# Keyless replay counterpart of session-sandbox-root.cordis.yml. Patches do not # compose across nested includes, so the replay swap, the recorded model pin, # and the deliberately distinct sandbox fallback are applied together to the # live tree. - id: base name: '@cordisjs/plugin-include' config: path: ./cordis.yml patches: - id: llm-deepseek name: '@deepseek-ai/dsh-llm-deepseek' disabled: true - id: acp-agent name: '@deepseek-ai/dsh-acp-demo' config: provider: deepseek model: deepseek-v4-flash persistenceRoot: !!js process.env.DSH_SNAPSHOT_SESSIONS_ROOT ?? './.sessions' persistenceCompression: none workspaceContext: maxBytes: 65536 persona: | You are a coding assistant powered by the {{model}} model. Your working directory is {{cwd}}. Your bash tool runs under a file sandbox — a `[sandbox: file access denied …]` result is policy, not a command bug. Verify your work by running the code or tests. Keep answers brief and factual. - id: sandbox name: '@deepseek-ai/dsh-sandbox-local' config: runnerCommand: - bash - -c - while [ "$1" != "--" ]; do shift; done; shift; exec "$@" - passthrough-runner runnerFailureSignatures: - 'passthrough-runner: profile rejected' - id: sandbox-policy name: '@deepseek-ai/dsh-sandbox-policy' config: mode: danger-full-access workspaceRoot: /tmp - insert: - id: llm-replay name: '@deepseek-ai/dsh-llm-replay' config: providers: - id: deepseek name: DeepSeek models: - id: deepseek-v4-flash - id: deepseek-v4-pro