Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/cpj-dev/dsh-plugin-cc/dsh-delegate-runtimenpx skills add cpj-dev/dsh-plugin-cc --skill dsh-delegate-runtimegit clone --depth 1 https://github.com/cpj-dev/dsh-plugin-ccWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00047 | $0.00881 |
| Opus 5 | $0.00023 | $0.00441 |
| Sonnet 5 | $0.00009 | $0.00176 |
| Haiku 4.5 | $0.00005 | $0.00088 |
Grade A, and why
dsh-delegate-runtime scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 47 lines — stays where its author put it; the contents beside it link to each section on GitHub.
dsh bridge runtime contract
Every DeepSeek Harness interaction goes through one script:
node "${CLAUDE_PLUGIN_ROOT}/scripts/dsh-bridge.mjs" <subcommand> [flags] [text]
stdout is the user-facing result; render it verbatim. A nonzero exit means the run failed and stderr carries the reason.
Subcommands
| Subcommand | Purpose | Key flags |
|---|---|---|
check |
readiness probe | --json |
setup |
install the pinned npm CLI (or --harness <built-checkout>) and create/verify the multi-turn cc profile |
--harness <path>, --mode, --json |
review |
read-only code review | --base <ref>, --scope, --model, --effort, --mode, --background |
critique |
structured adversarial critique | same as review |
run |
task execution | --write, --session, --resume, --fresh, --model, --effort, --mode, --background, --prompt-file |
run-resume-candidate |
is a resumable dsh session available? | --json |
import |
weak-import this conversation into a resumable session | --source <jsonl> |
runs |
list runs / one run's status | [run-id], --all |
show |
stored result of a finished run | [run-id] |
stop |
kill a run's process tree / the broker | [run-id], --broker |
Facts that shape correct usage
- Sandbox: default runs are read-only;
--writegrants workspace-write. There is no mid-run approval — permissions are decided before launch. - Fresh runs are one-shot headless dsh sessions and are NOT resumable. Only
--session,--resume, andimport(broker paths) record resumable session ids. --model/--effortwork on one-shot runs; a--resumekeeps the broker's startup model. Plugin defaults when omitted: modeldeepseek-v4-pro, effortmax(one-shot and broker alike).- Agent mode defaults to
standard(full toolset from request #1, no overlay).--mode minimallocks bash + str_replace_editor for the whole run;--mode anchored-standardshows that pair until this session records a tool call or assistant reply, then restores the full catalog.DSH_CC_MODEand the persisted/dsh:setup --modedefault sit between flag and built-in. A live broker keeps its startup mode — a--sessionrun resolving a different mode errors and names/dsh:stop --broker. --backgroundreturns immediately with a run id; the actual work continues in a detached worker. Pollruns <id>, fetchshow <id>.stopkills processes; a mid-turn broker stop discards all in-memory dsh sessions for the workspace.- Environment:
DSH_BINARYoverrides the dsh executable;DSH_CC_SESSION_ID/DSH_CC_TRANSCRIPT_PATHare exported by the SessionStart hook — never set them manually.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 47 lines · 47 tokens per session scan A 5c94d91d25d4
dsh-delegate-runtime is a skill published in the GitHub repository cpj-dev/dsh-plugin-cc (106 stars, last pushed 5d ago), licensed MIT. It adds 47 tokens to every session and 881 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
odai
Skill "odai" from orziz/odai, covering 精神内核, 当前判断, 按表现分配支撑, 共同行动边界 and 完成.
cordis-plugin-development
Create, modify, debug, or extend dynamic Cordis Plugins, including Host Services and Events, Client Slot and theme UI, Package-private Client-to-Host calls, dynamic Tools, version updates, approval failures, and runtime diagnostics. Use this Skill to route a user request to the correct platform and Inspect Provider…
editing-cordis-compositions
Use when creating, changing, or validating a Cordis composition for this harness — writing or editing an agent preset, adding or removing a plugin row, deciding whether something belongs to the host composition or to one session, checking whether a preset you authored actually mounts, or diagnosing a row that mounted…
dsh-web-community-plugin-developer
Develop a DSH community plugin and register it in the dsh-web Community Plugins index — author the plugin in the contributor's own repository following the official cordis bundle standard, add its entry to packages/dsh-community-plugins/community.json, regenerate the index with scripts/community-index, rebuild and…
submit-dsh-plugin
验证并提交 DeepSeek Harness 插件到 imsai-sh/awesome-deepseek-harness-plugins 社区目录。适用于插件作者要求收录、发布或提交自己的插件,创建目录 JSON,修复目录提交 PR,或者发起合规 PR。检查公开仓库、dsh-plugin topic、dsh.bundle.patch、作者测试证据、双语元数据和单文件差异,并在获得授权后执行 fork、push 和创建 PR。.
ribao
日报、周报、工作总结、状态更新:基于可核证事实形成完整汇报。用户要求汇报一段时期的工作、沿用既有汇报模板、整理进展与风险,或 odai 判断专业汇报工艺会改善结果时使用。.