Overview
dsh-prompt-polish
README / EN
Package documentation
Registry summary
dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.
Read the full README on GitHubLIMITATIONS
Known limitations
| Guardrail or boundary | What the code does | Important limitation | | --- | --- | --- | | Provider data flow | Uses DSH's configured LLM service and adds no separate plugin endpoint. | Drafts and enabled context can leave the machine through that provider. Provider retention, logging, and regional handling are outside this plugin. | | Context opt-in | Goal, todo, messages, compaction, and tool summaries are added only when the context switch is enabled; tool summaries additionally require the tool-result switch. | Context collection is bounded and budget-pruned, so it may be incomplete. Do not treat a missing item as proof that it was absent from the session. | | Untrusted reference data | The Host prompt labels draft/context as reference data and instructs the model not to execute instructions inside them. | This is instruction-based prompt-injection handling, not a deterministic security boundary. Review model output. | | Draft and custom limits | Drafts over 20,000 characters are rejected; custom instructions are trimmed to 500 characters. | These are application limits, not protection against expensive or sensitive model requests. | | Workspace writes | L3 writes go through the DSH file service and sandbox policy. | A denied or unavailable write falls back to L1; the workspace file is not an encrypted secret store. | | Composer writes | Optimization results require explicit adoption and an unchanged draft. | **Refill** from history intentionally writes to the composer; **Keep draft** and **Later** only dismiss the pending result. | | Local history | Last-five attempts are kept in component memory only. | History is not durable and can include failed output/error text until the component is destroyed. | The plugin itself does not collect credentials or create a database. It does store the selected settings in browser storage and, when possible, the workspace JSON file. Installing it runs third-party code in the DSH process; review the source and the provider policy before enabling it for sensitive work.
