# DSH 原生评测工作台

> 完整介绍 DSH Plugin 的 19 个工具、Workbench、Host 服务、受审动作与当前限制。

---

LLMS 索引： [llms.txt](/harbor-self-evolving/zh/llms.txt)

---

npm 包 `dsh-harbor-evolution` 不只是工具注册表，它承担五层职责：

1. **安装生命周期**：配置选定 DSH profile，安装 Python Adapter，暴露内置 Skill，并要求重启。
2. **Agent 编排**：注册 19 个带 typed boundary 与批准语义的严格工具。
3. **原生 Web 体验**：Workbench、Historical 启动器、Context、Evidence、Artifact、operation 与 Settings。
4. **Host 服务**：限量读取 project/job、选择 Session、代理模型调用、协调后台操作。
5. **信任边界**：脱敏、same-origin 浏览器检查、显式确认和不可信证据 envelope。

![DSH Plugin 职责层](https://istarwyh.github.io/harbor-self-evolving/images/diagrams/plugin-layers.svg "当前契约 · 解释图")

## 工具面 {#tools}

Plugin 注册 **19 个工具**。10 个 mutation 工具需要 DSH 一次性批准；9 个为只读或内存操作。逐工具契约见[工具参考](https://istarwyh.github.io/harbor-self-evolving/zh/docs/reference/tools/)。

## Workbench {#workbench}

Web 体验把严格流水线带进 DSH：

- Dashboard 与 Job/Trial 状态；
- Pipeline stage 与 preflight；
- Context、可比 baseline 与 Gate readiness；
- Trial 输出、criterion evidence 与 artifact；
- Historical Session 选择与披露；
- 受审动作草稿、确定性 preflight 与显式确认；
- 后台 operation 与恢复状态；
- Settings、执行环境和版本 UI。

![合成 Harbor Workbench](https://istarwyh.github.io/harbor-self-evolving/images/screenshots/workbench-desktop.png "v0.9.5 · 经过裁切的 synthetic component fixture · 非真实 Host/model/evaluation")

## 上下文与受审动作 {#context}

普通聊天仍是普通聊天。`@harbor` 页面上下文解析短期、owner-bound 引用；typed Evidence ref 再强制 Workspace → Job → Trial → Criterion → Evidence 祖先关系。Artifact 文本始终是不可信数据。

Ask AI 可以准备 proposal draft，但不能写文件、启动 Job、修改 Evaluator、运行 Gate 或部署。用户必须另行检查确定性 preflight，并确认精确动作。

## 当前限制 {#limits}

0.9.7 已接受 Candidate Context v3，并按 protocol 显式识别 Historical Context v2。Candidate Compare/Gate 仍要求可比 baseline、有效 Artifact、promotion-eligible mode 与 policy；支持该流程不代表一定返回 `PROMOTE`。

> [!WARNING]
> Same-origin 检查是浏览器 CSRF 防线，不是 caller authentication。Historical Web operation 锁为进程内状态，而部分 durable `@harbor` snapshot 可超过内存 TTL；retention 与恢复能力因 operation 而异。

早期未打 tag 的一键更新预览已在发布前撤回。0.9.7 只做版本检查，并且仅在完整安装身份可用时展示精确可复制的 setup 命令；浏览器不会执行 registry 包。
