Preface¶
In the DeepSeek Harness (DSH) plugin ecosystem, the Cordis framework allows all listeners to share the same args array. Since the internal/get / internal/set interception points are exposed, any plugin can silently rewrite the data flow. When hundreds of plugins run at the same time, it is difficult to answer the question, “Which plugin modified my data?”
dsh-audit-log aims to solve this problem. It is a runtime data-flow audit log plugin that records who changed what and when, with precise attribution to the specific plugin and Fiber level.
Plugin Overview¶
dsh-audit-log is a read-only observer plugin. It does not block, rewrite, or store concrete Payload values; it only records structural fingerprints.
- Category: admin-security
- Maintainer: ssdyg4444-sys
- License: MIT
Core Features¶
- Dispatch-level diff: Takes snapshots of argument shape before and after listener execution and records changes that occur in between.
- Per-listener window attribution: Each listener is wrapped at registration time, and changes are precisely attributed to the specific plugin and Fiber that made them (confidence is “window”).
- Read-only observer: Always remains in observer mode and never interferes with the data flow.
- Shape-only fingerprints: Stores only structural fingerprints (type, keys, length) and does not record Payload values, ensuring sensitive information does not enter logs.
Installation and Enabling¶
Navigate to your Web configuration directory:
cd ~/.dsh/profiles/web
pnpm add dsh-audit-log
Then add dsh-audit-log to dsh.profile.bundles in package.json, or use dsh plugin --profile web add dsh-audit-log. After installation, restart the DSH instance. By default, the plugin starts recording without configuration.
Typical Usage¶
In any plugin, you can query the audit log through ctx.auditLog.
Query mutation records for a specific event:
const records = await ctx.auditLog.query({
events: ['message/send'],
mutationsOnly: true, // 仅返回发生修改的 Dispatch
fromSeq: 100,
limit: 50
});
// 获取具体的责任人
const culprit = records[0].mutations[0].attribution?.package
// 获取每个监听器的窗口记录
const windows = ctx.auditLog.queryWindows({ event: 'message/send' })
Use Cases and Notes¶
- Use cases: Use when you need to investigate unintended data-flow mutations, trace data dependencies between plugins, or perform security audits.
- Caution: The plugin runs with the permissions of the current DSH process. Check the source code and license before installation.
- Privacy protection: Sensitive values such as Secrets never appear in logs; only structural fingerprints are stored.
Limitations¶
- Fingerprint limitation: Shape-only fingerprints cannot detect same-length string swaps (such as
'by-c'becoming'by-d') or in-place numeric edits. - Time precision: Timing records on synchronous paths are precise; however, in
serial/parallel/waterfallmodes, the synchronous-path timing granularity for asynchronous listeners is coarse (covered by Dispatch-level diff).
dsh-audit-log is complementary to other context-level observability tools in the ecosystem: the former focuses on runtime data-flow mutations, while the latter focuses on the input sources of model Prompts.