Sponsio Agent Safety Setup
SponsioLabs/Sponsio
Installs, tunes and enforces Sponsio contracts that block unsafe tool calls in LLM agents, covering setup, auditing, observe mode and flipping to enforce.
How to dispatch well — choosing flash vs pro, writing self-contained briefs, parallelism, verifying results, and guardrails
$ npx skills add ZSeven-W/dsh-crew --skill dsh-playbook -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ZSeven-W/dsh-crew dsh-playbook --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ZSeven-W/dsh-crew.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agy/skills/dsh-playbook .claude/skills/dsh-playbook && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dsh-playbook" agent skill from https://github.com/ZSeven-W/dsh-crew/tree/main/agy/skills/dsh-playbook into .claude/skills/dsh-playbook/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsh-playbook", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ZSeven-W/dsh-crew/tree/main/agy/skills/dsh-playbookType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ZSeven-W/dsh-crew --skill dsh-playbook -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ZSeven-W/dsh-crew dsh-playbook --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ZSeven-W/dsh-crew.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agy/skills/dsh-playbook .agents/skills/dsh-playbook && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dsh-playbook" agent skill from https://github.com/ZSeven-W/dsh-crew/tree/main/agy/skills/dsh-playbook into .agents/skills/dsh-playbook/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsh-playbook", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ZSeven-W/dsh-crew --skill dsh-playbook -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ZSeven-W/dsh-crew dsh-playbook --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ZSeven-W/dsh-crew.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agy/skills/dsh-playbook .cursor/skills/dsh-playbook && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dsh-playbook" agent skill from https://github.com/ZSeven-W/dsh-crew/tree/main/agy/skills/dsh-playbook into .cursor/skills/dsh-playbook/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsh-playbook", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ZSeven-W/dsh-crew.git --path agy/skills/dsh-playbook--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ZSeven-W/dsh-crew --skill dsh-playbook -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ZSeven-W/dsh-crew dsh-playbook --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ZSeven-W/dsh-crew.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agy/skills/dsh-playbook .gemini/skills/dsh-playbook && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dsh-playbook" agent skill from https://github.com/ZSeven-W/dsh-crew/tree/main/agy/skills/dsh-playbook into .gemini/skills/dsh-playbook/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsh-playbook", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ZSeven-W/dsh-crew dsh-playbookInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ZSeven-W/dsh-crew --skill dsh-playbook -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ZSeven-W/dsh-crew.git skills-src && mkdir -p .github/skills && cp -r skills-src/agy/skills/dsh-playbook .github/skills/dsh-playbook && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dsh-playbook" agent skill from https://github.com/ZSeven-W/dsh-crew/tree/main/agy/skills/dsh-playbook into .github/skills/dsh-playbook/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsh-playbook", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ZSeven-W/dsh-crew --skill dsh-playbook -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ZSeven-W/dsh-crew dsh-playbook --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ZSeven-W/dsh-crew.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agy/skills/dsh-playbook .opencode/skills/dsh-playbook && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dsh-playbook" agent skill from https://github.com/ZSeven-W/dsh-crew/tree/main/agy/skills/dsh-playbook into .opencode/skills/dsh-playbook/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dsh-playbook", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dsh-playbookHow to dispatch well — choosing flash vs pro, writing self-contained briefs, parallelism, verifying results, and guardrails
Dsh Playbook is an agent skill from ZSeven-W/dsh-crew. How to dispatch well — choosing flash vs pro, writing self-contained briefs, parallelism, verifying results, and guardrails
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in AI & LLM Engineering, covering LLM guardrails. It works with Model Context Protocol, DeepSeek and TypeScript. The repository describes itself as: DeepSeek Harness (DSH) plugin: dispatch work to DSH agents from Claude Code / Codex — native subagent progress, in-host worker sessions with per-tier presets, and a multimodal… The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit b0ddd92. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dsh Playbook loads about 1.1k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 677 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ZSeven-W/dsh-crew at commit b0ddd92, republished under its MIT licence (© ZSeven-W). 677 words, ~1,150 tokens.
.claude/skills/dsh-playbook/SKILL.md (or your agent's skills folder).When the user asks how to dispatch work to DSH workers — tier choice, writing a brief, parallelism, verifying results, guardrails — answer from the playbook below. Point to the relevant section rather than reciting it whole.
How to delegate work to DSH workers well. The tool descriptions carry the mechanics; this playbook is the decision layer.
flash — mechanical, well-scoped work:
pro — multi-file work, debugging, design judgment:
When in doubt, start with flash: escalate_on_failure retries a failed blocking flash run once on pro, so evidence, not guesswork, decides.
worker="agy" / worker="grok" is explicit opt-in. Set it only when the user explicitly asks for that CLI, never as a default. Two caveats to tell the user: grok refuses to start repo-local MCP servers in untrusted folders (global installs are unaffected; change directory or pass --trust), and agy runs with full approval because it has no workspace-scoped permission mode.
The worker has zero conversation context. Every task string must be self-contained:
Bad: "fix the auth bug". Good: "In /abs/path/repo/src/auth.ts the token refresh throws on 401 when the session expires; make it retry once and fail loudly, add a test in /abs/path/repo/test/auth.test.ts, and run npm test. Touch only auth.ts and its test. Do not commit."
| Tool | One line |
|---|---|
dsh_run_worker | Run one task and block until it finishes; flash for mechanical work, pro for judgment. |
dsh_spawn_worker | Start a task in the background for fan-out; returns a job id, not a result. |
dsh_worker_status | Live progress of all jobs plus the cwd advisory locks. |
dsh_worker_result | Fetch a job's final result, optionally waiting wait_seconds. |
dsh_worker_cancel | Terminate a running job and release its cwd lock. |
dsh_worker_config | Read/set session defaults (default_tier, default_effort, mode, default_timeout_seconds, tier_policy, escalate_on_failure) and list worker_profiles. |
© ZSeven-W, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in agy/skills/dsh-playbook of ZSeven-W/dsh-crew.
Open the folder on GitHubat commit b0ddd92
Dsh Playbook next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dsh Playbook this skillZSeven-W/dsh-crew | 158 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Sponsio Agent Safety SetupSponsioLabs/Sponsio | 454 | — | ~12k | Automated safety check: Pass | Apache-2.0 | |
| Deepseek Automationzhu1090093659/deepseek-pp | 1.9k | — | ~2.1k | Automated safety check: Notes | Apache-2.0 | |
| Spec Driven Developzhu1090093659/deepseek-pp | 1.9k | — | ~6.9k | Automated safety check: Pass | Apache-2.0 | |
| Cdesktopcdesktop-ai/cdesktop | 158 | — | ~697 | Automated safety check: Pass | Apache-2.0 | |
| Typesafe AI DshPerryLink/jevcore | 106 | — | ~2k | Automated safety check: Pass | Apache-2.0 |
SponsioLabs/Sponsio
Installs, tunes and enforces Sponsio contracts that block unsafe tool calls in LLM agents, covering setup, auditing, observe mode and flipping to enforce.
zhu1090093659/deepseek-pp
A skill your agent uses when implementing, resuming, reviewing, or verifying the DeepSeek++ Codex-style automation feature in this repository.
zhu1090093659/deepseek-pp
Automates pre-development workflow for large-scale complex tasks.
cdesktop-ai/cdesktop
Operate the cdesktop coding-session environment — agent teams, session management, file conventions.
PerryLink/jevcore
Use TypeSafe Jev for narrow judgments inside DeepSeek Harness — routing, classifying, scoring, verifying, reranking — instead of spending a model turn on them.
2FastLabs/agent-squad
Guide to building Node.js and TypeScript apps on the agent-squad package: orchestrator, agent types, classifier routing, storage, retrievers and MCP tools.
ZSeven-W/dsh-crew
Show or set this session's DSH worker defaults (tier / effort / mode / timeout / on-off)
Works with
Categories
How to dispatch well — choosing flash vs pro, writing self-contained briefs, parallelism, verifying results, and guardrails. Dsh Playbook is an agent skill from ZSeven-W/dsh-crew.
Dsh Playbook fits situations like: tasks that involve LLM guardrails.
Run `npx skills add ZSeven-W/dsh-crew --skill dsh-playbook -a claude-code`. Or copy the skill folder (agy/skills/dsh-playbook in ZSeven-W/dsh-crew) into .claude/skills/dsh-playbook in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ZSeven-W/dsh-crew --skill dsh-playbook -a codex`. Or copy the skill folder (agy/skills/dsh-playbook in ZSeven-W/dsh-crew) into .agents/skills/dsh-playbook in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ZSeven-W/dsh-crew --skill dsh-playbook -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dsh-playbook, .gemini/skills/dsh-playbook, .github/skills/dsh-playbook and .opencode/skills/dsh-playbook in your project.
Going by SKILL.md and its folder, Dsh Playbook needs the command-line tools its instructions call (npm).
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dsh Playbook is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dsh Playbook: Sponsio Agent Safety Setup (SponsioLabs/Sponsio, 454 stars), Deepseek Automation (zhu1090093659/deepseek-pp, 1.9k stars), Spec Driven Develop (zhu1090093659/deepseek-pp, 1.9k stars) and Cdesktop (cdesktop-ai/cdesktop, 158 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ZSeven-W (a GitHub organization) maintains it in ZSeven-W/dsh-crew, which has 158 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 8, 2026.
Source: ZSeven-W/dsh-crew on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.