The DeepSeek Harness (DSH) ecosystem already has performance-monitoring plugins (such as OTel / Prometheus), but there is a gap in security auditing and session forensics. As a DSH Bundle plugin, auditrail aims to fill this gap by recording complete tool-invocation call chains, flagging high-risk operations, providing privacy-masked storage, and enabling session playback, thereby establishing a security baseline for agent runtime environments.

Core Capabilities

The plugin subscribes to DSH’s session/event and tools/* streams to fully log every tool invocation.

  1. Complete audit chain records
    Record key information for each event: actor (session/actor), timestamp and sequence number, executed command (tool name and masked argument summary), involved files, target network address, execution result status, and duration. It merges tool_call, tool_result, and tool_dispatch events to form a complete call chain.

  2. Sensitive operation tagging
    A built-in rule engine detects high-risk operation patterns, such as rm -rf, curl | sh, key/sensitive-material operations, destructive Git/DB operations, data-exfiltration requests, and privilege escalation. The system attaches severity levels and rule labels to affected records.

  3. SQLite (WAL) persistence and privacy masking
    Persistence uses SQLite’s WAL mode, with hash chains to make data tampering detectable. By default, all stored content is masked and truncated, and original sensitive data is not stored. Configure redact to adjust the masking policy.

  4. Querying and export
    Records can be filtered by time window, session, tool, minimum severity, sensitive rule labels, and other dimensions. Export formats include JSON reports, Markdown reports, and JSONL conforming to the dsh-audit-trail/compliance/1 schema.

  5. Terminal session playback
    Render audit records as a plain-text timeline, with support for pause, step, seek, and playback speed control, allowing the session execution process to be replayed in the terminal without a browser.

  6. Model toolset
    Provide four dedicated tools for the model: audit_query (query audit data), audit_export (export reports), audit_playback (replay sessions), and audit_policy (manage rules).

Installation and Enablement

Ensure the environment meets the dependency requirements before installation.

Prerequisites:
- Node.js >= 22.13
- @deepseek-ai/cordis >= 4
- @deepseek-ai/dsh-tools >= 0.0.1-rc.1

Installation steps:

  1. Install from a local development package (recommended for development and debugging):
dsh plugin --profile <name> add /path/to/dsh-plugin/auditrail
  1. Install from a packaged file (production environment):
# assuming the tarball has already been generated
dsh plugin --profile <name> add ./dsh-audit-trail-0.1.0.tgz

After installation, the plugin is automatically mounted into the DSH process via the cordis.patch.yml layer.

Typical Usage

1. Model tool calls
In a DSH session, the model can directly call the following tools for audit operations:
- audit_query: Retrieve audit records matching specific conditions.
- audit_export: Export query results to the specified format (JSON/Markdown).
- audit_playback: Perform session playback.
- audit_policy: Manage the enabling and disabling of sensitive-operation rules.

2. Command-line interface
Use the standalone auditrail CLI to operate against the same database (without starting DSH Harness):

auditrail <command> [options]

Notes

  • Runtime permissions: The plugin runs with the permissions of the current DSH process. Ensure the database file path is writable.
  • Data security: Original sensitive data is not stored by default. Adjust the redact configuration as required for security needs.
  • License: This project is licensed under MIT. Review the source code before use.

Summary

auditrail completes the DSH ecosystem by extending it from performance monitoring to security auditing. Through SQLite hash-chain storage and privacy masking, it protects data security while maintaining detailed records, making it suitable for developers who need compliance review and risk tracing for agent operations.