feat(my-deepagent): v0.1.0 Step 0~5 — scaffolding through deepagent + OpenRouter
Python rewrite of the agent harness on top of deepagents 0.6.1 + langchain 1.x,
replacing the abandoned TS attempt in packages/. 388 unit/integration tests pass.
Steps
-----
0. Scaffolding — uv workspace, ruff/mypy/pre-commit/alembic, src/tests/docs
trees with docs/schemas/ seeded from my-deepagent-seed/.
1. Core — config (pydantic-settings with MYDEEPAGENT_ env prefix and TOML
source), enums (Backend, Capability, RiskLevel, ApprovalDecisionAction,
ApprovalState, RunState, RunPhaseState, SessionState, ErrorClass),
errors (MyDeepAgentError + BudgetExhaustedError with PEP-3134 cause +
context suppression), hash (canonical JSON + sha256).
2. Persona/Workflow/Binding — pydantic v2 schemas with tuple-based deep
immutability (post-construction hash drift prevented), YAML loaders,
deterministic auto-select (preferred_backends → version → name → hash),
override resolution with ineligibility diagnostics, PersonaConsentStore
with fcntl.flock + tmp+fsync+rename atomic write.
3. Artifact schema registry — Draft202012Validator, multi-root resolution,
structured ValidationFinding output.
4. Persistence — 18 SQLAlchemy 2.0 async ORM models with FK CASCADE/RESTRICT,
WAL + busy_timeout + foreign_keys PRAGMA, alembic baseline +
ux_active_run_repo_base partial unique index, LangGraph SqliteSaver as
context manager only (lifecycle safety).
5. DeepAgent session — build_agent wires Persona → create_deep_agent with
LocalShellBackend / FilesystemBackend / StateBackend / CompositeBackend,
ChatOpenAI(base_url=openrouter) for openrouter: model strings, and 4
middleware classes (cost / audit-tool / safety-shell / fallback-model).
Critical workarounds
--------------------
- deepagents 0.6.1 rejects FilesystemPermission together with backends that
implement SandboxBackendProtocol (LocalShellBackend). SafetyShellMiddleware
enforces destructive-command and secret-path policy at the tool layer
instead, and build_agent strips the permissions kwarg when the persona's
deepagents_backend is local_shell.
- FilesystemOperation in deepagents is Literal['read', 'write'] only;
_map_operations collapses our richer schema (read/write/edit/ls) safely.
Real OpenRouter smoke
---------------------
test_openrouter_deepagents_local_shell_smoke calls DeepSeek via deepagents +
LocalShellBackend + SafetyShellMiddleware end-to-end. PASS, ~$0.000001 cost,
input=9 / output=1 tokens with content "OK".
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>