PLUGIN DETAIL FLAVOR: INVISIBLE CLASS FLAVOR - REMOVAL

hook-dsh-normalize-invisible

Hook @ DSH @ Normalize @ Invisible • _The DeepSeek Harness Plugin Family for PlayForm._ The invisible-character normalizer for model output - a DeepSeek Harness plugin that hooks the llm/stream waterfall (the interceptable wrapper around EVERY streaming model call, bound to the LlmRuntime) and normalizes the zero-width/invisible character family in model output, live in the transcript - by REMOVING it: zero-width spaces, joiners, bidi controls and the BOM character simply vanish (the default replacement is the empty string). A CLASS flavor of the normalize family: the core's Invisible class plus a configurable replacement string (default "" - removal). The family's raw-write tool (registered by hook-dsh-normalize-dash) bypasses this flavor's transforms too - the exemption is family-wide.

CLI INSTALL COPIED
$ pnpm add @playform/hook-dsh-normalize-invisible
Namespace: @playform/hook-dsh-normalize-invisible Release: v0.0.1
Archetype: Hook Event: llm/stream Table: core Invisible class

The profile wiring for this plugin - the bundles list, the patch entry and the restart - is on the setup page.

Where It Fits

FAMILY POSITION: 5TH OF 6 STREAM NORMALIZERS

Family position (the @-sentence Hook @ DSH @ Normalize @ Invisible): a hook child of the plugin-dsh-factory service and the hook-dsh-core machinery; the fifth of the six stream normalizer siblings:

FlavorTableSubstitution
hook-dsh-normalize-dashcore Dashes class→ replacement (default -)
hook-dsh-normalize-quotescore Quotes MAPcurly → straight
hook-dsh-normalize-ellipsiscore Ellipsis classU+2026 → ...
hook-dsh-normalize-spacescore Spaces classunicode spaces → " "
hook-dsh-normalize-invisible (this bundle)core Invisible classremoved (default "")
hook-dsh-normalize-fullwidthcore Fullwidth MAPfull-width → half-width

A non-manifest factory consumer: it injects ["pluginFactory"] and uses only State (cell unwrap + shared Ledger/Enabled mappings + its own fields) and Append; the config is composed by the factory's standalone Schema helper with shared: false - the minimal block, no fs/observed dead fields. It touches no files, so fs/write-intent and fs/observed never see it; it wraps the downstream result and always calls next(), so it composes with other llm/stream listeners regardless of registration order.

In the DeepSeek Harness

WHERE THE FLAVOR OPERATES
SeamWhat the plugin does thereWhat you can observe
llm/stream - the model stream waterfallThe plugin's listener wraps the interceptable waterfall around EVERY streaming model call (bound to the LlmRuntime): next() is called first, options are never touched, one chunk in - one chunk out, upstream throws propagate.The smugglers are deleted before they reach the live UI or the durable transcript.
The model stream vocabulary (dsh-llm)The chunk/block shapes it rewrites come from the harness's stream vocabulary (@deepseek-ai/dsh-llm, type-only): text deltas, reasoning deltas and assembled blocks must agree.No inconsistencies between deltas and blocks for downstream consumers.
The factory serviceA non-manifest factory consumer: State for the config (the replacement is a hot-editable volatile cell) and Append for every ledger line; it touches no files.Composes with other llm/stream listeners regardless of registration order.
The raw-write exemption (family-wide)The family's raw-write tool (registered by hook-dsh-normalize-dash) passes through this flavor's stream transforms by identity - the tool's explicit normalize parameter is the only normalization it applies.Per-call control stays with the agent, even with every stream flavor armed.
The ledger / sessionTwo lines through the factory's Append: the activation proof from apply() (the empty default renders as replacement=) and the per-stream count line on a normal completion with N > 0.A thrown-away stream writes no ledger line.

The Problem

WHY THE INVISIBLE FLAVOR EXISTS

Zero-width and format characters carry no visible width - which makes them the perfect smugglers. A zero-width joiner inside a file path, a right-to-left mark inside a command, the U+202E visual-spoofing override in what looks like plain text: none of them show up in the transcript, all of them change what a parser, shell or diff sees. This flavor deletes the whole family before it reaches the transcript.

How It Works

THE STREAM PIPELINE
llm/stream waterfall (options, next) the interceptable wrapper around │ EVERY streaming model call ▼ next() called FIRST, always - options never touched Normalize(upstream, state) the async generator │ for await (chunk of upstream) ▼ CoreChunk(chunk, transform, reasoning, toolArgs, raw) the core's per-chunk dispatch │ ├─ text-delta ────────► Replace(text, Invisible, "") rewrite the text field ├─ reasoning-delta ───► same, when normalizeReasoning (default ON) ├─ block-end ─────────► the assembled block's text fields - │ TextBlock.text / ReasoningBlock.text (plus a │ runtime `thinking` string field) - the deltas │ AND the block must agree, or consumers see │ inconsistencies ├─ tool-call-delta ───► Replace(argumentsDelta, Invisible, "") when │ normalizeToolArguments (IMPLEMENTED, default │ OFF - execution-critical raw JSON, the user's │ accepted risk; the example patch turns it │ on) - the assembled ToolCallBlock.arguments │ follows the same flag via block-end │ The gate is THREE-WAY with the flag on: a │ delta/block whose `name` is "edit" passes │ through BY IDENTITY (the edit tool's │ `old_string` must match the real file bytes), │ and a call whose arguments open with the │ `{"__normalize":false` marker (FIRST key, │ tracked per call id) passes through │ UNNORMALIZED with the marker entry stripped, │ so the executed call carries no unknown key └─ block-start / usage / finish ──► PASSTHROUGH BY IDENTITY, ALWAYS (usage/finish ordering is the adapter contract) │ count === 0 → original chunk BY IDENTITY; rewritten → shallow copy ▼ yield ──► downstream consumers = the live UI + the durable transcript │ (order preserved, no buffering; upstream throws propagate) ▼ normal loop completion, Count > 0 Factory.Append ──► `hook-dsh-normalize-invisible: normalized N invisible char(s) in one stream`

The transform - the core's Invisible class, applied per text segment through the core's generic class-to-string Replace:

[\u00AD\u200B\u200C\u200D\u200E\u200F\u202A-\u202E\u2060\uFEFF] → replacement

All are removed (default replacement: "" - REMOVAL) per text segment:

U+ codepointsCharacters
00ADsoft hyphen
200Bzero-width space
200Czero-width non-joiner
200Dzero-width joiner
200Eleft-to-right mark
200Fright-to-left mark
202A-202ELRE, RLE, PDF, LRO, RLO (bidi embedding controls; U+202E is the classic visual-spoofing override)
2060word joiner
FEFFzero-width no-break space (the BOM character)

No context rules, chunk-boundary-safe - single-character replacement, no lookahead, per-chunk application can never disagree with whole-text application. The replacement is applied with a function replacer, so a custom replacement containing $ patterns is inserted literally. Replaced characters are counted per stream for the ledger line.

The Config

SCHEMA + DEFAULTS AT LOAD
FieldTypeDefaultVolatileMeaning
logbooleantrueyeswrite the durable ledger file
logFilestring~/.dsh/hook-dsh-normalize-invisible.logyesthe invisible ledger (separate from the family's logs)
replacementstring""yesthe transform's only knob - default REMOVAL; hot-editable
normalizeReasoningbooleantruenonormalize reasoning deltas and the assembled reasoning block too
normalizeToolArgumentsbooleanfalsenoIMPLEMENTED (default OFF): rewrite the tool-call argumentsDelta and the assembled ToolCallBlock.arguments when on (with the edit name exemption and the {"__normalize":false raw-marker pass-through) - execution-critical raw JSON, the user's accepted risk; the example patch turns it on

Volatile cells commit without remounting the plugin; the factory's State builder unwraps them defensively. Example cordis.patch.yml row:

- insert: - id: hook-dsh-normalize-invisible name: "@playform/hook-dsh-normalize-invisible" config: log: true logFile: ~/.dsh/hook-dsh-normalize-invisible.log replacement: ""

In Action

ONE STREAM, ONE DELETION

One stream, one deletion. The model emits text carrying invisible smugglers; the live UI and the transcript receive clean text - and the two lines below look identical in print, because the removed characters are invisible. The incoming line carries, in order: a soft hyphen (U+00AD), a zero-width space (U+200B), a zero-width joiner (U+200D), a left-to-right mark (U+200E), a right-to-left mark (U+200F), a word joiner (U+2060) and a BOM character (U+FEFF):

Before → after - identical in print, different to a parser

text-delta in (what the model wrote): pass­s​word‍:‎ correct‏⁠ text-delta out (what reaches the transcript): "password: correct"

In the incoming line the smugglers sit inside the word password and around the colon; a diff would see a password that does not match the author's text, a parser would tokenize differently, a shell could splice a command. After the pass all of them are simply gone - the output line is what the reader should see. When a stream finishes normally with replacements made, the ledger gets the count line shown below. The replacement is hot-editable (the default "" removes; a non-empty value such as "?" would mark each smuggler's position for debugging), and the same pass runs over reasoning deltas when normalizeReasoning is on and over tool-call arguments when the example patch enables normalizeToolArguments - with the edit name exempt and raw-marker calls passing through unnormalized.

The Ledger

TWO LINES VIA FACTORY APPEND

Two lines, both written through the factory's Append (the hook-dsh-normalize-invisible: prefix is the logger's <State.Module>:; the durable file line is [<ISO>] <message>). The empty default replacement renders as the empty replacement=:

hook-dsh-normalize-invisible: activated (replacement=, reasoning=on, toolArgs=off, logFile=~/.dsh/hook-dsh-normalize-invisible.log) hook-dsh-normalize-invisible: normalized 7 invisible char(s) in one stream

The activation line is written by apply(); the count line only follows a normal stream completion and only when N > 0 (a thrown-away stream writes no ledger line).

Related plugins

12 TOTAL
hook-dsh-core DSH FAMILY

Supplies the Invisible class, the Replace replacer and the generic Chunk/Block dispatch this flavor is a thin closure over.

The neighbouring sibling flavor - the unicode space family, normalized to the plain space.

plugin-dsh-factory PARENT SERVICE

The parent service: State, Append - plus the named Schema helper (shared: false) for the config.

License: MIT.