dsh-rerun-grader-invariant
v0.1.2
Published
Grader provider asserting workspace and session-log invariants an attempt must not violate
Maintainers
Readme
dsh-rerun-grader-invariant
Grader provider asserting invariants an attempt must not violate, over the final workspace diff and the session log.
These are the rules that make a passing test suite meaningful. An agent that
makes node test.mjs exit zero by deleting the assertion has satisfied the
command grader and failed the task, and only a rule that reads what it actually
did can tell the difference.
Shipped rules: no-write-outside, no-test-deletion, no-git-write,
no-secret-echo, no-unresolved-tool-calls, no-approval-stall.
graders:
- kind: invariant
rules: [no-test-deletion, no-git-write, no-unresolved-tool-calls]Every rule scores from stored artifacts alone, so a rule written after an incident can be applied retroactively to find out how long the behavior had been there.
Model Experience
None. This package never contributes to a model request: it runs in the orchestrator process, and the model calls it cares about happen inside a separate attempt subprocess running a different build of DSH entirely.
KV Cache effect
None; it neither assembles nor sends a provider request.
Known Limitations and Deferred Work
- Rules are name-based over a diff, so a mutation made through a shell heredoc is seen, but one made through a tool that does not appear in the diff is not.
no-secret-echomatches a fixed set of credential shapes. It catches common provider key formats and nothing else; it is a smoke alarm, not a scanner.- Rules are not configurable per rule beyond their arguments. A deployment needing different semantics writes its own grader.
