# Subagent-under-confinement snapshot overlay: pin the recorded model to # deepseek-v4-flash so this scenario's request headers match the recorded # sandbox-class corpus (cordis.yml ships deepseek-v4-pro for live use). The # read-only policy itself comes from the scenario's DSH_PERMISSION_MODE env — # the automation protocol has no session-scoped picker, so deployment policy # is the lever ([downgrade rationale in the scenario table]). A config patch # replaces the whole target config, so base fields are restated verbatim. - id: base name: '@cordisjs/plugin-include' config: path: ./cordis.yml patches: - id: acp-agent name: '@deepseek-ai/dsh-acp-demo' config: provider: deepseek model: deepseek-v4-flash persistenceRoot: !!js process.env.DSH_SNAPSHOT_SESSIONS_ROOT ?? './.sessions' persistenceCompression: !!js "process.env.DSH_SNAPSHOT === undefined ? 'zstd' : 'none'" workspaceContext: maxBytes: 65536 persona: | You are a coding assistant powered by the {{model}} model. Your working directory is {{cwd}}. Your bash tool runs under a file sandbox — a `[sandbox: file access denied …]` result is policy, not a command bug. Verify your work by running the code or tests. Keep answers brief and factual.