dongsheng123132/dsh-audit-bundle
跨独立DeepSeek Harness证据生产者的内容寻址审计索引
项目介绍Project Overview
dsh-audit-bundle 是 DSH 安全插件,基于内容寻址为独立证据生产者构建审计索引。它读取清单中 SHA-256 钉住的证据文件,按 JSON Pointer 绑定主题与版本,校验哈希断言后输出含覆盖率、状态及确定性 Merkle 根的索引。适用于需要验证某个版本是否由足够的独立生产者提供声明控制证据的场景。注意:插件不进行网络调用,仅在显式 artifactDir 写入索引。
dsh-audit-bundle is a DSH security plugin that builds content-addressed audit indexes from independent evidence producers. It reads a manifest pinning evidence files by SHA-256, binds them to a subject and revision via JSON Pointers, validates value-hash assertions, and emits a JSON index with coverage, statuses, and a deterministic Merkle root. Use it to verify that a specific subject revision has sufficient pinned, independent evidence covering declared controls. Note: the plugin makes no network calls, rejects symlinks and path escapes, and writes only the index to the explicit artifactDir.
请帮我了解并安装插件:【dsh-audit-bundle】【https://github.com/dongsheng123132/dsh-audit-bundle】
把上面这条消息直接发给当前会话里的 DSH,让它帮你了解并安装。安装命令不一定准确,发给 DSH 更稳。Send this message to DSH in your current session. CLI install commands may not be accurate across systems — DSH will figure it out for you.
或使用命令行安装(适合开发者)Or use CLI install (for developers)
命令行安装CLI Install
dsh plugin --profile web add github:dongsheng123132/dsh-audit-bundle
把 dongsheng123132/dsh-audit-bundle 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-audit-bundle
Content-addressed audit indexes across independent DeepSeek Harness evidence producers.
Version 0.2 adds a formal proof-only Codex MCP surface, host-neutral DSH ToolDefinitions, real ToolRuntime calls and a stock Web Loader regression test. The package exposes namespace exports only and does not bundle a second DSH runtime.
This plugin is not an SBOM scanner, signer, audit logger, policy engine or archive. Existing tools already scan dependencies and individual 2Origin plugins already produce release, runtime, recovery, lineage and policy evidence. The missing layer is a small verifier that proves a particular subject/revision has enough pinned evidence from allowed, independent producers to cover declared controls.
Contract
An explicit manifest declares:
- one subject ID and revision;
- required controls with minimum eligible evidence, minimum distinct producers and allowed evidence types;
- evidence files pinned by SHA-256;
- JSON Pointers that bind every evidence file to the subject and revision;
- value-hash assertions, so expected or observed values never enter the audit index.
Verification fails closed for missing, stale or invalid JSON evidence, subject/revision mismatch, failed assertions, disallowed types, insufficient evidence or insufficient independent producers. The output contains IDs, types, producers, paths into JSON, hashes, statuses, coverage and a deterministic SHA-256 pair-tree Merkle root. It never copies evidence bodies or assertion values.
Files must be workspace-relative regular files. Symlinks, path escape, oversized input and excessive structure are rejected. The plugin performs no network calls or child processes and writes only a content-addressed JSON index under the explicit artifactDir, followed by read-back verification.
CLI
node bin/dsh-audit-bundle.mjs inspect --workspace examples/basic --manifest audit.manifest.json
node bin/dsh-audit-bundle.mjs verify --workspace examples/basic --manifest audit.manifest.json --artifactDir artifacts
The CLI emits one JSON object. A failed audit verdict exits 2; invalid usage exits 1.
DeepSeek Harness and MCP
The DSH bundle registers dsh_audit_bundle_inspect and dsh_audit_bundle_verify. These workspace-bounded tools dereference pinned evidence and can write the content-addressed index. The companion stdio MCP server registers audit_bundle_inspect and audit_bundle_verify through .mcp.json, but accepts only an inline manifest and structural JSONL receipts containing IDs, hashes, producer/subject bindings and assertion digests. MCP never reads files, dereferences evidence, executes actions or writes artifacts; it reports evidenceContentVerification: not-performed. Use DSH or CLI for real evidence-content verification.
dsh plugin --profile audit-bundle add github:dongsheng123132/dsh-audit-bundle#<commit>
dsh --profile audit-bundle --dump-config
Verification
npm ci
npm test
npm run check
npm run smoke:plugin
npm run smoke:mcp
DSH_CHECKOUT=/path/to/built/deepseek-harness npm run smoke:dsh
DSH_CHECKOUT=/path/to/built/deepseek-harness DSH_HOME=/path/to/isolated-home npm run smoke:web-loader
python C:/Users/ZhuanZ/.codex/skills/.system/plugin-creator/scripts/validate_plugin.py .
CI runs on Ubuntu and Windows. Node.js 22 or newer. MIT licensed.
toby-bridges/api-relay-audit
howmp/dsh-pentest
saya-ch/dsh-mobile
summer1238/dsh-remote-web-gateway
NanmiCoder/dsh-auto-mode
lire1131/dsh-undo-savepoint
liguobao/deepseek-harness-remote
PerryLink/dsh-auto-review