DSH Hub
dsh-jev-interceptor cover

AskTheWay/dsh-jev-interceptor

dsh-jev-interceptor

BundleWorkflow21 GitHub stars· updated 2026-09-25

dsh-jev-interceptor is a community DeepSeek Harness plugin. Read the repository README before installing.

Install

npx @deepseek-ai/dsh plugin --profile <name> add dsh-jev-interceptor

Restart `dsh web` after install. Bundle APIs can change during the developer preview.

README badge

dsh-jev-interceptor DSH Hub badge
[![DSH Hub](https://dshhub.dev/badge/dsh-jev-interceptor.svg)](https://dshhub.dev/plugins/dsh-jev-interceptor)

Paste this into your README. The star count updates with every catalog sync.

From the README

Excerpt from AskTheWay/dsh-jev-interceptor, cleaned of badges and images.

dsh-jev-interceptor

⚡ Millisecond judgement for every tool call and every recalled message — for about two millionths of a dollar each.

Your agent's most expensive habits: asking a poetry-writing LLM yes/no questions, and amputating your context by age. This plugin wires Jev — the non-generative "System One" model that broke everyone's feed — into the decision points of DeepSeek Harness where an LLM is overkill and rules are blind.

English | 中文

What it does, in one breath: before a tool call runs, Jev classifies its risk, irreversibility, task-fit, and injection-suspicion in one ~$0.00002 request — confident high-risk calls get denied, medium ones escalate to a human, and clearly-granted reversible ones stop wasting your clicks on approval dialogs. And when an @session snapshot gets injected, Jev scores every message's value for the citing task so the error traceback survives the byte budget instead of the oldest small talk. Every doubt, every timeout, every missing key degrades to stock dsh behavior. Nothing to configure away, nothing that can widen a permission.

Why this exists

dsh ships zero per-call risk classification — the pre-execute waterfall's default is a bare allow. Its only built-in precedent, experimental/auto-review, does the classification with a generative LLM: one full model request per tool call, temperature 0, hand-rolled JSON text protocol, self-described as slow, expensive, and experimental. That's a System-2 scribe doing a System-1 reflex's job:

auto-review (generative LLM)dsh-jev-interceptor (Jev)
Decision shapeemits JSON token-by-token, then parses it and praystyped choice/noul answers — type errors are structurally impossible
Cost per callone full LLM request~$0.00002 (measured: 501 input tokens)
Latencyseconds~100ms provider-side (TypeSafe-reported p50); ~1s end-to-end from outside US-West
Uncertaintyburied in proseper-question probability distributions + calibrated confidence
Failure pathparse fallback → denylow confidence → next() — it never guesses

Jev's maker TypeSafe reports up to 200× faster / 400× cheaper than LLMs on classification workflows — and this plugin is that number, landed in a real agent harness, with receipts in /jev-stats.

We believe this is the first System-1 decision plugin in the dsh ecosystem. The full map of where decision models fit in dsh — this plugin's two hooks plus eleven more verified hooks (semantic model routing, context-retention scoring, image-offload pre-planning, worker-report verification...) — is in docs/jev-usage-points.md.

The FIFO pain point nobody talks about

When you @-mention a past session in dsh, the harness injects a bounded snapshot of it — and when that snapshot exceeds its byte budget, it drops messages oldest-first. Pure FIFO. Zero semantics. The bug report you pasted at the top of the session and the three-line question that started it all? Dropped first. The "thanks!" and "ok, continue"? Kept — they were newer.

…

Related plugins