool-guard
  128. name: '@deepseek-ai/dsh-repeat-tool-guard'
  129. # The filesystem stack rides the SAME sandbox policy as bash: dsh-fs-sandbox
  130. # replaces dsh-fs-local behind ctx.fs and fences write/edit by the effective
  131. # mode (read-only denies, workspace-write contains to the workspace + temp
  132. # roots, danger-full-access passes through), so read/write/edit are available
  133. # under every mode. fs-policy (read-before-edit) composes orthogonally on top.
  134. - id: fs-sandbox
  135. name: '@deepseek-ai/dsh-fs-sandbox'
  136. config:
  137. cwd: !!js process.cwd()
  138. - id: fs-policy
  139. name: '@deepseek-ai/dsh-fs-policy'
  140. - id: tool-fs
  141. name: '@deepseek-ai/dsh-tool-fs'
  142. # `configPath` is read once at load and resolves from the server launch cwd, not
  143. # `session/new.cwd`; one `hooks.json` therefore applies to every session and a
  144. # project-local file is not discovered. Missing config registers nothing. Hook
  145. # commands still run in the session cwd. Warnings use `ctx.logger`, never stdout;
  146. # see packages/hooks/hooks-claude/README.md for the deferred per-session design.
  147. - id: hooks-claude
  148. name: '@deepseek-ai/dsh-hooks-claude'
  149. config:
  150. configPath: ./hooks.json
  151. # Codex uses its own `codex-hooks.json` and snake_case five-event dialect; it
  152. # cannot share Claude's file. It has the same process-level, read-once, missing-is-no-op,
  153. # logger-only contract. Shipping both bridges lets a scenario seed and exercise either dialect.
  154. - id: hooks-codex
  155. name: '@deepseek-ai/dsh-hooks-codex'
  156. config:
  157. configPath: ./codex-hooks.json