{"_id":"@dhms-agentfuse/dsh-agentfuse","_rev":"2-32c0d75214c0a5835e43d603a8648369","name":"@dhms-agentfuse/dsh-agentfuse","dist-tags":{"latest":"0.2.1"},"versions":{"0.2.0":{"name":"@dhms-agentfuse/dsh-agentfuse","version":"0.2.0","license":"Apache-2.0","_id":"@dhms-agentfuse/dsh-agentfuse@0.2.0","maintainers":[{"name":"mkaliezz","email":"nathanzhong93@gmail.com"}],"homepage":"https://github.com/MkaliezZ/dsh-agentfuse-plugin#readme","bugs":{"url":"https://github.com/MkaliezZ/dsh-agentfuse-plugin/issues"},"dsh":{"bundle":{"patch":"./cordis.patch.yml"}},"dist":{"shasum":"7c3e5e39a2c354da8dbb020e27470d3acab35795","tarball":"https://registry.npmjs.org/@dhms-agentfuse/dsh-agentfuse/-/dsh-agentfuse-0.2.0.tgz","fileCount":8,"integrity":"sha512-zMQUIyNEOZG/ne9WAlHX5KrgMVq1MBmINlZrDr1wmHmisuMerNxZfktaCkdEXR4549HnZTdRtu7ts3/rK0DT0w==","signatures":[{"sig":"MEUCIH8wRbrJVQgz+2tBR+hFgr3/0FJgzkl/7P/0kv0V2z7UAiEA7pcmCENdwRVJLA9sjO3g5HGGRm716eJz5J7Uvxx8yBs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":23113},"main":"lib/index.js","type":"module","types":"lib/index.d.ts","exports":{".":{"types":"./lib/index.d.ts","default":"./lib/index.js"},"./src/*":"./src/*","./invariant":{"types":"./lib/invariant.d.ts","default":"./lib/invariant.js"},"./package.json":"./package.json","./cordis.patch.yml":"./cordis.patch.yml"},"gitHead":"366d213f207a833d45669b20551a33117eaeb6e6","scripts":{"test":"vitest run --config vitest.config.ts","build":"tsc -p tsconfig.build.json","prepublishOnly":"npm run build"},"_npmUser":{"name":"mkaliezz","email":"nathanzhong93@gmail.com"},"repository":{"url":"git+https://github.com/MkaliezZ/dsh-agentfuse-plugin.git","type":"git","directory":"packages/dsh-agentfuse"},"_npmVersion":"11.11.0","description":"AgentFuse fail-closed pre-dispatch tool gate for DeepSeek Harness: deterministic allow/block/ask policy with durable decision evidence","directories":{},"_nodeVersion":"25.8.1","dependencies":{"@dhms-agentfuse/core":"^0.2.0","@deepseek-ai/schemastery":"^3.18.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.0","typescript":"^5.8.3","@types/node":"^22.10.0","@deepseek-ai/cordis":"^4.0.1","@deepseek-ai/dsh-llm":"^0.1.0-rc.6","@deepseek-ai/dsh-agent":"^0.1.0-rc.6","@deepseek-ai/dsh-tools":"^0.1.0-rc.6","@deepseek-ai/dsh-session":"^0.1.0-rc.6","@deepseek-ai/dsh-invariants":"^0.1.0-rc.6","@deepseek-ai/dsh-system-prompt":"^0.1.0-rc.6","@deepseek-ai/dsh-user-approval":"^0.1.0-rc.6"},"peerDependencies":{"@deepseek-ai/cordis":"^4.0.1","@deepseek-ai/dsh-tools":"^0.1.0-rc.6","@deepseek-ai/dsh-session":"^0.1.0-rc.6","@deepseek-ai/dsh-invariants":"^0.1.0-rc.6"},"_npmOperationalInternal":{"tmp":"tmp/dsh-agentfuse_0.2.0_1787160601206_0.8367705882836216","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@dhms-agentfuse/dsh-agentfuse","description":"AgentFuse fail-closed pre-dispatch tool gate for DeepSeek Harness: deterministic allow/block/ask policy with durable decision evidence","version":"0.2.1","publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/MkaliezZ/dsh-agentfuse-plugin.git","directory":"packages/dsh-agentfuse"},"type":"module","main":"lib/index.js","types":"lib/index.d.ts","exports":{".":{"types":"./lib/index.d.ts","default":"./lib/index.js"},"./invariant":{"types":"./lib/invariant.d.ts","default":"./lib/invariant.js"},"./src/*":"./src/*","./cordis.patch.yml":"./cordis.patch.yml","./package.json":"./package.json"},"license":"Apache-2.0","dsh":{"bundle":{"patch":"./cordis.patch.yml"}},"dependencies":{"@dhms-agentfuse/core":"^0.2.0","@deepseek-ai/schemastery":"^3.18.1"},"peerDependencies":{"@deepseek-ai/cordis":"^4.0.1","@deepseek-ai/dsh-invariants":"^0.1.1-rc.2","@deepseek-ai/dsh-session":"^0.1.1-rc.2","@deepseek-ai/dsh-tools":"^0.1.1-rc.2"},"devDependencies":{"@deepseek-ai/cordis":"^4.0.1","@deepseek-ai/dsh-agent":"^0.1.1-rc.2","@deepseek-ai/dsh-invariants":"^0.1.1-rc.2","@deepseek-ai/dsh-llm":"^0.1.1-rc.2","@deepseek-ai/dsh-session":"^0.1.1-rc.2","@deepseek-ai/dsh-system-prompt":"^0.1.1-rc.2","@deepseek-ai/dsh-tools":"^0.1.1-rc.2","@deepseek-ai/dsh-user-approval":"^0.1.1-rc.2","@types/node":"^22.10.0","typescript":"^5.8.3","vitest":"^4.1.0"},"scripts":{"build":"tsc -p tsconfig.build.json","test":"vitest run --config vitest.config.ts","prepublishOnly":"npm run build"},"gitHead":"366d213f207a833d45669b20551a33117eaeb6e6","_id":"@dhms-agentfuse/dsh-agentfuse@0.2.1","bugs":{"url":"https://github.com/MkaliezZ/dsh-agentfuse-plugin/issues"},"homepage":"https://github.com/MkaliezZ/dsh-agentfuse-plugin#readme","_nodeVersion":"25.8.1","_npmVersion":"11.11.0","dist":{"integrity":"sha512-mjW50GUsz4TzxCvehZ7zq7p1gg7Icn31ivkhGepqdHP1vKIQ9wbV2r1j2TvCdPBPTruX7CVPynVK8sD59XUmtg==","shasum":"cefee811a8fea960b1b99d8b1b748fb376b12ab9","tarball":"https://registry.npmjs.org/@dhms-agentfuse/dsh-agentfuse/-/dsh-agentfuse-0.2.1.tgz","fileCount":8,"unpackedSize":23113,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIG/af13bP8nBPKQmVV038sieOuogdwMQeFD6DdD3zvj8AiEA4tB/eASLApHIl2lbyomEmYvck7d4KiMQlUB3OT7bwxc="}]},"_npmUser":{"name":"mkaliezz","email":"nathanzhong93@gmail.com"},"directories":{},"maintainers":[{"name":"mkaliezz","email":"nathanzhong93@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/dsh-agentfuse_0.2.1_1787513276122_0.17145962794862268"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-19T17:30:01.053Z","modified":"2026-08-23T19:27:56.450Z","0.2.0":"2026-08-19T17:30:01.366Z","0.2.1":"2026-08-23T19:27:56.286Z"},"bugs":{"url":"https://github.com/MkaliezZ/dsh-agentfuse-plugin/issues"},"license":"Apache-2.0","homepage":"https://github.com/MkaliezZ/dsh-agentfuse-plugin#readme","repository":{"type":"git","url":"git+https://github.com/MkaliezZ/dsh-agentfuse-plugin.git","directory":"packages/dsh-agentfuse"},"description":"AgentFuse fail-closed pre-dispatch tool gate for DeepSeek Harness: deterministic allow/block/ask policy with durable decision evidence","maintainers":[{"name":"mkaliezz","email":"nathanzhong93@gmail.com"}],"readme":"# dsh-agentfuse\r\n\r\n> **Status:** ALPHA · bounded conformance proof · no production-readiness claim\r\n\r\nAgentFuse is a fail-closed **pre-dispatch policy boundary** for AI agent tools,\r\nported from the DHMS AgentFuse Python project to a DeepSeek Harness (DSH) guard\r\nplugin.\r\n\r\nThis package is a thin DSH adapter over the framework-agnostic engine\r\n[`@dhms-agentfuse/core`](../core): the decision vocabulary, deterministic policy\r\nresolution, hashing, and evidence assembly all live in the core. This package\r\nowns only the DSH config schema, the `tools/pre-execute` gate, and the durable\r\n`agentfuse/decision` session event.\r\n\r\nIn the tested integrated DSH path, model-directed tool calls reach the\r\n`tools/pre-execute` waterfall. AgentFuse evaluates them against a deterministic denylist → asklist →\r\nallowlist → default policy, fails closed on `block`, defers asklisted tools to\r\nthe DSH human-approval chain, and appends a durable `agentfuse/decision`\r\nsession event for blocked calls carrying the canonical evidence — reason\r\ncode, policy id, and a canonical arguments hash, **never raw arguments**.\r\n\r\n```text\r\nAGENTFUSE_IS_A_DANGER_CLASSIFIER=false\r\nAGENTFUSE_IS_A_POLICY_AND_AUTHORIZATION_BOUNDARY=true\r\nAGENTFUSE_DECISIONS=allow|block\r\nAGENTFUSE_DEFERRALS=ask\r\nAGENTFUSE_FAILS_CLOSED=true\r\n```\r\n\r\n## What it is / is not\r\n\r\nAgentFuse owns only its deterministic `allow | block` decision and bounded\r\ndecision evidence. The adapter can return DSH's host-owned `ask` deferral; it\r\ndoes not own approval or make `ask` a third canonical AgentFuse decision. It is\r\n**not** a process sandbox, malware\r\ndetector, intrinsic danger classifier, or universal interceptor. Risk\r\nclassification, approval, dispatch, and physical execution remain the\r\nintegrating runtime's responsibility — the same boundary the Python\r\n`dhms_agentfuse` documents.\r\n\r\n## Config\r\n\r\n```yaml\r\n# cordis.yml (or a cordis.patch.yml insert)\r\n- id: agentfuse\r\n  name: '@dhms-agentfuse/dsh-agentfuse'\r\n  config:\r\n    defaultAction: block      # 'allow' | 'block' — fall-through for unlisted names\r\n    denyTools: []             # always wins\r\n    askTools: []              # defer to the DSH human-approval chain\r\n    allowTools: []            # non-empty = only these names may run\r\n    logDecisions: false       # durable evidence; needs in-repo catalog (see note below)\r\n```\r\n\r\nPolicy resolution order (fixed, deterministic):\r\n\r\n1. `denyTools` match → `block` (`explicit_denylist`)\r\n2. `askTools` match → `ask` (`requires_approval`)\r\n3. configured `allowTools` without the name → `block` (`not_allowlisted`)\r\n4. configured `allowTools` containing the name → `allow` (`allowed`)\r\n5. `defaultAction` → `allow`/`block` (`allowed` / `policy_denied`)\r\n\r\n## Approval integration\r\n\r\nAn `askTools` match returns `{ kind: 'ask' }` from the `tools/pre-execute`\r\nwaterfall. The DSH tool registry routes it through the approval service\r\n(`@deepseek-ai/dsh-user-approval`), which prompts the composed answerers (the\r\nWeb GUI approval card, CLI answerers, …) and records the `approval/asked` +\r\n`approval/decided` audit pair on the session log.\r\n\r\nOutcomes:\r\n\r\n- `allowed-once` — the tool runs;\r\n- `rejected` / `cancelled` / `unavailable` — the tool is denied, and the model\r\n  sees a distinct reason for each (a human \"no\" reads differently from a\r\n  missing approval channel);\r\n- no approval service composed, no answerer, or a `never` approval policy —\r\n  every ask **fails closed** to deny.\r\n\r\nAgentFuse emits **no** `agentfuse/decision` evidence for asks: a deferral is\r\nnot a final decision, and the approval layer already records the complete\r\nask/decide chain, so the two audits never overlap.\r\n\r\n## Regression locking with dsh-policy-test\r\n\r\nThe production policy is also a CI artifact. The\r\n[`dsh-policy-test`](https://github.com/MkaliezZ/dsh-policy-test) evaluator\r\nadapter compiles the **same** `PolicyConfig` through `@dhms-agentfuse/core` and runs\r\na fixture table against it — so configuration drift (a dropped allowlist, a\r\nflipped default) turns red in CI instead of silently becoming an unexpected\r\n`ALLOW` in production. See the\r\n[joint example](https://github.com/MkaliezZ/dsh-policy-test/tree/main/examples/agentfuse).\r\n\r\n## Cross-adapter conformance\r\n\r\nThe v3.6.2 conformance test consumes an exact snapshot of the canonical,\r\nprovider-neutral fixture vocabulary from `MkaliezZ/dhms-engine`. Provenance is\r\nrecorded in\r\n[`conformance/cross_adapter_v3_6_2/provenance.json`](conformance/cross_adapter_v3_6_2/provenance.json),\r\nincluding source commit `3ed2ccd0aadfcc61ad48ac5a49a54632f7911a91` and fixture SHA-256\r\n`1f66c9e20ff28ebeeae128b8aaf38a5b251582496a753acded9530b819056d7b`.\r\n\r\nThe tests overlay this package and `@dhms-agentfuse/core` onto DeepSeek Harness\r\ncommit `99f6f02fecdb7dff40c3fbc9470f5907c29f74ca` (`0.1.0-rc.7`) and exercise\r\nthe real `Context`, `SystemPrompt`, `ToolRuntime`, `tools/pre-execute`,\r\n`tools/execute`, and `tools/result` path. The deterministic result is 11 PASS,\r\n0 FAIL, and 3 N/A across 14 canonical cases.\r\n\r\nThe N/A cases are bounded:\r\n\r\n- policy callback exception and invalid callback output: the current DSH core\r\n  exposes static configuration, not a custom policy callback surface;\r\n- sync/async parity: DSH `ToolRuntime` exposes one asynchronous execution path,\r\n  not separate sync and async APIs.\r\n\r\nDSH `ask` remains a host approval deferral and does not appear in the canonical\r\n`allow | block` fixtures. Host `isError` materialization for a denied call also\r\ndoes not rewrite the earlier policy fact: it remains block/not-executed, not an\r\nexecuted handler failure. These tests prove only the pinned integrated path;\r\nthey do not prove universal DSH interception, global exactly-once execution,\r\nor official DeepSeek certification.\r\n\r\n## Install\r\n\r\n### As a bundle\r\n\r\nThe package declares itself as a DSH bundle (`dsh.bundle.patch` →\r\n`cordis.patch.yml`). Reference it from a profile bundle list or apply the patch\r\nrow directly; see the DSH [profiles and bundles\r\narchitecture](https://github.com/deepseek-ai/deepseek-harness/blob/master/docs/architecture.md#profiles-and-bundles).\r\n\r\n### Into the DSH repo (PR path)\r\n\r\nThis package is structured to drop into the DeepSeek Harness monorepo at\r\n`packages/guard/agentfuse/` unchanged, with the core vendored at\r\n`vendor/agentfuse-core/` (the `vendor/*` workspace glob links it automatically,\r\nso the `@dhms-agentfuse/core` dependency resolves as-is). That is the supported\r\nbuild path: DSH packages are not published to npm, so the `workspace:^`\r\ndependencies resolve only inside the monorepo.\r\n\r\n> **Durable event catalog:** the `agentfuse/decision` session event is a new\r\n> `SessionEventMap` member. DSH's persistence read path refuses unknown event\r\n> types unless they are registered in the generated\r\n> `KNOWN_SESSION_EVENT_TYPES` catalog. After the package lands in-repo, run\r\n> `pnpm run gen-persistence-catalog` so the event is recognized. Until then the\r\n> gate still blocks correctly; only the durable decision event is not\r\n> reconstructable on reload. For this reason `logDecisions` defaults to\r\n> `false` — leave it off for standalone installs and enable it only after the\r\n> package lands in-repo and the catalog is regenerated.\r\n\r\n## API\r\n\r\nThe complete core vocabulary (`evaluate`, `resolvePolicy`, `buildDecision`,\r\n`compileRules`, `argumentsHash`, `policyHash`, and all decision/evidence types)\r\nis re-exported from `@dhms-agentfuse/core` — see its\r\n[README](../core/README.md). This package adds only:\r\n\r\n- `apply(ctx, config)` — the Cordis plugin entry: installs the pre-execute gate.\r\n- `Config` / `Config` schema — the core policy config plus `logDecisions`.\r\n- `agentfuse/decision` — the durable session event type.\r\n\r\n## Relationship to DHMS\r\n\r\nThis is a faithful port of the DHMS AgentFuse decision engine and\r\n`agentfuse-evidence-schema-v0.1` from\r\n[`MkaliezZ/dhms-engine`](https://github.com/MkaliezZ/dhms-engine). Decision and\r\nexecution remain separate lifecycle facts; a blocked call is recorded as a\r\ncompleted policy decision with non-execution evidence, not as a failed tool\r\nexecution.\r\n\r\n## License\r\n\r\nApache-2.0. See [LICENSE](../../LICENSE).\r\n","readmeFilename":"README.md"}