Introduction

In the DeepSeek Harness (DSH) tool-calling pipeline, tool-generated results can be very large, or, for performance, privacy, and storage-cost reasons, we may need to preserve evidence without directly reading or storing the full content body. We need a mechanism to verify that results have been correctly retained, processed, and conform to specific byte budgets and mapping relationships, without accessing the actual content.

The dsh-output-custody-proof plugin provides a content-addressed proof mechanism for “content-free” DSH tool-result retention and spill-custody stages. It confirms the validity of custody receipts through offline, deterministic verification, ensuring integrity and consistency of results.

Plugin Positioning

This is a plugin maintained by dongsheng123132, focused on the “Memory” category. It does not store results, transform outputs, or clean data; instead, it acts as a verification layer that inspects and proves the state of results during retention and spill stages.

The core role of the plugin is to reconcile formatted source digests and byte counts against model-visible or persistence-only projections, and to verify byte budgets, omission accounting, spill/source identity, surface mapping, stage ordering, and explicit upstream incompleteness.

Core Features

  1. Offline Deterministic Verification
    The plugin can validate content-free DSH tool-result custody receipts offline. It does not read result bodies or open spill artifacts, and makes determinations solely based on metadata in the receipt.

  2. Multi-dimensional Checks
    The verification process covers byte budgets, precise omission accounting, spill/source identity, surface mapping, stage ordering, repeated call/locator identity, and explicit upstream incompleteness.

  3. MCP and File Tools
    It provides MCP tools output_custody_inspect_inline and output_custody_verify_inline (inline only).
    File tools have strict security constraints: they accept workspace-relative paths, reject path traversal and symbolic links, limit input size, write only to the designated artifact directory, expose only creation operations, and use read-back validation to ensure data consistency.

Installation and Activation

Before installation, ensure your environment meets the dependency requirements:
* DSH version: >= 0.1.2-alpha.4
* Node.js version: >= 22

Install it using the following command (replace #COMMIT in the installation command with the actual Git Commit Hash):

dsh plugin --profile web add github:dongsheng123132/dsh-output-custody-proof#COMMIT

After installation, you can operate it through the following command-line tools:

dsh_output_custody_inspect
dsh_output_custody_verify

Typical Usage

The plugin provides basic example files. You can use the following commands:

dsh-output-custody-proof inspect examples/custody.
dsh-output-custody-proof verify examples/custody. artifacts

At the root of the plugin repository, a set of test scripts is also provided to verify that the environment configuration is correct:

npm test
npm run check
npm run smoke:plugin
npm run smoke:mcp

Notes

  1. Feature Boundaries
    This is a verification tool, not spill storage, an output transformer, a cleaner, a session exporter, or a result logger.

    • The dsh-output-retention library determines the content that is mechanically retained.
    • dsh-spill-policy is responsible for converting oversized plain-text results into spill format.
    • dsh-spill-local is responsible for storing this spilled content.
    • dsh-telemetry-redactor is responsible for cleaning exported copies.
      This plugin only validates explicit receipts from the above components or other producers.
  2. Security and Privacy
    The plugin never reads result bodies or opens spill artifacts, ensuring that actual tool output content is not exposed during verification.

  3. Proof Scope
    Each report explicitly states that hashes only prove the integrity and consistency of content, and do not prove source authenticity or real-world integrity.

  4. Data Type Restrictions
    The schema only accepts bounded identifiers, byte counts, categories, and SHA-256 hashes, and rejects tool values, output text, prompts, messages, credentials, or spill locators.

Summary

The dsh-output-custody-proof plugin provides a lightweight, non-intrusive verification method for the result-custody stages in the DSH ecosystem. Through content addressing and strict metadata validation, it helps developers confirm the retention status of tool execution results without touching the actual content.

  • Plugin directory: https://www.skillhub.cn/plugins/dongsheng123132/dsh-output-custody-proof
  • Source code: https://github.com/dongsheng123132/dsh-output-custody-proof