DeepSeek Harness 插件

dsh-surface-contract-proof

Content-addressed conformance proof across recorded DSH ToolRuntime, MCP JSON-RPC and CLI JSON surfaces(英文原文)

跳到安装方式

来源信息

GitHub 仓库
dongsheng123132/dsh-surface-contract-proof
最近更新
2026年8月20日
分类
插件开发工具
GitHub stars
2
载体类型
plugin
目录证据
上游声明已找到 dsh.bundle
证据路径
package.json#dsh.bundle
核对版本
0.1.0-rc.8
上游核对日期
2026-08-20

该证据由上游目录提供。本站没有安装、运行或安全审核这个插件。

安装

默认先复制一段 Prompt,让 Agent 读 GitHub 仓库和源码;需要自己装时再切到命令。

复制这段 Prompt,发给 DSH、Codex 或其他 Agent,让它先读 GitHub 仓库和源码。

请先不要安装或执行任何命令。阅读这个插件的 GitHub 仓库、README 和关键源码,然后用清楚、直接的方式回答以下问题,帮助我判断它是否适合我的需求:

1. 这个插件是什么,解决什么问题;
2. 适合哪些用户和典型使用场景;
3. 安装后如何使用,并给出一个最小使用示例;
4. 有哪些已知限制,以及隐私、安全、兼容性或维护风险;
5. 给出“推荐 / 有条件推荐 / 不推荐”的明确建议和理由。

请区分仓库明确说明、根据源码推断和未知信息。证据不足时请明确说明,不要猜测或照抄 README。

GitHub:https://github.com/dongsheng123132/dsh-surface-contract-proof
插件名:dsh-surface-contract-proof
作者:dongsheng123132

检查来源文件

安装前先看这个插件目录里的 README 和其他文件。

文件资源管理器3 个文件
README.md来源说明 · 只读预览

dsh-surface-contract-proof

![CI](https://github.com/dongsheng123132/dsh-surface-contract-proof/actions/workflows/ci.yml) ![MIT license](LICENSE) ![Node.js 22+](package.json) ![Awesome DSH Plugins](https://github.com/dongsheng123132/awesome-dsh-plugins#2origin-plugin-lab)

dsh-surface-contract-proof verifies that recorded DeepSeek Harness ToolRuntime, MCP JSON-RPC, and CLI JSON envelopes preserve one pinned semantic contract across a baseline and an observed revision.

Version 0.2.0 removes the bundled DSH tool runtime and the default export that stock Cordis Loader misclassified. It exposes host-neutral tool definitions through its namespace export and is regression-tested through real local-path and fixed-commit stock Web profiles.

It reads explicit, SHA-256-pinned JSON fixtures. It does not execute the target, start arbitrary commands, call a network service, replay side effects, or implement an action core.

Complementary boundary

dsh-action-parity proves that interfaces bind the same Action ID/core and that runtime success/conflict behavior is reachable. This plugin answers a different upgrade question: given immutable recordings, did request/response schema versions, success bits, error classes, exit-code mapping, conflict and confirmation semantics, normalization, timeout/stale/out-of-order behavior, and result digests remain identical across ToolRuntime, MCP, and CLI?

Generic OpenAPI/Pact tools validate HTTP consumer-provider contracts. This verifier is specific to the three DSH machine surfaces and uses offline recorded envelopes.

Safety and evidence

  • Exactly three surface kinds are required: dsh-toolruntime, mcp-jsonrpc, and cli-json.
  • Baseline and observed fixtures bind target revisions, contract/schema versions, transport versions, and SHA-256 bytes.
  • Surface-specific fields normalize into one canonical case digest; the manifest pins each expected digest.
  • Missing, stale, malformed, secret-shaped, schema/version-drifted, or semantically different fixtures fail closed.
  • Reports expose hashes, identities, statuses, and differing field names only—never request arguments, response bodies, CLI output, prompts, messages, credentials, or secrets.
  • Paths are workspace-relative regular files; traversal and symlinks are rejected. Writes are atomic, read back, and limited to explicit artifactDir.

CLI

dsh-surface-contract-proof inspect --workspace . --manifest contract.json
dsh-surface-contract-proof verify --workspace . --manifest contract.json --artifactDir artifacts

Use inspect to obtain canonical baseline digests, review them, then pin them as cases[].expectedSha256. Exit 0 means verified; exit 2 means failed or invalid evidence.

DSH / MCP tools

  • dsh_surface_contract_inspect
  • dsh_surface_contract_verify
  • MCP aliases: surface_contract_inspect, surface_contract_verify

The MCP surface is proof-only and in-memory: it accepts bounded inline manifest/fixture JSON, reads or writes no files, and returns no fixture bodies. DSH/CLI may write only a content-addressed report beneath an explicit workspace-relative artifactDir, with atomic read-back verification.

dsh plugin --profile surface-contract add github:dongsheng123132/dsh-surface-contract-proof#<commit>

Development

npm ci
npm test
npm run check
npm run smoke:plugin
npm run smoke:mcp

MIT licensed. See [SECURITY.md](SECURITY.md).