Foreword¶
The DSH philosophy is “everything is a plugin.” In agent development, whether a recorded authorization decision is consistent with its corresponding effect envelope is a critical boundary for verifying system state. This plugin provides offline, deterministic proof to verify whether the two match.
Plugin Overview¶
This plugin is maintained by dongsheng123132 and is designed to check the consistency of authorization/effect envelopes. It detects cases such as the effects of denied actions, authorized actions that are never settled, request/state/policy mismatches, missing confirmations, duplicate idempotency summaries, duplicates, and out-of-order evidence.
Core Capabilities¶
- Consistency Checks: Checks the consistency of authorization/effect envelopes.
- Anomaly Detection:
- Detects the effects of denied actions.
- Detects authorized actions that are never settled.
- Detects request/state/policy mismatches.
- Detects missing confirmations.
- Detects duplicate idempotency summaries.
- Detects duplicates.
- Detects out-of-order evidence. - Reporting Mechanism: Reports are content-addressed and verified by read-back after publication.
Tool Support¶
The plugin provides multiple tools for inspection and verification:
CLI Tools¶
dsh_decision_effect_inspectdsh_decision_effect_verify
MCP Tools¶
decision_effect_inspect_inline: Accepts inline JSON and cannot select filesystem paths.decision_effect_verify_inline: Accepts inline JSON.
File Tool Features¶
File tools accept workspace-relative paths, reject traversal and symbolic links, limit input size, write only to the specified artifact directory, publish atomically, and verify by read-back.
Installation¶
Install it through the DSH plugin manager:
dsh plugin --profile web add github:dongsheng123132/dsh-decision-effect-proof#COMMIT
Typical Usage¶
Inspect Evidence¶
dsh-decision-effect-proof inspect examples/decision-effects.
Verify Consistency¶
dsh-decision-effect-proof verify examples/decision-effects. artifacts
Applicable Scenarios and Notes¶
This plugin is intended to inspect explicit “bodyless evidence” to verify a narrower boundary that other layers cannot imply. It does not prove that effects occurred; it only proves that the receipts are internally consistent.
Important Notes:
- This plugin is not an approval engine, policy evaluator, action runtime, signature format, or prompt wrapper.
- The plugins that decide or enforce access are dsh-user-approval, dsh-auto-approval, dsh-tiered-approval, and dsh-permission-rules.
- Security boundaries are documented in SECURITY.md.
Summary¶
This plugin provides DSH developers with a rigorous method to verify the consistency between authorization decisions and effect envelopes, ensuring the reliability of system state.