Overview
dsh-roles-zeta
README / EN
Package documentation
Registry summary
dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.
Read the full README on GitHubLIMITATIONS
Known limitations
- **A preset's delegation tools survive a role's `allow` list.** Under a preset whose `subagent` row sets `modelSelectionSettings: true`, that row installs itself per agent, and `tools.restrict()` never filters a scope's own layer: a role allowing six tools received eight in the web profile (`subagent` and `list_subagent_models` leaked) and six in headless. A read-only role in the web profile can still start a child; the persona says not to, the filter cannot enforce it. - **A role cannot change the workspace instruction chain.** Every child loads the same `AGENTS.md`/`CLAUDE.md` chain as its parent. - **The registry probe is advisory.** A `tools.restrict()` rejection narrows the filter and retries up to three times, so a stale name costs one failed start. - **A slash command is a request, not a guarantee.** The model performs the delegation; the transcript shows whether it did. - **The settings page edits files, not sessions.** A running child is unaffected by a later edit; the next start reads the new file. - **No per-role memory.**
