Foreword

The DSH philosophy is “everything is a plugin.” In agent development, whether a recorded authorization decision is consistent with its corresponding effect envelope is a critical boundary for verifying system state. This plugin provides offline, deterministic proof to verify whether the two match.

Plugin Overview

This plugin is maintained by dongsheng123132 and is designed to check the consistency of authorization/effect envelopes. It detects cases such as the effects of denied actions, authorized actions that are never settled, request/state/policy mismatches, missing confirmations, duplicate idempotency summaries, duplicates, and out-of-order evidence.

Core Capabilities

  1. Consistency Checks: Checks the consistency of authorization/effect envelopes.
  2. Anomaly Detection:
    - Detects the effects of denied actions.
    - Detects authorized actions that are never settled.
    - Detects request/state/policy mismatches.
    - Detects missing confirmations.
    - Detects duplicate idempotency summaries.
    - Detects duplicates.
    - Detects out-of-order evidence.
  3. Reporting Mechanism: Reports are content-addressed and verified by read-back after publication.

Tool Support

The plugin provides multiple tools for inspection and verification:

CLI Tools

  • dsh_decision_effect_inspect
  • dsh_decision_effect_verify

MCP Tools

  • decision_effect_inspect_inline: Accepts inline JSON and cannot select filesystem paths.
  • decision_effect_verify_inline: Accepts inline JSON.

File Tool Features

File tools accept workspace-relative paths, reject traversal and symbolic links, limit input size, write only to the specified artifact directory, publish atomically, and verify by read-back.

Installation

Install it through the DSH plugin manager:

dsh plugin --profile web add github:dongsheng123132/dsh-decision-effect-proof#COMMIT

Typical Usage

Inspect Evidence

dsh-decision-effect-proof inspect examples/decision-effects.

Verify Consistency

dsh-decision-effect-proof verify examples/decision-effects. artifacts

Applicable Scenarios and Notes

This plugin is intended to inspect explicit “bodyless evidence” to verify a narrower boundary that other layers cannot imply. It does not prove that effects occurred; it only proves that the receipts are internally consistent.

Important Notes:
- This plugin is not an approval engine, policy evaluator, action runtime, signature format, or prompt wrapper.
- The plugins that decide or enforce access are dsh-user-approval, dsh-auto-approval, dsh-tiered-approval, and dsh-permission-rules.
- Security boundaries are documented in SECURITY.md.

Summary

This plugin provides DSH developers with a rigorous method to verify the consistency between authorization decisions and effect envelopes, ensuring the reliability of system state.

GitHub Repository