Introduction

DeepSeek Harness (DSH) adopts an everything-is-a-plugin architecture. During plugin loading and tool invocation, there is often a need to verify loading state, injection closure, and tool Schema settlement. The dsh-loader-settlement-proof plugin provides an offline evidence layer for recording and settling information about these DSH Loaders.

What Is It

The plugin is maintained by dongsheng123132 and belongs to the admin-security category. It generates deterministic, content-addressed JSON for verifying DSH Loader revisions and contract bindings, lifecycle states, and tool Schema receipts.

Core Features

  1. Offline Evidence Layer: Generates deterministic, content-addressed JSON to support offline audit.
  2. Lifecycle Verification: Verifies the declared → resolved → loaded → activated lifecycle.
  3. Binding and Receipts: Verifies DSH Loader revisions and contract bindings, tool names, and their Schema SHA-256 receipts.
  4. State Checks: Verifies requests against resolved injections, enabled/required entry activation, and classified failures.
  5. Collision Detection: Verifies duplicate entries, stages, tools, and cross-entry tool collisions.
  6. Byte Verification: DSH tools/CLI can publish and verify bytes under an explicit artifactDir.
  7. MCP Support: MCP tools are inline-only.

Installation and Enabling

To add the plugin in a DSH environment, specify the exact commit hash or tag:

dsh plugin --profile web add github:dongsheng123132/dsh-loader-settlement-proof#<commit>

Typical Usage

After installation, you can use CLI commands to inspect and verify settlement evidence:

dsh-loader-settlement-proof inspect examples/settlement.json
dsh-loader-settlement-proof verify examples/settlement.json artifacts

You can also invoke them directly as DSH tools:
- dsh_loader_settlement_inspect
- dsh_loader_settlement_verify

For MCP environments, you can use:
- loader_settlement_inspect_inline
- loader_settlement_verify_inline

Use Cases and Notes

  • Positioning Clarification: This is not another loader. DSH app-boot already handles runtime checks (such as assertEntriesLoaded and assertEntriesActivated); this plugin only verifies producer-provided, revision-bound settlement receipts.
  • Behavioral Limits: It does not import, run, reload, or toggle recorded plugins, nor accepts raw logs, stack traces, output, business payloads, or secrets.
  • Verification Meaning: verified only means the receipts are internally consistent with their explicit policy, not a security attestation or proof of producer honesty.

Brief Conclusion

By providing an offline, deterministic evidence layer, this plugin helps DSH developers audit plugin loading and tool Schema state. For more details, see the plugin directory or the GitHub repository.