Introduction¶
In DeepSeek Harness (DSH) development practice, distinguishing capabilities declared by a plugin from the behavior actually produced at runtime is the foundation of security and compliance. A plugin author may declare support for network access or file writing, but those operations may not be triggered within the current execution window. The dsh-runtime-nutrition-label plugin addresses this information asymmetry by observing DSH tool and filesystem event seams and generating a JSON snapshot that includes declarations, observations, and inferred evidence.
What It Is¶
This is a community-maintained plugin that provides evidence-based runtime “nutrition labels” for DeepSeek Harness plugin and tool namespaces. It separates declarations made by authors or deployers from actually observed metrics, helping developers confirm the real behavior pattern of a plugin in the current session. The plugin is licensed under the MIT License.
Core Features¶
The plugin mainly provides the following capabilities:
- Capability declaration and observation: Supports declarations of capabilities such as network, credentials, subprocesses, persistence, and domains, and collects success/failure statistics for actual invocations.
- Metrics collection:
- Tool metrics: Records schema byte size, invocation count, success rate, failure rate, and duration statistics.
- Filesystem metrics: Records read/write counts, number of unique targets, and privacy-controlled path samples.
- Network scanning: Scans only hostnames in HTTP(S) URLs and does not record full URLs, query parameters, fragments, or credentials.
- Evidence records: Provides bounded evidence records containing declaration, observation, and inference provenance.
- Automatic integration: Automatically integrates into the specified Profile via a
dsh.bundlepatch and mounts services and commands.
Installation and Enablement¶
Install the plugin into the specified Profile using the DSH command line:
dsh plugin --profile web add dsh-runtime-nutrition-label
After installation, the plugin automatically adds itself to dsh.profile.bundles and mounts the ctx.runtimeNutritionLabels service and the /nutrition-label command. By default, tools without configured attributes have an effective label of unattributed.
Typical Usage¶
1. Configure Attribute Mapping¶
In the Profile’s cordis.patch.yml, override the runtime-nutrition-label entry to explicitly specify the plugin ID, tool prefixes, capability declarations, and side-effect classification:
- id: runtime-nutrition-label
config:
plugins:
- id: mcp-github
displayName: GitHub MCP
tools:
prefixes:
- mcp__github__
declared:
network: true
credentials: true
domains:
- api.github.com
effects:
- prefixes:
- mcp__github__create_
- mcp__github__merge_
effect: write
2. View Snapshot¶
Get a snapshot via the /nutrition-label [plugin-id] command or the API:
/nutrition-label
Call it in code:
ctx.runtimeNutritionLabels.snapshot()
ctx.runtimeNutritionLabels.snapshot('mcp-github')
The snapshot contains an ISO timestamp, a monotonically increasing revision, configured declarations, observed aggregate metrics, and bounded evidence records.
Use Cases and Notes¶
- Privacy-first model: The plugin does not store raw tool parameters, raw results, file contents, or credential values. Network scanning retains only hostnames, and file samples default to
omit. - Local diagnostics: Evidence records are bounded and intended for local diagnostics rather than long-term audit archives.
- Runtime peer dependencies: Because the current public DSH dependency graph is incomplete, the plugin requires specific DSH runtime peers (such as
dsh-tools,dsh-fs, etc.) to function properly. - Non-official maintenance: This is a community-maintained package, not an official DeepSeek AI component. Check the source code and license before integration.
Brief Closing¶
By separating declarations from observed facts, the plugin provides an observable skeleton for DSH plugin runtime behavior. Developers can quickly validate a plugin’s permission usage and behavior pattern in the current session through the /nutrition-label command or the API.
- GitHub repository: https://github.com/biubiukam/dsh-runtime-nutrition-label
- Community directory: https://www.skillhub.cn/plugins/biubiukam/dsh-runtime-nutrition-label