dongsheng123132/dsh-capability-receipt
DeepSeek Harness 实际加载技能的内容寻址收据
Project Overview项目介绍
dsh-capability-receipt is a DeepSeek Harness plugin that proves which skill the runtime actually loaded. It hashes the effective instruction body from ctx.skills.get(), records the winning provider, source, and invocation policy, and—under a local resource base—hashes a bounded resource-directory closure, then reconciles the observation against a trusted source artifact and writes a deterministic content-addressed receipt. Use it to close the last hop between a pinned source artifact and the effective DSH capability. Caveat: a verified receipt proves equality at one runtime observation only; it is not a signature, does not attest usefulness, and does not guarantee that the skill was executed correctly.
dsh-capability-receipt 是 DeepSeek Harness 插件,用于为已加载的技能生成确定性、内容寻址的收据。它通过哈希 ctx.skills.get() 返回的指令体、记录来源、provider 与调用策略,并在资源为本地目录时哈希其有界闭包,进而与受信任的源制品对账。适用于在固定制品与运行时能力之间补齐最后一跳证明。需注意:收据仅证明一次 DSH 运行时观察的相等性,不证明技能安全性或外部行为正确性,需另行固定受信任提交并保留评审证据。
请帮我了解并安装插件:【dsh-capability-receipt】【https://github.com/dongsheng123132/dsh-capability-receipt】
Send this message to DSH in your current session. CLI install commands may not be accurate across systems — DSH will figure it out for you.把上面这条消息直接发给当前会话里的 DSH,让它帮你了解并安装。安装命令不一定准确,发给 DSH 更稳。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile capability-proof add \
把 dongsheng123132/dsh-capability-receipt 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-capability-receipt
dsh-capability-receipt proves which skill DeepSeek Harness actually loaded. It hashes the effective instruction body returned by ctx.skills.get(), records the winning provider/source/invocation policy, and—when the resource base is local—hashes a bounded resource-directory closure. It can then compare that runtime observation with hashes pinned by a trusted source artifact and write a deterministic content-addressed receipt.
This is deliberately not another skill package format, dependency resolver, installer, registry, evaluator, per-turn summary, or event audit ledger. Use pack-agent for packaging and distribution; use this plugin for the missing last hop between a fixed source artifact and the effective capability inside DSH.
Version 0.3.0 is host-neutral: the DSH entry does not import a private ToolRuntime helper and exposes no default export, so the stock Cordis loader preserves the module-level inject = ['tools', 'skills'] contract in the built web profile.
DSH tools
dsh_capability_receipt_inspect: returns structural fields and hashes without returning skill instructions, metadata, or absolute paths.dsh_capability_receipt_issue: requiresexpectedContentSha256, accepts optional resource/provider/source/invocation expectations, and writes only beneath an explicit workspace-relativeartifactDir.dsh_capability_receipt_issue_from_pack: reads a workspace-relative pack-agentagent-pack/lock/v1, recomputes pack-agent's directory and portable-bundle skill hashes, requires the effective DSH body to equal the lockedSKILL.mdbody, checks optional provider/source/invocation expectations, and writes the same receipt format.
The plugin observes but never executes the target capability. A receipt fails closed when the DSH catalog is incomplete or changes during observation, when the loaded definition disagrees with its catalog entry, when an expectation mismatches, or when resources cannot be safely closed.
MCP proof surface
The formal .mcp.json declaration exposes two stdio tools:
capability_receipt_inspect_lockparses one explicit inline pack-agent lock and returns only identities and hashes.capability_receipt_verify_recordedcompares an explicit recorded DSH content/resource digest envelope with that lock and returns a content-addressed verdict.
This MCP surface is intentionally proof-only and in-memory. It cannot inspect the live DSH registry, read files, access the network, execute a capability, or write a receipt. Live observation and artifact issuance remain DSH ToolRuntime responsibilities, sharing the same core verifier.
pack-agent bridge
After pack-agent has exported/installed a pack, issue a receipt against its lock without translating it into another manifest:
pack-agent .agent-pack/lock.json
│ skill contentHash + fileCount
▼
dsh_capability_receipt_issue_from_pack
│ recompute pack-agent hash + compare loaded SKILL.md body
▼
content-addressed DSH runtime receipt
Required inputs are skillName, packLockPath, and artifactDir. The lock's ref and lockedAt are not copied into the receipt. The bridge currently pins the hash contract observed at pack-agent commit e2db1f8f56b74b64597a01175c810358f2c0b450; the fixture records the exact upstream Git blobs. Both directory-source and portable-bundle path forms are recognized, and the matched form is explicit in verification.matchedHashMode.
Install in DSH
Pin a reviewed commit in an isolated DSH profile:
dsh plugin --profile capability-proof add \
github:owner/dsh-capability-receipt#<commit>
The package declares its DSH bundle and ships cordis.patch.yml, so a successful plugin install adds the layer to that profile automatically.
Offline receipt verification
The CLI never discovers or loads skills. It only verifies an already-issued artifact:
dsh-capability-receipt verify \
--receipt artifacts/capability-receipt-<sha256>.json \
--require-verified
stdout is one JSON result. Failures go to stderr and exit with code 4; usage errors exit with code 1.
Resource safety
Directory closure defaults to at most 256 regular files, 1 MiB per file, and 8 MiB total. Symbolic links and special files are rejected. URL and opaque resource bases are disclosed as unavailable rather than fetched. Limits may be lowered or raised in trusted DSH plugin configuration.
Development
npm install
npm test
npm run check
npm run smoke:plugin
npm run smoke:mcp
DSH_CHECKOUT=/path/to/deepseek-harness npm run smoke:dsh
Requires Node.js 22 or newer. No install lifecycle scripts are used.
Security boundary
A verified receipt proves equality with caller-supplied expectations or one pack-agent lock at one DSH runtime observation. A pack lock is evidence input, not a signature or trust anchor: the bridge verifies its equality to runtime files and the effective body, but does not prove who produced the lock. It also does not prove that the skill is useful or safe, that the capability was executed, or that external model/tool behavior was correct. Pin trusted source commits and preserve their review/evaluation evidence separately.
YuJunZhiXue/dsh-purge
yejiming/MuseAI
superdesigndev/superdesign-skill
FSMargoo/dsh-at-file
Rain-kl/dsh-preset-plus
bugmaker2/dsh-plugin-template