At a glance
What it does
A bounded engineering-orchestration plugin for DeepSeek Harness with planning, execution, evaluation, and recovery roles.
Web Profile
Tested with @deepseek-ai/dsh 0.1.5-rc.2; Node.js >=22.19.0
Evidence-verified
Checked Sep 13, 2026, 2:15 PM UTC
Code-evidenced contributions
What it adds to DSH
Starts, resumes, inspects, stops, or diagnoses a bounded engineering run.
Mechanism evidence ↗Adds web controls for Commander and Watchdog model routes while the Executor follows the session model.
Mechanism evidence ↗Before you choose it
Orbit adds an OrbitService and the orbit_controller tool to DeepSeek Harness. It supervises a goal through a deterministic PLAN → EXECUTE → EVALUATE flow, with bounded corrections and recovery; cx_controller remains a legacy alias.
Best for
DeepSeek Harness users who want a structured, resumable way to run multi-step engineering goals rather than an open-ended agent loop.
Common tasks
- Run a constrained engineering goal with an approved loop budget and hard workspace constraints.
- Resume an interrupted Orbit run from its persisted state.
- Check a run's phase, plan, remaining budget, or latest error with the status action.
- Use browser-capable plan steps when a separate browser plugin provides agent_browser.
Permissions and data
Orbit coordinates DSH subagents and persists execution state in the project workspace.
Permissions- Commander and Watchdog use read-only tool allowlists.
- Executor uses the configured writer allowlist.
- Browser tools are added only to steps declaring browser capability.
- Durable run state is stored at <project>/.cx/state.json.
- Model routes for active runs are frozen into state.routes.
- Uses the DeepSeek Harness model routes configured by the user.
- Optional browser capability requires a separate plugin that registers agent_browser.
- No credentials are included in the package; configure provider routes and credentials in your own DSH environment.
Limitations
- The supplied evidence describes testing with DSH 0.1.5-rc.2 and does not establish compatibility with other Harness versions.
- The npm package version was not found; use the verified Git bundle path.
- Browser steps cannot run unless agent_browser is supplied by a separate browser plugin.
- This is a community plugin and is not affiliated with or endorsed by DeepSeek.
What DSHub checked
- The pinned repository contains a structure-verified DSH bundle for @kasenri/dsh-orbit 0.5.0.
- The bundle patch inserts the dsh-orbit plugin.
- The package declares Node.js >=22.19.0 and required DSH peer dependencies.
What DSHub did not check
- Installation was not executed during this curation.
- Runtime behavior, model-provider configuration, and recovery behavior were not independently tested.
Pinned install
Install Orbit for DeepSeek Harness
This plugin bundle does not have a DSH Plugin install action. Use its source documentation for the delivery method.
Maintainer source
Project README
@kasenri/dsh-orbit
This repository is an installable release mirror for @kasenri/dsh-orbit 0.5.0. Canonical source: https://github.com/KasenRi/dsh-orbit-browser-plugins/tree/main/packages/orbit Do not develop features here; publish changes from the canonical source monorepo. Community plugin for DeepSeek Harness (DSH). Not affiliated with or endorsed by DeepSeek.
Orbit — Deterministic Engineering Orchestration for DeepSeek Harness
Orbit is a deterministic engineering orchestration runtime for DSH, implemented as a Cordis plugin:
- an
OrbitServiceonctx.orbit - a model-facing
orbit_controllertool (cx_controllerremains a legacy alias) - recoverable tool guards
Goal
│
▼
OrbitService
└─ Deterministic Supervisor
├─ Commander (plan / step & final evaluation / strategy reconsider)
├─ Executor (one engineering step at a time)
└─ Smart Watchdog (runtime diagnosis and recovery)
Every child role runs on DSH's native ctx.subagents service; durable state
lives in <project>/.cx/state.json.
Orbit is a bounded, self-converging engineering execution track:
PLAN → EXECUTE → EVALUATE → CORRECT / RECOVER → SUCCESS
It is not a timer loop, an infinite auto-continue, a pure reviewer, a pure planner, or an agent swarm. It is a deterministic supervisor plus Commander, Executor, Smart Watchdog, durable state and bounded recovery.
Requirements
| Component | Tested with |
|---|---|
@deepseek-ai/dsh |
0.1.5-rc.2 |
@deepseek-ai/cordis |
4.0.2 |
| Node.js | >= 22.19.0 |
Requires the DSH base services: agents, subagents, tools, sessions
(the standard/web profile provides them).
Install
Install the current stable Git source so DSH can compare the locked commit with repository HEAD:
dsh plugin --profile web add github:KasenRi/dsh-orbit
The canonical source monorepo also keeps versioned GitHub Release tarballs for manual or offline installation.
Usage
The orbit_controller tool drives the run:
| Action | Meaning |
|---|---|
run / start |
Start a run for a goal (or continue the current one). |
resume |
Continue the persisted run after an interruption. |
status |
Inspect phase, plan, loop budget and last error. |
stop |
Close the run. |
doctor |
Read-only environment and configuration checks. |
// orbit_controller
{
"action": "run",
"goal": "…",
"approved_loop_count": 4,
"user_hard_constraints": ["only touch src/"]
}
Activation
Orbit supports three activation styles:
/agent-orbit <goal>— deterministic slash-command activation. In the Web GUI it appears in the/menu (Run a goal with Orbit deterministic engineering orchestration); on headless/CLI surfaces a genuine user message that starts with/agent-orbitactivates Orbit directly. The original command line stays visible in the conversation, the goal is passed through without rewriting, and no goal asks for one instead of starting an empty run.orbit模式— recommended natural-language activation, e.g. “用 orbit模式完成这个项目”.cx模式— legacy compatibility; still resolves to Orbit.
All three routes converge on the existing orbit_controller tool and
OrbitService; the activation layer never starts a run of its own.
Model configuration (Web)
The Orbit model control sits immediately left of the native composer model
seat (conversation.input.right renders before conversation.input.model).
Its button names the Commander's model; the menu edits three roles:
- Commander and Watchdog pick from the same native model catalog and
persist into the DSH
orbitsettings namespace (settings.yaml), with the compositionconfig.routesas the base/default. Switching a model uses that model's own default reasoning effort — a previous model's effort is never inherited. - Executor follows the current session model ("Follows current session
model"). Both the Orbit row and the native seat read and write the SAME
per-session
ModelDirectory, so a change in either place updates the other.
A new run resolves its routes exactly once — Commander/Watchdog from orbit
settings, Executor from the initiating session's current selection, each
falling back to config.routes — and freezes them into state.routes.
Changes made while a run is active apply to the next run; resumed runs keep
their frozen routes. Headless/CLI profiles without a settings provider keep
running from config.routes unchanged.
State machine
PLAN → EXECUTE → EVALUATE → SUCCESS
│
├─ correction (bounded per step)
├─ append (bounded by remaining loop budget)
├─ NEEDS_USER
└─ BUDGET_EXHAUSTED
- Only a normally completed Executor step consumes one loop from the budget.
- Corrections are limited per base step and reserve budget for the remaining planned steps.
- Commander decisions are validated in code (
PASS_CURRENT_STEP/CORRECT_CURRENT_STEP/NEEDS_USERfor step evaluation,SUCCESS/APPEND/NEEDS_USERfor final evaluation,KEEP_APPROACH/REPLACE_CURRENT_STEP/NEEDS_USERfor strategy reconsider). - Commander runs under an adaptive timeout: a soft review at 360s, a second review at 600s and a deterministic hard ceiling at 840s; an extension always keeps the same child.
- The Smart Watchdog is only invoked on runtime anomalies, performs at most two diagnoses per step, and can resume the same child or restart the step with a fresh one after interrupting the old child.
- Blocked tools are recoverable: a guard denial stops that single call, not the turn or the run.
Safety boundaries
- Commander and Watchdog receive read-only tool allowlists.
- Executors receive the configured writer allowlist; browser tools are added
only for steps that declare the
browsercapability. - While Orbit owns a workspace, other top-level autonomous drivers
(
create_goal,ralph,workflow) are refused, and Orbit refuses to start while an active goal driver owns the same workspace. .cxdurable state is written only by the Orbit service (atomic write, short lock transaction, monotonic revision).
Configuration
| Key | Default | Meaning |
|---|---|---|
projectDir |
session cwd | Project the run operates on. |
routes.commander |
deepseek-official / deepseek-v4-pro / high |
Commander model route. |
routes.executor |
deepseek-official / deepseek-v4-flash / high |
Executor model route. |
routes.watchdog |
deepseek-official / deepseek-v4-flash / low |
Watchdog model route. |
executorTools |
read/glob/grep/bash/edit/write/… | Executor allowlist. |
browserTools |
["agent_browser"] |
Browser capability tool names. |
commanderReadOnlyTools |
read/glob/grep/web… | Commander allowlist. |
watchdogTools |
read/glob/grep | Watchdog allowlist. |
executorTimeoutMs |
480000 |
Deterministic executor runtime timeout. |
registerTool |
true |
Register the orbit_controller tool and the legacy cx_controller alias. |
registerGuards |
true |
Register recoverable tool guards. |
slashCommand |
true |
Register the /agent-orbit host command and the gesture boundary. |
Routes are normal DSH model routes; configure them for your own provider and model identifiers. No credentials are included in this package.
Optional browser capability
Orbit does not depend on @kasenri/dsh-browser. A plan step that declares
capabilities: ["browser"] needs the agent_browser tool to be registered by
the browser plugin; otherwise Orbit reports BROWSER_CAPABILITY_UNAVAILABLE and
lets the Commander decide what to do. Install both packages to use that path:
dsh plugin --profile web add github:KasenRi/dsh-browser
dsh plugin --profile web add github:KasenRi/dsh-orbit
Migrating from dsh-cx
| CX | Orbit |
|---|---|
dsh-cx |
dsh-orbit |
@kasenri/dsh-cx |
@kasenri/dsh-orbit |
cx_controller |
orbit_controller |
| CX mode | Orbit mode (orbit模式; cx模式 still works) |
ctx.cx |
ctx.orbit (same OrbitService instance; ctx.cx remains an alias) |
.cx/state.jsonremains unchanged.- Legacy
cx模式remains supported. - Existing durable runs do not need migration: Orbit reads the same
.cx/state.json, including historicalCX_*error strings. .cxis retained as the durable execution state path for backward compatibility with existing CX projects.
License
MIT
Operate deliberately
Install and manage
Prerequisites and target Profile
Target: Web Profile
Delivery: Dsh Bundle Git — KasenRi/dsh-orbit#ce728128287724ab2b1b41a7eb005fc1b42cab0f。
Verify, update, and remove
Show lifecycle commands
dsh plugin --profile web listCompatibility and access
DeepSeek Harness bundle; web client support declared: Tested with @deepseek-ai/dsh 0.1.5-rc.2; Node.js >=22.19.0。
Review compatibility evidence ↗
Risk facts
Executor steps may use configured write-capable tools in the selected project directory.
Evidence ↗Run state is persisted under <project>/.cx/state.json.
Evidence ↗Evidence and editorial reviewManifest, Bundle patch, distribution and freshness
Immutable evidence
Review status and source activity
MIT-licensed community release mirror; review configured executor tool allowlists before using it on a writable project.
AI reviewed Sep 13, 2026, 2:15 PM UTC。GitHub facts last checked Sep 13, 2026, 2:15 PM UTC。
No material source change has been recorded since this evidence baseline.