030611/qiushi-dsh-evidence-audit

Observe-only hash-chained evidence receipts for DeepSeek Harness

Qiushi DSH Evidence Audit is an observe-only Profile Bundle that leaves a locally checkable execution trail without storing prompts, tool arguments, tool results, or session IDs in plaintext. It listens to tools/result and session/event extension points and appends deterministic, hash-chained JSONL evidence receipts. Each receipt is canonicalized and hashed — the chain makes any tampering detectable. Designed for audit, compliance, and transparency use cases where execution evidence must be verifiable without leaking content.

Coding & Development ★ 5 updated 2026-08-14 ✅ runtime-tested
View on GitHub ↗

Install

dsh plugin --profile web add qiushi-dsh-evidence-audit

npm package qiushi-dsh-evidence-audit 0.1.0 (registry-verified 2026-08-24). Observe-only Profile Bundle — install and restart. Listens to the official tools/result and session/event extension points. Never registers a model-facing tool, changes a prompt, or transforms a tool result. Related trust-layer plugins from the same author: dsh-verification-receipt, dsh-telemetry-redactor, dsh-context-provenance.

Compatibility

DeepSeek Harness web profile (any), Node.js ^22.19.0 || >=24.0.0. Observe-only — no model requests, no prompt changes, no tool results transformed. Community-maintained; not an official DeepSeek project.

Details

Recent updates

0.1.0: observe-only hooks on tools/result and session/event; deterministic hash-chained JSONL evidence receipts; canonicalization before hashing; no plaintext prompts/arguments/results/session IDs in output; zero model-facing tools registered.

FAQ

What is the difference from dsh-verification-receipt?
dsh-verification-receipt is a heuristic per-turn summary with lexical verification signals. qiushi-dsh-evidence-audit produces a deterministic, hash-chained JSONL audit trail — each entry is cryptographically linked to the previous, making tampering detectable. Neither stores prompts or tool arguments in plaintext.
Can I verify the receipt chain myself?
Yes — the JSONL file is a locally stored hash chain. Each record's hash covers the canonicalized observation plus the previous record's hash, so any modification to past records breaks the chain. Local verification tools are described in the repository.
Does it work with headless DSH?
The plugin hooks the standard tools/result and session/event extension points, which are available in both web and headless profiles. Install into the profile you want to audit.

Alternatives

030611/dsh-verification-receipt · omdsh-dev/dsh-session-health · omdsh-dev-dsh-record-replay

More plugins in Coding & Development

Browse more in Coding & Development

Guides for Coding & Development plugins