Enforcing KDD's implementer/validator split mechanically with a toolFilter-restricted subagent #4806
MauricioPerera
started this conversation in
General
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Not a new plugin — a config pattern on top of kdd-gates, documented in its README under "Forzar la separación implementador/validador con un subagente restringido".
KDD's core thesis is "the agent that implements is never the one that decides it's correct" — normally that's just a system-prompt instruction the model is trusted to follow.
@deepseek-ai/dsh-tool-subagentalready ships everything needed to make it a mechanical restriction instead: a second instance withprovider: spawn(fresh child, no inherited history — the task contract is the interface, not shared conversation memory) and atoolFilter.denylist naming the gate tools (kdd_validate,kdd_seal,kdd_perimeter,kdd_preflight,kdd_scaffold).Real trap hit while verifying it:
toolFilter.denynaming a tool that isn't mounted in that profile makestools.restrict()throw at delegation time —Error: tools.restrict() names unknown global tool "kdd_scaffold". The deny-list has to match exactly which plugins are actually loaded alongside it.Verified by delegating a task and asking the child to report its own tool list back — none of the 5 KDD tools appeared, confirmed it couldn't even attempt to call them.
All reactions