DeepSeek Harness plugin

dsh-audit-bundle

Content-addressed audit indexes across independent DeepSeek Harness evidence producers

Jump to install

Source facts

Repository
dongsheng123132/dsh-audit-bundle
Latest update
Aug 20, 2026
Category
Development & Runtime
GitHub stars
3
Format
plugin
Catalog evidence
Upstream dsh.bundle evidence
Evidence path
package.json#dsh.bundle
Checked against
0.1.0-rc.8
Upstream check date
2026-08-20

This evidence comes from the upstream catalog. This site has not installed, run, or security-reviewed the plugin.

Install

Start with a prompt that asks an agent to review the GitHub repository and source. Switch to the command if you want to install it yourself.

Copy this prompt into DSH, Codex, or another agent and ask it to review the GitHub repository and source first.

Do not install or run any commands yet. Read this plugin's GitHub repository, README, and relevant source code. Then answer the questions below clearly and directly so I can decide whether it fits my needs:

1. What is this plugin, and what problem does it solve?
2. Who is it for, and what are its typical use cases?
3. How is it used after installation? Include one minimal example.
4. What known limitations or privacy, security, compatibility, or maintenance risks does it have?
5. Give a clear recommendation: recommend, conditionally recommend, or do not recommend, with reasons.

Distinguish statements documented by the repository, inferences from source code, and unknowns. If evidence is insufficient, say so explicitly. Do not guess or simply repeat the README.

GitHub: https://github.com/dongsheng123132/dsh-audit-bundle
Plugin: dsh-audit-bundle
Author: dongsheng123132

Check the source files

Read the README and other files from this plugin directory before installing.

File explorer3 files
README.mdSource · read only

dsh-audit-bundle

![CI](https://github.com/dongsheng123132/dsh-audit-bundle/actions/workflows/check.yml) ![MIT license](LICENSE) ![Node.js 22+](package.json) ![Awesome DSH Plugins](https://github.com/dongsheng123132/awesome-dsh-plugins#2origin-plugin-lab)

Content-addressed audit indexes across independent DeepSeek Harness evidence producers.

Version 0.2 adds a formal proof-only Codex MCP surface, host-neutral DSH ToolDefinitions, real ToolRuntime calls and a stock Web Loader regression test. The package exposes namespace exports only and does not bundle a second DSH runtime.

This plugin is not an SBOM scanner, signer, audit logger, policy engine or archive. Existing tools already scan dependencies and individual 2Origin plugins already produce release, runtime, recovery, lineage and policy evidence. The missing layer is a small verifier that proves a particular subject/revision has enough pinned evidence from allowed, independent producers to cover declared controls.

Contract

An explicit manifest declares:

  • one subject ID and revision;
  • required controls with minimum eligible evidence, minimum distinct producers and allowed evidence types;
  • evidence files pinned by SHA-256;
  • JSON Pointers that bind every evidence file to the subject and revision;
  • value-hash assertions, so expected or observed values never enter the audit index.

Verification fails closed for missing, stale or invalid JSON evidence, subject/revision mismatch, failed assertions, disallowed types, insufficient evidence or insufficient independent producers. The output contains IDs, types, producers, paths into JSON, hashes, statuses, coverage and a deterministic SHA-256 pair-tree Merkle root. It never copies evidence bodies or assertion values.

Files must be workspace-relative regular files. Symlinks, path escape, oversized input and excessive structure are rejected. The plugin performs no network calls or child processes and writes only a content-addressed JSON index under the explicit artifactDir, followed by read-back verification.

CLI

node bin/dsh-audit-bundle.mjs inspect --workspace examples/basic --manifest audit.manifest.json
node bin/dsh-audit-bundle.mjs verify --workspace examples/basic --manifest audit.manifest.json --artifactDir artifacts

The CLI emits one JSON object. A failed audit verdict exits 2; invalid usage exits 1.

DeepSeek Harness and MCP

The DSH bundle registers dsh_audit_bundle_inspect and dsh_audit_bundle_verify. These workspace-bounded tools dereference pinned evidence and can write the content-addressed index. The companion stdio MCP server registers audit_bundle_inspect and audit_bundle_verify through .mcp.json, but accepts only an inline manifest and structural JSONL receipts containing IDs, hashes, producer/subject bindings and assertion digests. MCP never reads files, dereferences evidence, executes actions or writes artifacts; it reports evidenceContentVerification: not-performed. Use DSH or CLI for real evidence-content verification.

dsh plugin --profile audit-bundle add github:dongsheng123132/dsh-audit-bundle#<commit>
dsh --profile audit-bundle --dump-config

Verification

npm ci
npm test
npm run check
npm run smoke:plugin
npm run smoke:mcp
DSH_CHECKOUT=/path/to/built/deepseek-harness npm run smoke:dsh
DSH_CHECKOUT=/path/to/built/deepseek-harness DSH_HOME=/path/to/isolated-home npm run smoke:web-loader
python C:/Users/ZhuanZ/.codex/skills/.system/plugin-creator/scripts/validate_plugin.py .

CI runs on Ubuntu and Windows. Node.js 22 or newer. MIT licensed.