Machine-produced by `pnpm run rescope-vendor --apply` plus the regeneration it prints: `pnpm install` for the lockfile, `pnpm run gen-third-party-notices`, `verify-translation-pairing --write` for the touched bilingual pairs, `gen-doc-graphs`, and one typert snapshot whose ids embed character offsets. `pnpm run rescope-vendor --check` verifies the result. Renames nine vendored packages (cordis, cosmokit, schemastery and the six @cordisjs plugins) and every reference that resolves them: manifest names and dependency keys, module specifiers including declare-module merges, cordis.yml plugin names, tsconfig paths, every Markdown fence, and `docs/` prose. Directory names, upstream versions, and dependency ranges are unchanged, so vendor/README.md still reads as an upstream snapshot; its manifest table gains an upstream-name column so THIRD_PARTY_NOTICES keeps MIT attribution pointed at each fork's origin. The tutorial tier follows the rename end to end: its yaml fences named plugins the Loader can no longer resolve, its `ts ignore-check` fences disagreed with the compiled fences beside them, and its prose quoted both. The contracts that told readers to keep upstream names — the root convention and the vendoring cookbook's tree comment and manifest invariant — now say to rescope instead. Two rules read `@deepseek-ai/` as "another workspace plugin": the client bundle purity gate now names the vendored libraries a browser bundle inlines, and the files where a bare `cordis` is an agent-preset id keep that product data.
jsonrpc-agent
English | 中文
The unattended coding-agent composition for the Python SDK's bundled JSON-RPC runtime. It intentionally loads no terminal UI, console logger, approval surface, or user-interaction tool because stdout belongs to the SDK protocol and turns are driven by the SDK.
The model-facing tools are:
bash, foreground onlyread,write, andeditsubagent, using one foreground in-process spawn providertodo_write
The surrounding runtime also loads JSONL session persistence and automatic context compaction. maxTokensAsSuccess keeps a token-limited model turn as an accepted evaluation result while preserving its max-tokens reason.
Runtime environment
| Variable | Purpose |
|---|---|
DEEPSEEK_API_KEY |
Credential passed to the OpenAI-compatible host endpoint |
DEEPSEEK_BASE_URL |
Host endpoint used by dsh-llm-deepseek |
DSH_CWD |
Agent workspace for bash and filesystem tools |
DSH_MAX_TOKENS_AS_SUCCESS |
true (default) accepts token-limited results; false reports them as errors |
DSH_SESSION_ROOT |
JSONL trajectory directory |
DSH_SYSTEM_PROMPT |
Deployment-provided coding persona |
Pass the config path through the Python SDK's cordis option or DSH_CORDIS_CONFIG. The bundled executable already carries every plugin named by this file; the target machine does not need Node.js.
Persistent tools variant
persistent-tools.cordis.yml is a minimal runnable variant whose model-facing surface is exactly:
- owner-scoped persistent
bash str_replace_editorwithview,create,str_replace, andinsert
It composes the local PTY, filesystem intent policy, and session sandbox policy.