dsh-plan-adversarial
gendui123/dsh-plan-adversarial
모든 플랜에 대한 명령 트리거 적대적 검토(quant 전용 아님). /plan-adversarial <plan>: 두 개의 독립적인 서브에이전트(red=공격, blue=방어)를 파생시키고, th 없이 합의 플랜에 수렴하도록 요구하는 게이트를 활성화
설치
dsh plugin --profile web add github:gendui123/dsh-plan-adversarialREADME
dsh-plan-adversarial
Command-triggered red/blue adversarial review for ANY plan (domain-agnostic), for DeepSeek Harness. Unlike dsh-adversarial-review (which is quant-specific: design/backtest/report), this plugin reviews any plan via a general-purpose red/blue debate that self-converges — no third-party referee.
Trigger
/plan-adversarial <被审plan/内容>
The command appears in the command bar (slash-menu) automatically once registered (zero UI-source changes). It arms a gate for the calling agent.
Mechanism
/plan-adversarial <brief>arms the gate and stores the brief.- The gate injects a red/blue adversarial task into the agent's next step:
- 红队 (red / attacker): find holes — unclear goal, suspicious implicit assumptions, counterexamples/boundaries/failure conditions, broken evidence chain, poor executability, missing rollback. Never defend.
- 蓝队 (blue / defender): defend the plan, rebut red point by point, and repair/harden it against every valid attack.
- The two converge directly (multi-round). No third-party referee — convergence is reached by red and blue themselves, not adjudicated by the main agent. The main agent only orchestrates (dispatches, transcribes disagreement, summarizes the consensus) and never judges win/loss.
- Gate enforcement: while pending, every non-investigative tool call is denied (investigation, subagent-spawning, and asking the user remain allowed). The gate lifts only when the reply text contains a
🛡️ 对抗结果marker that also has a结论:line. - Anti-loop:
maxRounds(default 2) caps adversarial rounds per trigger; past the cap the gate force-releases and the unresolved disagreements must be reported honestly. A user interjection resets the gate.
Install (this workspace)
Registered in dsh-home/profiles/web/package.json (file: dependency + dsh.profile.bundles). cordis.patch.yml mounts the plugin row via dsh.bundle.patch. After adding a new bundle, run pnpm install in the profile dir, then restart the backend.
Config (cordis.patch.yml)
- insert:
- id: plan-adversarial
name: dsh-plan-adversarial
config:
enabled: true
maxRounds: 2
enabled: master switchmaxRounds: adversarial-round cap per trigger (anti-loop)allowlist: extra tools allowed while pending (default includes subagent/subagent_fork/workflow/explore and all read-only investigation)conclusionPatterns: extra phrases that keep the gate armed
Fail-safe
apply wraps applyInner in try/catch, so a bug here disables only this plugin (console.error) and never prevents the harness from booting.
Relationship to dsh-adversarial-review
dsh-adversarial-review: quant-specific red-team gate (design/backtest/report), single reviewer, referee-by-protocol.dsh-plan-adversarial: generic plan review, red + blue converge with no referee, command-triggered.