dongsheng123132/dsh-windows-readiness-proof
Content-addressed readiness proof for sanitized DeepSeek Harness observations on managed Windows hosts
Evaluates a SHA-256-pinned, sanitized observation of a managed Windows host against explicit DeepSeek Harness readiness requirements, producing a deterministic artifact suitable for CI or audit. An explicit manifest fixes an opaque machine digest, snapshot revision, observation bytes, evaluation time, maximum evidence age, and requirements covering Windows product type/architecture/build and pending reboot; Node, DSH, PowerShell edition/version and language mode; classified WDAC, AppLocker, Defender, execution policy, Credential Guard and TLS 1.2 posture; long paths, atomic rename, workspace/temp ACL class and symlink policy; non-interactive session, opaque identity class, writable profile and recovery configuration; free storage; and connectivity identities represented only by endpoint SHA-256 plus status/TLS/proxy classes. It fails closed on missing, stale, future, malformed, secret-shaped, identity-bearing, path-escaping, symlinked or policy-mismatched evidence, and reports only opaque identities, hashes, classifications, reason codes and control status. It exposes dsh_windows_readiness_inspect and dsh_windows_readiness_verify (MCP aliases windows_readiness_inspect / windows_readiness_verify) plus a CLI (inspect / verify, exit 0 verified, exit 2 readiness or evidence failure).
Install
⚠️ Install command not yet confirmed — check the README on GitHub for the exact command.
Compatibility
Windows-focused evidence verification; the README says the plugin never runs PowerShell, reads the registry, changes Group Policy, creates Defender exclusions, edits WDAC/AppLocker, installs software, restarts services or probes the network — it only evaluates a pre-collected, sanitized observation. The DSH entry is a namespace plugin (name / inject / apply) with no default export, documented as part of the shipped compatibility contract with the real Cordis Loader.
Details
- Repo: dongsheng123132/dsh-windows-readiness-proof
- Category: Other
- Stars: 2
- Version: Git install pinned to a commit (README's documented form github:dongsheng123132/dsh-windows-readiness-proof#<commit>; no registry release)
- Last push: 2026-09-07
- First seen: 2026-08-14
Recent updates
The README documents what the plugin proves, the fail-closed evidence rules, the CLI and the DSH/MCP tool names rather than a versioned changelog; there is no release history or migration section and no published version. MIT-licensed. Verify the current install instructions in the repository before installing.
FAQ
- How do I install dsh-windows-readiness-proof?
- The README publishes dsh plugin --profile windows-readiness add github:dongsheng123132/dsh-windows-readiness-proof#<commit> — pin a reviewed commit; no registry release exists (404 verified 2026-09-13).
- Does it collect data from the machine?
- No — the README says it is an evidence verifier, not a collector: it never runs PowerShell, reads the registry, changes policy, installs software, restarts services or probes the network, and it evaluates a SHA-256-pinned sanitized observation.
- What tools does it expose?
- dsh_windows_readiness_inspect and dsh_windows_readiness_verify (MCP aliases windows_readiness_inspect / windows_readiness_verify), plus a CLI where exit 0 means verified and exit 2 means a readiness or evidence failure.
Alternatives
SepineTam/mcp-for-stata · PerryLink/dsh-mcp-panel · hyqhyq3/dsh-mcp-manager