dongsheng123132/dsh-windows-readiness-proof

Content-addressed readiness proof for sanitized DeepSeek Harness observations on managed Windows hosts

Evaluates a SHA-256-pinned, sanitized observation of a managed Windows host against explicit DeepSeek Harness readiness requirements, producing a deterministic artifact suitable for CI or audit. An explicit manifest fixes an opaque machine digest, snapshot revision, observation bytes, evaluation time, maximum evidence age, and requirements covering Windows product type/architecture/build and pending reboot; Node, DSH, PowerShell edition/version and language mode; classified WDAC, AppLocker, Defender, execution policy, Credential Guard and TLS 1.2 posture; long paths, atomic rename, workspace/temp ACL class and symlink policy; non-interactive session, opaque identity class, writable profile and recovery configuration; free storage; and connectivity identities represented only by endpoint SHA-256 plus status/TLS/proxy classes. It fails closed on missing, stale, future, malformed, secret-shaped, identity-bearing, path-escaping, symlinked or policy-mismatched evidence, and reports only opaque identities, hashes, classifications, reason codes and control status. It exposes dsh_windows_readiness_inspect and dsh_windows_readiness_verify (MCP aliases windows_readiness_inspect / windows_readiness_verify) plus a CLI (inspect / verify, exit 0 verified, exit 2 readiness or evidence failure).

Other ★ 2 updated 2026-09-07 ✅ runtime-tested
View on GitHub ↗

Install

⚠️ Install command not yet confirmed — check the README on GitHub for the exact command.

Compatibility

Windows-focused evidence verification; the README says the plugin never runs PowerShell, reads the registry, changes Group Policy, creates Defender exclusions, edits WDAC/AppLocker, installs software, restarts services or probes the network — it only evaluates a pre-collected, sanitized observation. The DSH entry is a namespace plugin (name / inject / apply) with no default export, documented as part of the shipped compatibility contract with the real Cordis Loader.

Details

Recent updates

The README documents what the plugin proves, the fail-closed evidence rules, the CLI and the DSH/MCP tool names rather than a versioned changelog; there is no release history or migration section and no published version. MIT-licensed. Verify the current install instructions in the repository before installing.

FAQ

How do I install dsh-windows-readiness-proof?
The README publishes dsh plugin --profile windows-readiness add github:dongsheng123132/dsh-windows-readiness-proof#<commit> — pin a reviewed commit; no registry release exists (404 verified 2026-09-13).
Does it collect data from the machine?
No — the README says it is an evidence verifier, not a collector: it never runs PowerShell, reads the registry, changes policy, installs software, restarts services or probes the network, and it evaluates a SHA-256-pinned sanitized observation.
What tools does it expose?
dsh_windows_readiness_inspect and dsh_windows_readiness_verify (MCP aliases windows_readiness_inspect / windows_readiness_verify), plus a CLI where exit 0 means verified and exit 2 means a readiness or evidence failure.

Alternatives

SepineTam/mcp-for-stata · PerryLink/dsh-mcp-panel · hyqhyq3/dsh-mcp-manager

More plugins in Other

Browse more in Other

Guides for Other plugins