Replies: 2 comments
|
The no-way-to-scope claim only holds if you treat the two injections as one thing. At the orchestrator layer, per-agent scoping is absolutely possible: we compose each child's brief from that role's own prompt, the member card, and that role's memory file, not from the parent's context. A bounded child gets its brief and nothing else from us. What we cannot do at that layer is remove the user-global file, because the CLI itself injects it on startup and exposes no flag to disable it. So the fix for the first part is in the orchestrator, and the fix for the user-global part has to happen upstream in the CLI. |
|
Thanks for the write-up — the part that made it actionable for me is that you separated (a) the mechanism-level injection from (b) the child's consequent behaviour, and that you located the decision with the dispatcher. The seam. The chain is composed inside I verified that end to end before building anything (real harness, real filesystem workspace with a real
On @capitaharlock's point about the user-global file. It is not a second channel arriving from somewhere else: Shipped — npm install @argszero/cordis-plugin-instruction-scope- insert:
- id: instruction-scope
name: '@argszero/cordis-plugin-instruction-scope'
config:
rules:
- match:
origin: subagent
delegationDepth: { gte: 1 }
policy: omit
reason: bounded child, no project context neededThe decision stays with the dispatcher, as you argued it must. A rule matches the lane the dispatcher chose — the durable session header ( Evidence. 32 tests against the real packages, including the control arm above; 39 mutations of the plugin's own logic, all red, no survivors. The published artifact was then verified by installing it by name in an empty directory and running the same two-arm probe from there — Honest boundaries — three.
One smaller note that may matter for the upstream shape: the subagent descriptor is the right input, but it currently carries no instruction field ( |
Uh oh!
There was an error while loading. Please reload this page.
Summary
@deepseek-ai/dsh-agent-instructionsinjects the workspace instruction chain into everyagent in the tree. There is no way to scope it per agent, per task class, or per subagent role.
For a delegated child whose task needs zero project context — a bounded review, a source
check, a numeric recheck, a verdict — that is more than overhead: it arrives with user-role
authority, and it includes the user-global file, not just the project chain.
What is observed
A subagent was dispatched for a bounded read-only task: review one note and report whether two
of its sections contradict each other. The delegation prompt named exactly one file and
explicitly said not to load workspace memory,
ownership-map,AGENTS.md, or any skill.Two distinct effects appear in the child's session event log, and they should not be conflated.
(a) Injected automatically, before the child acts. One user-role message is present in the
child's context regardless of the prompt:
user$DSH_HOME/AGENTS.md(user-global), project-rootAGENTS.md, project-rootCLAUDE.mdThe message begins with the user-global file, before any project file:
So a child inherits user-level configuration — personal workflow conventions, machine-local
paths, credential-handling notes — whether or not its task has anything to do with the project,
and even when its prompt explicitly said not to load any of it.
(The block above is redacted. The real message contains the full text of the user-global file
verbatim; I have not reproduced this workspace's actual contents here.)
(b) Read by the child on its own initiative, because of (a). The injected project-root
AGENTS.mdcontains a startup protocol that instructs the reader to load several furtherfiles. The child followed it:
bashcalls)user-preferences.md,research-memory-evolution-protocol.md,scientific-preferences.md, subtreeAGENTS.md)README.md,_index.md×2)The causal chain is the point: (a) is a mechanism-level injection the dispatcher cannot
suppress, and (b) is the child doing its best to comply with what it was handed. Suppressing
(a) removes the trigger for (b) as well.
Why this is not only "extra tokens"
1. Role confusion. The plugin's own template (verified verbatim in
lib/index.js) framesthe injection as:
It is delivered as a user-role message — the same role as the dispatcher's prompt. Real-world
AGENTS.mdfiles commonly state precedence rules such as "Direct Human instructions prevail".A child that reads the injected block as operator input can act on instructions the dispatcher
deliberately scoped out.
2. It contradicts the tool's own contract. The
subagenttool's description says:The prompt is presented as the child's entire contract, but a second, undisclosed input channel
is injected alongside it.
3. The child cannot resolve this correctly. It sees its prompt and the injected message, but
not the lane it was dispatched into — so it has no basis on which to judge whether the chain
applies to it.
Why the current config surface cannot express the fix
Every field governs which files are discovered, globally. None expresses which agents
receive them. The subagent descriptor carries no instruction-related field either:
{"version":3,"mode":"continuable","provider":"spawn", "label":"...","agentProvider":"...","agentModel":"...","agentReasoningEffort":"max"}Disabling the plugin would strip workspace context from the main agent too, and the main agent
should load project governance. What is missing is per-agent scoping, not an off switch.
Prior art
Claude Code added
omitClaudeMdin v2.1.271 (2026-09-14) for exactly this case:Two design details worth borrowing:
not thereby opt out of organisation policy. The same distinction may be worth drawing here
between project/user scopes and any harness- or org-managed baseline.
Before that flag existed, the documented workaround was restructuring the repository so each
subagent ran from its own working directory with its own scoped
AGENTS.md— i.e. solving anagent-scoping problem with filesystem layout. Community reports describe the pain point
persisting for over a year, including measurement runs where every subagent loaded the project
CLAUDE.mdregardless of task.I found no equivalent report for DSH. The closest existing discussion is
#3285, which concerns
whether
$DSH_HOME/AGENTS.mdshould be the user-global path — a different axis (path scoping,not agent scoping).
Implementation lead: the primitive already exists
docs/subsystems/core.mddescribesscope/as:and lists scope-filtered dispatch (
@deepseek-ai/dsh-scope): "agent-scoped listenersreceive only that agent."
I checked
dsh-agent-instructions@0.1.6-alpha.1'slib/index.js: it does not consumedsh-scope(no hits fordsh-scope,scopeOf,scopeTarget,withInitiator). If theinstruction baseline can be registered or dispatched per-agent, this feature may be
considerably smaller than a new subsystem. I did not trace how the baseline is prepared
relative to agent scope — that part needs a maintainer's confirmation.
Suggested shape
Any of these would resolve the reported case; the first is closest to prior art:
e.g.
omitWorkspaceInstructions: true— suppressing the user-global and project chain forthat child while leaving any managed/org baseline intact.
context;
subagent-spawn-in-processand out-of-process providers could differ.instructionFileCandidatescould resolve per-agent rather thanper-workspace, a dispatcher could supply a narrower candidate set for a child.
The decision point should be the dispatcher, not the child. The dispatcher knows the lane;
the child does not. Any design that asks the child to "determine what applies" cannot work,
because the information needed to decide is not in the child's context.
Workaround available to a dispatcher today
A dispatcher can only compensate in the prompt: declare the task class, name the exact files to
read, and tell the child not to load workspace memory,
ownership-map.yaml, subtreeAGENTS.md,or the skill catalog. Doing that took the same review from 23 tool calls with no deliverable to
7 tool calls with a verdict.
It only saves turns. The injected user-role message still arrives; the child still has to be
told to ignore it; and correctness depends on every dispatcher remembering to say so. The
mechanism, not the prompt, is the thing that needs the scope.
What I did not verify
dsh-scopecan be applied to the instruction baseline without changinghow the baseline is prepared per request. Stated as a lead, not a claim.
chars), of which the project chain is a subset.
subagent-acp,subagent-codex,subagent-claude-code) behave differently — those children may already apply their owninstruction policy upstream, which is itself an argument for per-provider declaration.
@deepseek-ai/dsh-agent-instructions@0.1.6-alpha.1.Reproduction
AGENTS.md(a startup protocol requiring severalmemory files works well), plus
CLAUDE.mdand a subtreeAGENTS.md.prompt, state that the task is bounded read-only and that it must not load workspace memory,
ownership-map.yaml, subtreeAGENTS.md, or any skill.chain is present regardless of the prompt's instruction.
In the originating case: 10 tool calls before the target artifact was opened, 23 in total,
and no deliverable.
All reactions