dsh-orchestrator
安全与治理 活跃维护

dsh-orchestrator

softspark/dsh-orchestrator

支持Claude Code与GitHub Copilot的Gemini原生订阅一键调度,无需额外配置登录凭证,可直接复用各平台现有订阅权限完成跨模型任务派发,降低工具切换成本。

0
Stars 标星
0
Forks 分支
0
Watchers 关注
1
Open Issues
JavaScript
主要语言
Apache-2.0
开源协议
252 KB
仓库大小
18 天前
最后推送
一键安装扩展 / 插件指令
dsh plugin --profile web add github:softspark/dsh-orchestrator
git clone https://github.com/softspark/dsh-orchestrator.git
git clone git@github.com:softspark/dsh-orchestrator.git
README.md main

dsh-orchestrator

CI
License: Apache-2.0
DSH community plugin

@softspark/dsh-orchestrator is a config-only DeepSeek Harness bundle and agent preset. It lets one DSH parent delegate standalone tasks to Claude Code through its native Max/Pro login and to Gemini through the official GitHub Copilot CLI ACP server.

The package does not implement OAuth, read credential files, accept provider API keys, or call model APIs directly. It is an independently maintained SoftSpark community integration. It is unofficial and is not affiliated with or endorsed by Anthropic, DeepSeek, GitHub, Google, or Microsoft.

Status

Version 1.0.1 is the current patch release and targets DSH 0.1.1-rc.2.

Verified locally: 14/14 tests, 100 percent line coverage, 93.75 percent branch coverage, zero source or dependency findings, 459 verified registry signatures, and 58 attestations. The network-free suite composes this patch through DSH 0.1.1-rc.2 and verifies the complete Codex override. Version 1.0.1 is published with SLSA provenance; fresh isolated pre-tag and exact-registry post-release smokes completed both subagent_claude_code and subagent_gemini_copilot marker roundtrips through native subscription logins on 2026-09-01.

Requirements

  • Node.js 22.19.0 or newer.
  • npm for repository verification.
  • pnpm for the DSH profile plugin manager.
  • DeepSeek Harness 0.1.1-rc.2.
  • @softspark/dsh-codex@1.0.0 installed before this bundle when Codex is the parent.
  • Claude Code authenticated through claude auth login.
  • GitHub Copilot CLI 1.0.80 or a separately reviewed compatible version, authenticated through copilot login with an active Copilot plan.

No Anthropic, DeepSeek, Google, Gemini, or GitHub API key is required by this package. GitHub Copilot usage consumes the plan's AI credits.

Architecture

DSH parent session
    |
    +-- subagent_claude_code --> official DSH Claude provider --> Claude Code native login
    |
    +-- subagent_gemini_copilot --> official GitHub Copilot ACP --> Gemini 3.6 Flash

cordis.patch.yml enables the opt-in dynamic-tool bridge on the existing
llm-codex row, then registers dormant Claude and Copilot ACP host-plane
providers. agent-presets/softspark-orchestrator/agent.cordis.yml derives from
the DSH standard preset and grants only selected sessions their static
delegation tools. Installing the bundle starts no vendor process.

DSH applies bundle patches in profile order. Install dsh-codex before
dsh-orchestrator. The Codex provider remains safe with dynamic tools disabled
when it is installed without this orchestration bundle.

Gemini route

Gemini CLI stopped serving individual Google AI Pro/Ultra and free accounts on 2026-06-18. This package still registers no Google provider and does not use Antigravity, Google OAuth, Google AI Pro/Ultra, or Gemini API keys. Gemini runs through GitHub Copilot CLI's official ACP server, using GitHub authentication, GitHub plan policy, and GitHub AI credits.

Source verification

git clone https://github.com/softspark/dsh-orchestrator.git
cd dsh-orchestrator
npm ci --ignore-scripts
npm run verify
npm run lint
npm run test:coverage
npm run audit
npm run audit:permissions
npm run audit:dependencies
npm run audit:signatures
npm run package:check

Local installation

Use an isolated DSH_HOME before modifying a regular profile.

dsh plugin --profile web add @softspark/dsh-codex@1.0.0 --save-exact
dsh plugin --profile web add "file:$(pwd)"

PRESET_ROOT="${DSH_HOME:-$HOME/.dsh}/.agent-presets"
test ! -e "$PRESET_ROOT/softspark-orchestrator"
mkdir -p "$PRESET_ROOT"
cp -R agent-presets/softspark-orchestrator "$PRESET_ROOT/softspark-orchestrator"

Restart DSH, create a new session, and select SoftSpark Orchestrator. Existing sessions keep the preset generation with which they started.

Install a published release

Install the exact reviewed version and copy its preset into the profile's user preset root:

dsh plugin --profile web add @softspark/dsh-codex@1.0.0 --save-exact
dsh plugin --profile web add @softspark/dsh-orchestrator@1.0.1 --save-exact

DSH_ROOT="${DSH_HOME:-$HOME/.dsh}"
PROFILE_ROOT="$DSH_ROOT/profiles/web"
PRESET_ROOT="$DSH_ROOT/.agent-presets"
test ! -e "$PRESET_ROOT/softspark-orchestrator"
mkdir -p "$PRESET_ROOT"
cp -R "$PROFILE_ROOT/node_modules/@softspark/dsh-orchestrator/agent-presets/softspark-orchestrator" \
  "$PRESET_ROOT/softspark-orchestrator"

DSH 0.1.1-rc.2 discovers user presets only from configured roots and $DSH_HOME/.agent-presets; installing a bundle does not automatically add its embedded preset directory. Restart DSH, then select SoftSpark Orchestrator for a new session.

If dsh-orchestrator loads without an earlier llm-codex row, DSH logs
patch: entry "llm-codex" not found and skips the override. It does not insert
or own a Codex provider. Install the exact dsh-codex package first and restart
the profile.

Configuration

Component Setting Value
Codex parent provider row existing llm-codex from @softspark/dsh-codex@1.0.0
Codex parent sandbox and approval workspace-write, untrusted
Codex parent API-key auth false
Codex parent dynamic tools true only in this later bundle layer
Codex parent request, turn, and tool timeouts 30000, 600000, 600000 ms
Claude provider registry name claude-code
Claude provider permission mode dontAsk
Claude provider explicit environment {}
Claude tool background mode one-shot
Claude tool depth provider-managed
Copilot provider command copilot --acp --stdio
Copilot provider model gemini-3.6-flash
Copilot provider permissions reject, no available tools
Copilot provider session AI credit cap 30
Copilot tool background mode one-shot
Copilot tool depth provider-managed

The optional subagent_codex row remains disabled because Codex is the intended parent provider. The orchestration override repeats the complete intended static dsh-codex config because DSH replaces a targeted row's config rather than deep-merging it. DSH scrubs credential-shaped ambient variables before spawning children. Native vendor settings and account state remain authoritative.

Security boundaries

  • No provider credential input or custom OAuth.
  • Dynamic-tool execution is enabled only when this bundle follows the exact dsh-codex layer.
  • No npm lifecycle scripts.
  • Claude denies operations that native policy has not already authorized.
  • Copilot receives no tools, rejects permission requests, disables remote export/control, built-in MCP servers, custom instructions, and auto-update.
  • Each delegation receives a standalone task and workspace cwd, not parent conversation history.
  • Child effects completed before cancellation are not rolled back.
  • Prompts and workspace content selected by a child may leave the computer through that vendor CLI.

Report vulnerabilities privately through SECURITY.md.

Documentation

Document Purpose
Architecture Planes, request flow, and scope limits
Configuration Exact providers and tool bindings
Security Credential and permission boundaries
Setup Native login and isolated installation
Common issues Login, Google compatibility, and tool discovery failures
Copilot Gemini ADR Terms-safe protocol, model, permissions, and upstream artifact risk
Codex dynamic-tools ADR Bundle ownership, ordering, and bridge activation decision
Release SOP Versioned publication workflow

License

Apache-2.0. See LICENSE and NOTICE.