buildTelemetryPayload read the two reported files independently, so a dsh-sdk command mistakenly run in an arbitrary non-SDK directory (no cordis.yml, e.g. any unrelated repo) still uploaded that directory's package.json — dependency names and metadata of a project that never opted into the SDK toolchain. Gate the manifest on cordis.yml presence: without the config the directory is not an SDK project and its manifest is not ours to report. Consent semantics are unchanged.
SDK packages
Developer tooling for creating, editing, building, and running DeepSeek Harness projects.
The feature RFC owns the developer workflow; the architecture RFC owns the package and project-editing boundaries.
| Package | Role |
|---|---|
helper |
Project aggregate, edit session, builtin features, project documents, templates, package managers, and prompt abstraction |
scripts |
The dsh-sdk launcher: start, dev, build, and interactive config |
create-sdk |
The npm create @deepseek-ai/sdk initializer |
@deepseek-ai/create-sdk is the one package-name exception to the repository's @deepseek-ai/dsh-* rule: npm's scoped initializer convention requires that name for npm create @deepseek-ai/sdk.
Generated projects keep cordis.yml as the only runtime plugin tree. dsh-sdk dev adds TypeScript and local-workspace resolution around that same file; it does not create a development-only config.