dongsheng123132/dsh-capability-receipt
Content-addressed receipts for skills actually loaded by DeepSeek Harness
Proves which skill DeepSeek Harness actually loaded: hashes the effective instruction body returned by ctx.skills.get(), records the winning provider/source/invocation policy, hashes a bounded resource-directory closure when local, and compares runtime observation with hashes pinned by a trusted source artifact — writing a deterministic content-addressed receipt. Tools: dsh_capability_receipt_inspect (structural fields + hashes, no instruction/metadata/path leakage), dsh_capability_receipt_issue (requires expectedContentSha256, writes only beneath an explicit workspace-relative artifactDir), dsh_capability_receipt_issue_from_pack (pack-agent lock bridge). MCP proof surface is read-only and in-memory. Fails closed on incomplete catalogs, mismatches, or unsafe resource closure.
Install
dsh plugin --profile capability-proof add github:dongsheng123132/dsh-capability-receiptGitHub install per README (pin a reviewed commit in an isolated profile): dsh plugin --profile capability-proof add github:dongsheng123132/dsh-capability-receipt#<commit>. The package declares its DSH bundle and ships cordis.patch.yml, so a successful install adds the layer automatically. No npm package published. Requires Node.js 22+; no install lifecycle scripts. MIT.
Compatibility
DeepSeek Harness (isolated profile recommended); Node.js 22+. Host-neutral — no private ToolRuntime helper; preserves the module-level inject = ['tools', 'skills'] contract in the built web profile.
Details
- Repo: dongsheng123132/dsh-capability-receipt
- Category: Agent Capabilities
- Stars: 4
- Version: GitHub source v0.3.0 (host-neutral; no npm package)
- Last push: 2026-09-07
- First seen: 2026-08-14
Recent updates
v0.3.0: host-neutral stock-Cordis-loader safe; inspect/issue/issue_from_pack tools; pack-agent lock bridge; SHA-256 receipts; fail-closed verification.
FAQ
- What does a receipt prove?
- That the effective skill body loaded in DSH matches a caller-supplied expected SHA-256 (or a pack-agent lock) at one runtime observation — it is evidence of equality, not a signature or trust anchor.
- Does it modify the capability?
- No — the plugin observes but never executes the target capability; it only hashes the effective body and writes receipts beneath an explicit artifactDir.
- What is the MCP surface for?
- A proof-only, in-memory stdio pair (inspect_lock / verify_recorded) that verifies an already-issued artifact — it cannot read files, hit the network, or write receipts.
Alternatives
030611/dsh-verification-receipt · omdsh-dev/dsh-security-audit · jkrandom-sudo/dsh-plugin-audit