
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
dsh-retry-guard
Advanced tools
Observe repeated identical tool failures and optionally pause before DSH's next model step.
Pause before the next model step after three identical DSH tool errors.

20-second recording: real DSH Web, scripted model, no API key. The demonstration uses a deliberately failing local tool, not a production AI model.
In DSH, open Plugins → Add plugin, enter this package name, click Install, then Enable now:
dsh-retry-guard@alpha
Supported target: DSH Web 0.2.0-rc.2 · Node.js 24. Early prototype, MIT. Unofficial community plugin; independently maintained and not endorsed by DeepSeek. Default: observe. Opt-in: pause. The plugin requires no separate account, API key or network connection. Installing dependencies requires registry access.
Requires an existing DSH Web 0.2.0-rc.2 installation on Node.js 24.
The released archive contains built JavaScript. You do not need Git, pnpm, a
source checkout, or a build to install it. The alpha tag selects the current
prerelease. To pin this version, enter dsh-retry-guard@0.1.0-alpha.2.
dsh-retry-guard@alpha into
Package name or address and click Install.See verification scope for the installation checks.
dsh plugin --profile web add dsh-retry-guard@alpha
Restart DSH Web after a CLI installation, then open the settings as above.
Use DSH's plugin manager to install and activate the bundle; a plain
npm install in an unrelated project does not activate it in DSH.
The earlier alpha.1 archive
remains available with identical detector, host and browser code. Download its
.tgz and SHA256SUMS, then install it from the download directory:
dsh plugin --profile web add ./dsh-retry-guard-0.1.0-alpha.1.tgz
The archive's dsh.bundle manifest points to cordis.patch.yml; this is a
package manifest field, not a separate file extension. DSH 0.2.0-rc.2 does not
automatically update installed plugins. To switch versions, uninstall the old
bundle and install the desired version, then check its saved mode.
For example, a tool repeatedly returns the same missing-argument error with the same arguments. On the third consecutive failure:
The plugin notices a repeated error; it does not work out or fix its cause. The notice currently gives record references, not a one-click inspector link. See the error-record walkthrough.
You can watch the recording above without installing development tools. To run our exact keyless demonstration yourself, follow the separate developer demo guide. Its scripted model and failing tool belong to the source checkout and are not included in the normal plugin installation.
In that one deterministic fixture, Observe runs 6 tool calls / 7 model requests; Pause runs 3 / 3, followed by one successful call after a new repair instruction. These are fixture counts, not a general cost-saving claim. See verification scope, alternatives, and reported failures and detection limits.
Within one agent and turn, three consecutive failed calls must have the same
tool name, recursively key-sorted JSON arguments, and exact failure content.
"Failed" means DSH marks the tool result isError: true. A Bash command returning
exit code 1 is normally a successful tool execution in DSH and is not counted.
Array order, strings, and failure details are significant. A successful call,
changed arguments/error/tool, an excluded call, or a new turn breaks the chain.
Excluded names are exact matches, not wildcards.
Configuration has exactly three fields:
mode: observe # observe | pause
failureLimit: 3 # integer >= 2
excludeTools: [] # exact names; excluded calls break a streak
Changes start a fresh detector state at the next boundary. Detector state is in memory and resets when the plugin or host restarts. Existing notices and tool records remain in the DSH session. A fresh human message also resets an armed pause, including messages queued while tools finish.
The guard performs no network requests and has no telemetry. It hashes raw arguments/failure content only in memory. The notice's shareable JSON includes metadata only: no arguments, error text, authentication values, or conversation text. Review tool names and identifiers before sharing. DSH's original session log still contains the original tool data; do not confuse a full session export with this small report.
Different errors, changing arguments, interleaved calls, pure text loops and provider request failures are outside this detector's narrow rule. Successful polling is not blocked. Other plugins may independently stop work. The plugin does not diagnose a root cause, repair files, switch models, or estimate savings.
Only DSH Web 0.2.0-rc.2 is targeted. Other versions require compatibility tests. The exact DSH peer declarations identify the tested API versions; package-manager warnings alone are not a compatibility test. DSH's profile installer may warn about peers that its host supplies; the isolated Web install is tested separately.
Stop the DSH Web process for the profile, then run:
dsh plugin --profile web remove dsh-retry-guard
Restart DSH Web. Existing session records remain. For the isolated demo only,
prefix the command with DSH_HOME="$PWD/.work/demo-home" and use pnpm exec dsh
if the CLI is not globally installed. Do not delete your normal DSH home.
DSH retains the dormant settings row in the profile patch; removing the bundle
unloads its hooks and UI. Reinstalling into that same profile can reuse the saved
mode, so check it before starting work.
See developer setup, keyless demo and Web checks.
The detector is in src/core.ts; the DSH adapter and durable notice are in
src/index.ts; settings and the visible report are in src/client/index.tsx.
Dependencies are pinned in pnpm-lock.yaml.
No dependency lifecycle scripts are needed for the detector tests.
The Check workflow
runs type checks, tests, the build and both keyless terminal examples on Node.js 24.
This is a validation alpha. We are looking for five DSH Web users to try installing it and report whether they still use it after 48 hours. See the five-person trial for the steps and a public feedback form. The DSH community invitation has the demo and participation details. Feature expansion and a broader launch wait until at least three people install within five minutes and confirm continued use. Stars and downloads do not count as installation or retention evidence.
FAQs
Observe repeated identical tool failures and optionally pause before DSH's next model step.
We found that dsh-retry-guard demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.