dongsheng123132/dsh-capability-receipt

Content-addressed receipts for skills actually loaded by DeepSeek Harness

Proves which skill DeepSeek Harness actually loaded: hashes the effective instruction body returned by ctx.skills.get(), records the winning provider/source/invocation policy, hashes a bounded resource-directory closure when local, and compares runtime observation with hashes pinned by a trusted source artifact — writing a deterministic content-addressed receipt. Tools: dsh_capability_receipt_inspect (structural fields + hashes, no instruction/metadata/path leakage), dsh_capability_receipt_issue (requires expectedContentSha256, writes only beneath an explicit workspace-relative artifactDir), dsh_capability_receipt_issue_from_pack (pack-agent lock bridge). MCP proof surface is read-only and in-memory. Fails closed on incomplete catalogs, mismatches, or unsafe resource closure.

Agent Capabilities ★ 4 updated 2026-09-07 ✅ runtime-tested
View on GitHub ↗

Install

dsh plugin --profile capability-proof add github:dongsheng123132/dsh-capability-receipt

GitHub install per README (pin a reviewed commit in an isolated profile): dsh plugin --profile capability-proof add github:dongsheng123132/dsh-capability-receipt#<commit>. The package declares its DSH bundle and ships cordis.patch.yml, so a successful install adds the layer automatically. No npm package published. Requires Node.js 22+; no install lifecycle scripts. MIT.

Compatibility

DeepSeek Harness (isolated profile recommended); Node.js 22+. Host-neutral — no private ToolRuntime helper; preserves the module-level inject = ['tools', 'skills'] contract in the built web profile.

Details

Recent updates

v0.3.0: host-neutral stock-Cordis-loader safe; inspect/issue/issue_from_pack tools; pack-agent lock bridge; SHA-256 receipts; fail-closed verification.

FAQ

What does a receipt prove?
That the effective skill body loaded in DSH matches a caller-supplied expected SHA-256 (or a pack-agent lock) at one runtime observation — it is evidence of equality, not a signature or trust anchor.
Does it modify the capability?
No — the plugin observes but never executes the target capability; it only hashes the effective body and writes receipts beneath an explicit artifactDir.
What is the MCP surface for?
A proof-only, in-memory stdio pair (inspect_lock / verify_recorded) that verifies an already-issued artifact — it cannot read files, hit the network, or write receipts.

Alternatives

030611/dsh-verification-receipt · omdsh-dev/dsh-security-audit · jkrandom-sudo/dsh-plugin-audit

More plugins in Agent Capabilities

Browse more in Agent Capabilities

Guides for Agent Capabilities plugins