Hyperionjust/dsh-tool-underseal
Hash-sealed, file-authorization protocol for delegating bounded work between AI agents, wrapped as model-facing typed tools for DeepSeek Harness. Chat is transport, not authorization: authority is a hash-sealed assignment file; evidence is append-only and re-derivable by any third party; every boundary fails closed — sealed tools, a worker check-in lock, and byte-pinned supply-chain sentinels. The frozen Python verifier is the only authority; this package is a process shell only and never reimplements validation. Ships the underseal-delegation DSH skill documenting the workflow in DSH terms (subagent / subagent_fork / workflow / goal).
Install
dsh plugin --profile web add dsh-tool-undersealnpm package dsh-tool-underseal 0.1.4 (registry-verified 2026-08-26): dsh plugin --profile web add dsh-tool-underseal. Tested on DSH 0.1.0-rc.5 — runtime mounting smoke test passed (dsh plugin add + dsh --dump-config mounts both underseal and underseal-guard layers). Field note: when dsh plugin add takes a local path containing spaces, wrap it in literal double quotes.
Compatibility
Tested on DeepSeek Harness 0.1.0-rc.5. Spawns the vendored underseal Python adapter through the ctx.subprocess seam; requires the adapter's canonical UNDERSEAL_ADAPTER_* marker; throws with E_* diagnostics on failure.
Details
- Repo: Hyperionjust/dsh-tool-underseal
- Category: Other
- Stars: 3
- Version: npm dsh-tool-underseal 0.1.4 (registry-verified 2026-08-26)
- Last push: 2026-08-14
- First seen: 2026-08-13
Recent updates
v0.1.4: hash-sealed delegation; fail-closed boundaries; worker check-in lock; supply-chain sentinels; underseal-delegation skill; rc.5 tested.
FAQ
- What makes it secure?
- Authority is a hash-sealed assignment file verified by a frozen Python verifier — the plugin is a process shell only and never reimplements validation.
- Does it fail open?
- No — every boundary fails closed: sealed tools, a worker check-in lock, and byte-pinned supply-chain sentinels.
- How does the agent use it?
- Each tool spawns the vendored adapter through ctx.subprocess, requires the UNDERSEAL_ADAPTER_* marker, and throws E_* diagnostics on failure.
Alternatives
MkaliezZ/dsh-agentfuse-plugin · jkrandom-sudo/dsh-plugin-audit · omdsh-dev/dsh-security-audit