Introduction

The configuration management of DeepSeek Harness (DSH) relies on source priority and policy composition. When developers debug or audit configurations, they often need to confirm which source a final effective configuration actually comes from, and whether it has been overridden by a higher-priority source or a “shadow source.” Although DSH’s own --dump-config can display the composed result, it does not provide verifiable evidence about source ownership or the decision process. dsh-config-origin-proof is designed to fill this gap by using an evidence layer to translate configuration source decision processes into reproducible receipts.

Plugin Overview

dsh-config-origin-proof is a plugin that provides a configuration source ownership evidence layer for DeepSeek Harness. It is maintained by the user dongsheng123132.

The core purpose of this plugin is to convert structured records produced by trusted producers (such as the DSH composer) into reproducible evidence receipts. It does not reimplement the DSH composer or collect live configuration; DSH’s own --dump-config remains the authoritative source. It complements dsh-policy-drift-proof (checking policy changes) and dsh-profile-lock-proof (proving installation package integrity), focusing on answering “which recorded source won” and “why.”

Core Features

  1. Source Validation: Validates the ownership of DSH configuration sources.
  2. Reproducible Evidence: Provides reproducible evidence receipts to ensure the traceability of configuration decisions.
  3. Safe Redaction: Refuses raw values and sensitive fields (such as secrets, credentials, prompts, messages, or prose-shaped text), and reports only stable IDs, SHA-256 digests, and verdicts.
  4. Multi-interface Support: Supports DSH, CLI, and MCP operation modes.

Installation and Activation

Add the plugin to the specified DSH profile (for example, web) using the following command:

dsh plugin --profile web add github:dongsheng123132/dsh-config-origin-proof

Typical Usage

Depending on the usage scenario, the plugin provides a DSH interface, CLI commands, and an inline MCP interface.

CLI Verification

Run the verification command in the command line, specifying the workspace root directory, recording file, and output directory:

dsh-config-origin-proof verify --workspace-root examples --recording recording.json --artifact-dir artifacts

DSH Interface

In the DSH runtime environment, you can call the following interfaces:

  • dsh_config_origin_inspect
  • dsh_config_origin_verify

MCP Interface

MCP mode performs inline operations, with no filesystem, network, process, or artifact writes:

  • config_origin_inspect_inline
  • config_origin_verify_inline

Applicable Scenarios and Cautions

Applicable Scenarios: Development environments that require strict auditing of configuration sources, prevention of configuration injection attacks, or generation of tamper-resistant evidence for configuration decisions.

Cautions:
* Permissions and Security: The plugin runs with the permissions of the current DSH process; it is recommended to review the source code and license (MIT) before installation.
* Compatibility: The DSH version must satisfy >=0.1.2-alpha.4, and the Node.js version must satisfy >=22.
* Validation Logic: If a higher-priority source is not observed, the verifier fails closed, meaning it reports an error directly instead of continuing.
* Mode Differences: MCP mode is entirely in-memory and does not involve filesystem or network writes.

Summary

By using a content-addressed evidence mechanism, dsh-config-origin-proof makes the configuration management of DeepSeek Harness verifiable. It does not collect live configuration; instead, it provides an audit perspective based on trusted recording files, helping developers clarify the priority and decision rationale of configuration sources. For more details and source code, refer to the GitHub repository.