
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
dsh-cc-agents
Advanced tools
Load Claude Code .claude/agents (identity-anchored subagents: frontmatter + system-prompt body) into DSH delegation via the persona channel.
Load Claude Code "first kind" agents (.claude/agents/*.md) into DSH as
delegatable subagents with identity anchoring.
CC agents are identity-anchored subagents: a frontmatter block
(name / description / tools / disallowedTools / model / skills /
background / initialPrompt …) plus a Markdown body that is the agent's
system prompt. DSH's subagent seam has no pre-registered agent directory, so
this adapter provides both halves:
name: description), reproducing CC's @-mention
semantics: the model sees which agents exist and when to delegate.cc_agent delegation tool — the model calls
cc_agent(agent, description, prompt); the adapter:
ctx.subagents.start(provider, …) with
persona = the agent body (DSH's native identity channel),toolFilter from disallowedTools
(applied first) then tools (CC semantics; buckets like Read/Bash
expand to DSH tool names, mcp__… names pass through),skills (frontmatter skill names → full skill bodies),model → agentOptions.model, background → background job,initialPrompt → prompt prefix.| key | default | meaning |
|---|---|---|
provider | spawn | ctx.subagents provider to delegate on (spawn / fork) |
toolName | cc_agent | model-facing tool name |
injectCatalog | true | inject agent catalog into session start |
enableRunInBackground | true | expose run_in_background |
maxDepth | 3 | absolute delegation-depth cap |
enableGlobal | true | include global ~/.claude/agents |
globalClaudeDir | ~/.claude | override global dir |
Project .claude/agents/ beats global ~/.claude/agents/ on name clashes
(fail loud — a warning is logged). Plugin agents arrive with the plugin source
(M4).
DIRECT — delegatable.ADAPTED — delegatable with degraded fields (memory, unknown fields).UNSUPPORTED — fields DSH cannot honor (hooks / mcpServers /
permissionMode — CC itself forbids these on plugin agents); the agent
still delegates without them.BLOCKED — isolation: worktree; never offered for delegation.dsh plugin --profile <p> add dsh-cc-agents
Dev checkout (hot user layer, file:/// required on Windows):
- insert:
- id: cc-agents
name: 'file:///C:/Users/.../packages/cc-agents/src/index.js'
config: { provider: spawn }
@deepseek-ai/dsh-subagent with an in-process provider (spawn) registered.@deepseek-ai/dsh-jobs + @deepseek-ai/dsh-tool-jobs only for background
runs.MIT. Shared parse layer is dsh-cc-loader (MIT, part of this repo).
FAQs
Load Claude Code .claude/agents (identity-anchored subagents: frontmatter + system-prompt body) into DSH delegation via the persona channel.
We found that dsh-cc-agents demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.