Introduction¶
In the development workflow of DeepSeek Harness (DSH), verifying the integrity of build artifacts or files is a common requirement. Reading file contents directly can consume context window and may expose sensitive data. Traditional text hashing tools often require file contents to be passed into the model, which is inconsistent with principles of security and efficiency. dsh-file-checksum solves this problem by using DSH’s active filesystem provider to compute only the raw SHA-256 or SHA-512 checksum of a file without passing the file contents to the model.
Plugin Overview¶
dsh-file-checksum is a read-only plugin for DeepSeek Harness, maintained by developer yan9651688, and released under the MIT license.
The core value of this plugin is “not exposing content.” It reads files through ctx.fs, does not invoke a shell, does not bypass the filesystem provider, and does not access the network. It computes the hash of the file’s raw bytes and returns a structured checksum result for the model to use when verifying file integrity.
Installation and Configuration¶
Installing this plugin requires DSH’s plugin management commands.
- Add the plugin to a specified profile:
dsh plugin --profile web add github:yan9651688/dsh-file-checksum
- To ensure a reproducible installation, it is recommended to pin a specific commit:
dsh plugin --profile web add github:yan9651688/dsh-file-checksum#<commit-sha>
After installation, start the profile to use the plugin.
Tool Usage¶
The plugin provides a tool named file_checksum.
Parameter Description:
| Parameter Name | Required | Description |
|---|---|---|
file_path |
Yes | An absolute path, or a path relative to the current agent session workspace |
algorithm |
No | Hash algorithm, sha256 (default) or sha512 |
expected |
No | Expected hexadecimal digest. The tool returns match or mismatch |
Typical Usage Example:
In a prompt, you can directly ask the model to use this tool:
Use file_checksum to verify dist/app.tgz against this SHA-256: <digest>
Return Result:
The tool returns structured JSON data, including the path, algorithm, digest, byte count, and verification status.
{
"path": "/workspace/dist/app.tgz",
"algorithm": "sha256",
"digest": "...",
"bytes": 12345,
"verification": "match"
}
If the checksum does not match, the returned JSON contains verification set to mismatch. If the file is missing, not a regular file, too large, or unreadable, an error is returned.
Configuration Options¶
The plugin has a default single-file size limit of 64 MiB to prevent out-of-memory errors.
In the profile configuration, this limit can be adjusted using the maxBytes parameter, up to a maximum of 256 MiB.
- insert:
- id: file-checksum
name: dsh-file-checksum
config:
maxBytes: 67108864
Data and Security¶
The plugin is designed with security in mind:
- Read-only operations: The plugin is declared read-only and does not invoke a shell or access environment variables, credentials, or the network.
- Raw bytes: File contents are read without a shell, processed directly through
ctx.fs, and the result does not include the file content itself. - Concurrency control: Checksum invocations are declared mutually exclusive to prevent concurrent calls in Native or Code Mode batch processing from exceeding memory limits.
- Integrity logging: Both successful and failed reads are recorded via DSH’s
fs/observedevent, staying consistent with built-in file reading behavior.
Known Limitations¶
When using this plugin, note the following limitations:
- Single-file invocation: Each call only supports computing the checksum for one file. Directories and Git tree hashes are not supported.
- Size limit: Files exceeding
maxBytesare rejected. Streaming reads or truncation are not supported. - Version compatibility: The plugin depends on DSH 0.1.0-rc.6 and compatible 0.1.x versions. Because DSH is in developer preview, upstream breaking changes may require plugin updates.
- Pure ESM: The plugin is written in pure ESM JavaScript, so GitHub installation does not require a build step.
Conclusion¶
dsh-file-checksum provides DeepSeek Harness with a secure and efficient way to verify file integrity. By leveraging DSH’s filesystem capabilities, it computes hashes without exposing file contents, making it suitable for scenarios such as build workflow verification and file distribution validation.
Plugin directory: https://www.skillhub.cn/plugins/yan9651688/dsh-file-checksum
GitHub repository: https://github.com/yan9651688/dsh-file-checksum