dongsheng123132/dsh-policy-drift-proof

Plugin插件 Native原生 ⭐ 2 MIT Approval & Security审批与安全

面向DeepSeek Harness的基于内容寻址、值遮蔽的策略漂移证据

Project Overview项目介绍

dsh-policy-drift-proof is a read-only evidence plugin for DeepSeek Harness. It pins a baseline and observed policy-snapshot/v1 by SHA-256, then classifies changes at declared JSON Pointer roots as ordered-not-weaker, set-no-additions, exact, or unclassified, emitting only paths, classifications, and digests. Use it when auditing whether an operator-observed policy snapshot diverged from a pinned baseline. Note: it produces evidence only; it does not enforce, scan, or repair configuration.

dsh-policy-drift-proof 是面向 DeepSeek Harness 的只读策略漂移证据插件。它通过 SHA-256 钉住基线与观测的 policy-snapshot/v1,按 JSON Pointer 规则判定变更属于削弱、放宽、精确或不分类,并仅输出路径、分类与摘要。适用于需要审计策略快照是否偏离钉定基线的场景。注意:它不强制执行、不扫描修复,仅对所提供的快照生成证据。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:dongsheng123132/dsh-policy-drift-proof

把 dongsheng123132/dsh-policy-drift-proof 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-policy-drift-proof

CI MIT license Node.js 22+ Awesome DSH Plugins

Read-only, content-addressed policy/configuration drift evidence for DeepSeek Harness.

Version 0.2 adds host-neutral DSH ToolDefinitions, a proof-only inline Codex MCP surface, real ToolRuntime calls and a stock Web Loader regression. The package exposes namespace exports only and does not bundle a second DSH runtime.

This plugin does not enforce tool calls, approve actions, scan repositories, or repair configuration. dsh-tool-policy already provides pre-execution policy routing, while SecurStack provides security scans and policy gates. This plugin covers the missing evidence question: did the policy snapshot actually observed by an operator differ from the pinned baseline, and was the difference weakening, tightening, exact, or unclassified?

Evidence model

The explicit manifest pins a baseline and observed policy-snapshot/v1 by SHA-256 and revision. Rules cover declared JSON Pointer roots:

  • ordered-not-weaker: enum order is restrictive to permissive; moving right fails.
  • set-no-additions: additions fail, removals are recorded as tightening.
  • exact: any change fails.
  • any changed covered leaf without a rule fails closed as UNCLASSIFIED_DRIFT.

Reports include paths, classifications and SHA-256 digests only. They never include policy values. Secret-shaped fields, raw output fields, absolute/escaping paths, symlinks, oversized inputs and excessive structure are rejected. The verifier performs no network calls or child processes and writes only one content-addressed JSON report beneath the explicit artifactDir, then reads it back and verifies its digest.

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev suanzhang-dsh 下一个 Next dsh-recall →