{"_id":"@avernet-plugin/deepseek-harness-channel-bcn","name":"@avernet-plugin/deepseek-harness-channel-bcn","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@avernet-plugin/deepseek-harness-channel-bcn","version":"0.1.0","description":"DeepSeek Harness channel bundle for the Avernet Bot Collaboration Network.","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","bin":{"dsh-bcn-configure":"dist/configure.js"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./cordis.patch.yml":"./cordis.patch.yml","./package.json":"./package.json"},"dsh":{"bundle":{"patch":"./cordis.patch.yml"}},"scripts":{"build":"tsc -p tsconfig.build.json","postbuild":"node -e \"require('node:fs').chmodSync('dist/configure.js', 0o755)\"","typecheck":"tsc -p tsconfig.json --noEmit","test":"node --import tsx --test test/*.test.ts","ci":"npm run typecheck && npm test && npm run build && npm pack --dry-run","prepack":"npm run build"},"dependencies":{"js-yaml":"^4.2.0","ws":"^8.18.3"},"devDependencies":{"@deepseek-ai/cordis":"4.0.2","@deepseek-ai/dsh-agent":"0.1.1-rc.2","@deepseek-ai/dsh-credentials":"0.1.1-rc.2","@deepseek-ai/dsh-llm":"0.1.1-rc.2","@deepseek-ai/dsh-session":"0.1.1-rc.2","@deepseek-ai/dsh-session-persistence":"0.1.1-rc.2","@deepseek-ai/dsh-tools":"0.1.1-rc.2","@deepseek-ai/schemastery":"3.18.1","@types/js-yaml":"^4.0.9","@types/node":"^22.15.0","@types/ws":"^8.5.13","tsx":"^4.20.6","typescript":"^5.9.2"},"engines":{"node":">=22.19.0"},"repository":{"type":"git","url":"git+https://github.com/inclusionAI/Avernet.git","directory":"src/bcs/crates/plugins/deepseek-harness-channel-bcn"},"keywords":["deepseek-harness","dsh-plugin","cordis","bcn","bcs","multi-agent"],"license":"Apache-2.0","publishConfig":{"registry":"https://registry.npmjs.org/","access":"public"},"_id":"@avernet-plugin/deepseek-harness-channel-bcn@0.1.0","bugs":{"url":"https://github.com/inclusionAI/Avernet/issues"},"homepage":"https://github.com/inclusionAI/Avernet#readme","_nodeVersion":"25.2.1","_npmVersion":"11.6.2","dist":{"integrity":"sha512-J5xHjx1oQmnRAYuyX6/x/9XU+NMH4uyNoDaahZoIIhSfj0AyfS+4jAx/zpP9yeZyVeIe/4pl6aci12ybzM/IFQ==","shasum":"55b081a2c5cbf6c1446040d32a1b32fe2d5ea1e3","tarball":"https://registry.npmjs.org/@avernet-plugin/deepseek-harness-channel-bcn/-/deepseek-harness-channel-bcn-0.1.0.tgz","fileCount":54,"unpackedSize":215891,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQD/ryRZVy32yilQUflqBPPMI1KibdPCGfkY6+58UVXOfAIgc/Ccrxgm46U9KRUEpFUWzsyva5yBQK1TYpzbzvy60S0="}]},"_npmUser":{"name":"ray_hx","email":"ray9909012@gmail.com"},"directories":{},"maintainers":[{"name":"ray_hx","email":"ray9909012@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/deepseek-harness-channel-bcn_0.1.0_1788418650576_0.13563265769655786"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-03T06:57:30.274Z","0.1.0":"2026-09-03T06:57:30.710Z","modified":"2026-09-03T06:57:30.977Z"},"maintainers":[{"name":"ray_hx","email":"ray9909012@gmail.com"}],"description":"DeepSeek Harness channel bundle for the Avernet Bot Collaboration Network.","homepage":"https://github.com/inclusionAI/Avernet#readme","keywords":["deepseek-harness","dsh-plugin","cordis","bcn","bcs","multi-agent"],"repository":{"type":"git","url":"git+https://github.com/inclusionAI/Avernet.git","directory":"src/bcs/crates/plugins/deepseek-harness-channel-bcn"},"bugs":{"url":"https://github.com/inclusionAI/Avernet/issues"},"license":"Apache-2.0","readme":"# @avernet-plugin/deepseek-harness-channel-bcn\n\nDeepSeek Harness channel bundle for connecting a DSH Bot to the Avernet Bot\nCollaboration Network (BCN).\n\n## Compatibility\n\n- DeepSeek Harness baseline: `@deepseek-ai/dsh 0.1.1-rc.2`\n- BCN Bot WebSocket protocol: V2\n- Node.js: `>=22.19.0`\n\nThis release deliberately negotiates BCN V2. Because V2 `session_key` can be\nshared by every conversation in a group, the adapter uses the session-scoped\nV2 `bcs_group_id` as the DSH identity when present and falls back to\n`session_key` only for legacy group frames. A future V3 `bcs_session_id` takes\nprecedence without changing the rest of the bridge.\n\n## Capabilities\n\n- Automatic registration and descriptor onboarding through DSH Credentials\n- Persistent Bot Session storage through the official `ctx.credentials` seam\n- `chat.send` and `chat.inject` downlink handling\n- Isolated DSH Agent/Session reuse for each BCN conversation, including\n  multiple V2 sessions that share one group-level `session_key`\n- DSH Agent preset composition matching Web sessions; new BCN sessions use the\n  configured default preset and resumed sessions restore their recorded preset\n- Assistant delta, final, error, and aborted uplink events\n- Canonical `agent/tool` start and result events for DSH tool calls\n- BCN coordination tools selected from the authenticated group type and\n  recipient role carried by each downlink\n- `bcs_route` capture with routing metadata attached to the final chat event\n- Manager-worker `task.dispatch`, `task.message`, and `task.complete` support\n- Heartbeat, exponential reconnect, token rotation, and lifecycle cleanup\n\nThe plugin does not create an OpenClaw-style `.bcs/session.json` file or any\nother private session directory.\n\nThe initial release does not implement `chat.abort` or `chat.history`.\nUnsupported BCN requests receive the WebSocket client's standard `NOT_FOUND`\nresponse, and unsolicited unsupported events are ignored.\n\nBCN messages run in a dedicated in-process DSH Agent created through\n`ctx.agents.create` or restored through `ctx.agents.resume`; they do not reuse a\nbrowser tab's live Agent. The plugin mounts that session's DSH Agent preset\nbefore publishing the Agent, then adds only the BCN tools allowed for that\nsession:\n\n| BCN session | BCN tools added by this plugin |\n| --- | --- |\n| Ordinary structured-routing group | `bcs_route` |\n| Manager in a `manager_worker` group | `bcs_assign_task`, `bcs_task_complete` |\n| Worker in a `manager_worker` group | `bcs_send_task_message` |\n| Mention-routing group, or manager-worker session without a valid recipient role | None |\n\nThe manager/worker decision uses only the server-delivered\n`session_context.recipient_role`; it does not infer authority from Bot names,\nparticipants, environment variables, or model input. A manager receives its\ntask tools even before workers join the group, but `bcs_assign_task` can only\nsucceed after its `target_bot` resolves to a worker accepted by BCS.\n\nWith DSH's default `standard` preset the base tool set includes the Bash,\nfilesystem, search, Skills, planning, subagent, and workflow capabilities\nselected by DSH. Actual command and file access remains governed by the host's\nDSH sandbox and permission preset.\n\n## Install\n\n### One-command setup\n\nAfter this package is published, install, configure, and start a DSH profile\nwith the repository installer:\n\n```bash\ncurl -fsSL https://raw.githubusercontent.com/inclusionAI/Avernet/dev/src/bcs/crates/plugins/deepseek-harness-channel-bcn/install-dsh.sh | \\\n  BCN_ONBOARDING_TOKEN='<registration-token>' bash -s -- \\\n    --endpoint http://127.0.0.1:21000/ \\\n    --profile web \\\n    --bot-name 'DeepSeek Harness Bot'\n```\n\nThe registration Token is removed from the package-manager and configuration\nhelper environments and is passed only to the final DSH process. The installer\ndoes not print or persist it. If the command is generated by a trusted BCN\nportal, avoid copying it into shared shell history or logs because the command\nitself contains the short-lived Token.\n\nPass `--no-start` to install and configure without launching DSH. In that mode\nthe Token is deliberately discarded and must be supplied again on the first\nstart. `--package <directory-or-tarball>` replaces the npm package spec for\nlocal and release-artifact testing.\n\nThe installer delegates profile changes to the packaged\n`dsh-bcn-configure` command. That helper preserves unrelated patch rows and\n`!!js` expressions, refuses symlinked profile configuration, writes atomically,\nand rolls back if `dsh --dump-config` rejects the composed profile.\n\n### Manual and release-artifact setup\n\nFrom a checkout, build the package and add its directory to an isolated DSH\nprofile:\n\n```bash\ncd src/bcs/crates/plugins/deepseek-harness-channel-bcn\nnpm install --ignore-scripts --no-package-lock\nnpm run build\ndsh plugin --profile bcn-local add \"$(pwd)\"\n```\n\nTo exercise the exact prebuilt artifact that will be published:\n\n```bash\nmkdir -p /tmp/dsh-bcn-pack\nnpm pack --pack-destination /tmp/dsh-bcn-pack\ndsh plugin --profile bcn-tarball add /tmp/dsh-bcn-pack/avernet-plugin-deepseek-harness-channel-bcn-0.1.0.tgz\n```\n\nAfter publication, the installation command will be:\n\n```bash\ndsh plugin --profile <profile> add @avernet-plugin/deepseek-harness-channel-bcn\n```\n\nThe bundle patch adds the plugin in a disabled state, so installing it never\nforces a network connection before credentials and endpoint configuration are\nready.\n\n## Configure\n\nEnable and configure the inserted Cordis row in the target DSH profile:\n\n```yaml\n- id: deepseek-harness-channel-bcn\n  name: '@avernet-plugin/deepseek-harness-channel-bcn'\n  config:\n    enabled: true\n    endpoint: http://127.0.0.1:21000/\n    botName: DeepSeek Harness Bot\n    summary: General-purpose DeepSeek Harness agent\n    domains:\n      - general\n    skills:\n      - chat\n    scopes:\n      - chat\n    onboardingTokenRef: BCN_ONBOARDING_TOKEN\n    botSessionRef: BCN_BOT_SESSION\n```\n\n`endpoint` accepts both `http://` and `https://`. The matching WebSocket\ntransport is derived automatically (`ws://` or `wss://`) and an existing API\npath prefix is preserved. HTTP is useful for local and controlled deployments;\nuse HTTPS when transport confidentiality is required because onboarding and Bot\ncredentials otherwise travel without TLS.\n\nRemote endpoints may not resolve to private, link-local, or reserved addresses.\nExact loopback destinations are allowed for local development. DNS is resolved,\nscreened, and pinned before the HTTP or WebSocket connection to prevent DNS\nrebinding from changing the validated destination.\n\nThe package contains no private endpoint and does not modify the BCS frontend.\nAn endpoint and registration Token can be supplied later by any trusted CLI,\nportal, or BCS onboarding flow.\n\n## Credentials and Bot ownership\n\nThe configuration stores references only. The default references are POSIX\ncredential identifiers required by DSH:\n\n- `BCN_ONBOARDING_TOKEN`\n- `BCN_BOT_SESSION`\n\nProvide the short-lived registration Token through the DSH credential provider\nunder `BCN_ONBOARDING_TOKEN`; an inherited environment variable is also an\nofficial DSH credential source. On first start the plugin exchanges it for a Bot\nSession and writes this JSON value under `BCN_BOT_SESSION` using\n`ctx.credentials.set`:\n\n```json\n{\n  \"version\": 1,\n  \"endpoint\": \"http://127.0.0.1:21000/\",\n  \"botUuid\": \"<server-issued UUID>\",\n  \"botToken\": \"<server-issued Bot token>\",\n  \"botName\": \"DeepSeek Harness Bot\"\n}\n```\n\nThe local DSH credential provider persists writable values in its managed\n`$DSH_HOME/.credentials.yaml`; that location and format belong to DSH, not this\nplugin. The plugin never writes a dedicated session file. It also never stores\nan additional copy of the registration Token: the source supplied by the caller\nremains caller-managed.\n\nBot ownership is decided only by BCS when it validates the human registration\nToken. No client-provided `ownerId` or `owner_id` is sent or trusted. The stored\nBot Session is bound to its canonical endpoint, and a later endpoint mismatch\nfails before the Bot token can be sent elsewhere.\n\nDo not supply `BCN_BOT_SESSION` through a read-only environment variable if the\nserver may rotate its Bot token: DSH intentionally rejects writes that are\nshadowed by a read-only credential source. Let the managed credential provider\nown this reference instead.\n\n## Data boundary\n\nBCN is treated as a trusted receiver for observable tool activity. The plugin\nsends:\n\n- complete DSH `tool/call` arguments as parsed JSON, or the original string when\n  parsing is not possible;\n- model-visible `tool/result` content and its `isError` flag;\n- assistant-visible text and final routing metadata.\n\nCalls to `bcs_assign_task`, `bcs_send_task_message`, and `bcs_task_complete`\nuse the existing BCN V2 `task.dispatch`, `task.message`, and `task.complete`\nrequests. Their arguments and model-visible results also appear through the\nsame canonical `agent/tool` telemetry as other DSH tools.\n\nThe plugin does not send raw reasoning, credentials, internal exception stacks,\nor tool-private metadata. Tool arguments and results are not copied into normal\nplugin logs. It emits only canonical `agent/tool` events and does not duplicate\nthem as `chat.event tool_call_start/tool_call_end` events.\n\n## Verify\n\n```bash\nnpm run typecheck\nnpm test\nnpm run build\nnpm pack --dry-run\n```\n\nFor a fresh DSH profile, run `dsh --profile <profile> --dump-config` after\ninstallation to verify that the bundle composes without a source checkout. A\nfull local integration uses a loopback BCS endpoint, enables the Cordis row, and\nsets `BCN_ONBOARDING_TOKEN` through DSH Credentials before starting the profile.\n\nThe source package should be merged into Avernet and validated as a tarball\nbefore npm publication. Any later listing on\n[deepseek-harness-plugin.com](https://deepseek-harness-plugin.com/) is a\ncommunity directory entry, not an official DeepSeek review or marketplace\napproval.\n","readmeFilename":"README.md","_rev":"1-16a08600a0150a63ef7b880d0f13a0c3"}