Introduction¶
DeepSeek Harness (DSH) adopts an everything-is-a-plugin architecture. During plugin loading and tool invocation, there is often a need to verify loading state, injection closure, and tool Schema settlement. The dsh-loader-settlement-proof plugin provides an offline evidence layer for recording and settling information about these DSH Loaders.
What Is It¶
The plugin is maintained by dongsheng123132 and belongs to the admin-security category. It generates deterministic, content-addressed JSON for verifying DSH Loader revisions and contract bindings, lifecycle states, and tool Schema receipts.
Core Features¶
- Offline Evidence Layer: Generates deterministic, content-addressed JSON to support offline audit.
- Lifecycle Verification: Verifies the
declared → resolved → loaded → activatedlifecycle. - Binding and Receipts: Verifies DSH Loader revisions and contract bindings, tool names, and their Schema SHA-256 receipts.
- State Checks: Verifies requests against resolved injections, enabled/required entry activation, and classified failures.
- Collision Detection: Verifies duplicate entries, stages, tools, and cross-entry tool collisions.
- Byte Verification: DSH tools/CLI can publish and verify bytes under an explicit
artifactDir. - MCP Support: MCP tools are inline-only.
Installation and Enabling¶
To add the plugin in a DSH environment, specify the exact commit hash or tag:
dsh plugin --profile web add github:dongsheng123132/dsh-loader-settlement-proof#<commit>
Typical Usage¶
After installation, you can use CLI commands to inspect and verify settlement evidence:
dsh-loader-settlement-proof inspect examples/settlement.json
dsh-loader-settlement-proof verify examples/settlement.json artifacts
You can also invoke them directly as DSH tools:
- dsh_loader_settlement_inspect
- dsh_loader_settlement_verify
For MCP environments, you can use:
- loader_settlement_inspect_inline
- loader_settlement_verify_inline
Use Cases and Notes¶
- Positioning Clarification: This is not another loader. DSH
app-bootalready handles runtime checks (such asassertEntriesLoadedandassertEntriesActivated); this plugin only verifies producer-provided, revision-bound settlement receipts. - Behavioral Limits: It does not import, run, reload, or toggle recorded plugins, nor accepts raw logs, stack traces, output, business payloads, or secrets.
- Verification Meaning:
verifiedonly means the receipts are internally consistent with their explicit policy, not a security attestation or proof of producer honesty.
Brief Conclusion¶
By providing an offline, deterministic evidence layer, this plugin helps DSH developers audit plugin loading and tool Schema state. For more details, see the plugin directory or the GitHub repository.