Supplies the Invisible class, the Replace replacer and the generic Chunk/Block dispatch this flavor is a thin closure over.
hook-dsh-normalize-invisible
Hook @ DSH @ Normalize @ Invisible • _The DeepSeek Harness Plugin Family for PlayForm._ The invisible-character normalizer for model output - a DeepSeek Harness plugin that hooks the llm/stream waterfall (the interceptable wrapper around EVERY streaming model call, bound to the LlmRuntime) and normalizes the zero-width/invisible character family in model output, live in the transcript - by REMOVING it: zero-width spaces, joiners, bidi controls and the BOM character simply vanish (the default replacement is the empty string). A CLASS flavor of the normalize family: the core's Invisible class plus a configurable replacement string (default "" - removal). The family's raw-write tool (registered by hook-dsh-normalize-dash) bypasses this flavor's transforms too - the exemption is family-wide.
$ pnpm add @playform/hook-dsh-normalize-invisible The profile wiring for this plugin - the bundles list, the patch entry and the restart - is on the setup page.
Where It Fits
Family position (the @-sentence Hook @ DSH @ Normalize @ Invisible): a hook child of the plugin-dsh-factory service and the hook-dsh-core machinery; the fifth of the six stream normalizer siblings:
| Flavor | Table | Substitution |
|---|---|---|
| hook-dsh-normalize-dash | core Dashes class | → replacement (default -) |
| hook-dsh-normalize-quotes | core Quotes MAP | curly → straight |
| hook-dsh-normalize-ellipsis | core Ellipsis class | U+2026 → ... |
| hook-dsh-normalize-spaces | core Spaces class | unicode spaces → " " |
| hook-dsh-normalize-invisible (this bundle) | core Invisible class | removed (default "") |
| hook-dsh-normalize-fullwidth | core Fullwidth MAP | full-width → half-width |
A non-manifest factory consumer: it injects ["pluginFactory"] and uses only State (cell unwrap + shared Ledger/Enabled mappings + its own fields) and Append; the config is composed by the factory's standalone Schema helper with shared: false - the minimal block, no fs/observed dead fields. It touches no files, so fs/write-intent and fs/observed never see it; it wraps the downstream result and always calls next(), so it composes with other llm/stream listeners regardless of registration order.
In the DeepSeek Harness
| Seam | What the plugin does there | What you can observe |
|---|---|---|
| llm/stream - the model stream waterfall | The plugin's listener wraps the interceptable waterfall around EVERY streaming model call (bound to the LlmRuntime): next() is called first, options are never touched, one chunk in - one chunk out, upstream throws propagate. | The smugglers are deleted before they reach the live UI or the durable transcript. |
| The model stream vocabulary (dsh-llm) | The chunk/block shapes it rewrites come from the harness's stream vocabulary (@deepseek-ai/dsh-llm, type-only): text deltas, reasoning deltas and assembled blocks must agree. | No inconsistencies between deltas and blocks for downstream consumers. |
| The factory service | A non-manifest factory consumer: State for the config (the replacement is a hot-editable volatile cell) and Append for every ledger line; it touches no files. | Composes with other llm/stream listeners regardless of registration order. |
| The raw-write exemption (family-wide) | The family's raw-write tool (registered by hook-dsh-normalize-dash) passes through this flavor's stream transforms by identity - the tool's explicit normalize parameter is the only normalization it applies. | Per-call control stays with the agent, even with every stream flavor armed. |
| The ledger / session | Two lines through the factory's Append: the activation proof from apply() (the empty default renders as replacement=) and the per-stream count line on a normal completion with N > 0. | A thrown-away stream writes no ledger line. |
The Problem
Zero-width and format characters carry no visible width - which makes them the perfect smugglers. A zero-width joiner inside a file path, a right-to-left mark inside a command, the U+202E visual-spoofing override in what looks like plain text: none of them show up in the transcript, all of them change what a parser, shell or diff sees. This flavor deletes the whole family before it reaches the transcript.
How It Works
The transform - the core's Invisible class, applied per text segment through the core's generic class-to-string Replace:
All are removed (default replacement: "" - REMOVAL) per text segment:
| U+ codepoints | Characters |
|---|---|
| 00AD | soft hyphen |
| 200B | zero-width space |
| 200C | zero-width non-joiner |
| 200D | zero-width joiner |
| 200E | left-to-right mark |
| 200F | right-to-left mark |
| 202A-202E | LRE, RLE, PDF, LRO, RLO (bidi embedding controls; U+202E is the classic visual-spoofing override) |
| 2060 | word joiner |
| FEFF | zero-width no-break space (the BOM character) |
No context rules, chunk-boundary-safe - single-character replacement, no lookahead, per-chunk application can never disagree with whole-text application. The replacement is applied with a function replacer, so a custom replacement containing $ patterns is inserted literally. Replaced characters are counted per stream for the ledger line.
The Config
| Field | Type | Default | Volatile | Meaning |
|---|---|---|---|---|
| log | boolean | true | yes | write the durable ledger file |
| logFile | string | ~/.dsh/hook-dsh-normalize-invisible.log | yes | the invisible ledger (separate from the family's logs) |
| replacement | string | "" | yes | the transform's only knob - default REMOVAL; hot-editable |
| normalizeReasoning | boolean | true | no | normalize reasoning deltas and the assembled reasoning block too |
| normalizeToolArguments | boolean | false | no | IMPLEMENTED (default OFF): rewrite the tool-call argumentsDelta and the assembled ToolCallBlock.arguments when on (with the edit name exemption and the {"__normalize":false raw-marker pass-through) - execution-critical raw JSON, the user's accepted risk; the example patch turns it on |
Volatile cells commit without remounting the plugin; the factory's State builder unwraps them defensively. Example cordis.patch.yml row:
In Action
One stream, one deletion. The model emits text carrying invisible smugglers; the live UI and the transcript receive clean text - and the two lines below look identical in print, because the removed characters are invisible. The incoming line carries, in order: a soft hyphen (U+00AD), a zero-width space (U+200B), a zero-width joiner (U+200D), a left-to-right mark (U+200E), a right-to-left mark (U+200F), a word joiner (U+2060) and a BOM character (U+FEFF):
Before → after - identical in print, different to a parser
In the incoming line the smugglers sit inside the word password and around the colon; a diff would see a password that does not match the author's text, a parser would tokenize differently, a shell could splice a command. After the pass all of them are simply gone - the output line is what the reader should see. When a stream finishes normally with replacements made, the ledger gets the count line shown below. The replacement is hot-editable (the default "" removes; a non-empty value such as "?" would mark each smuggler's position for debugging), and the same pass runs over reasoning deltas when normalizeReasoning is on and over tool-call arguments when the example patch enables normalizeToolArguments - with the edit name exempt and raw-marker calls passing through unnormalized.
The Ledger
Two lines, both written through the factory's Append (the hook-dsh-normalize-invisible: prefix is the logger's <State.Module>:; the durable file line is [<ISO>] <message>). The empty default replacement renders as the empty replacement=:
The activation line is written by apply(); the count line only follows a normal stream completion and only when N > 0 (a thrown-away stream writes no ledger line).
Related plugins
The neighbouring sibling flavor - the unicode space family, normalized to the plain space.
The parent service: State, Append - plus the named Schema helper (shared: false) for the config.
License: MIT.