Preamble¶
In the DeepSeek Harness (DSH) environment, a “skill” is typically a folder containing SKILL.md, along with runnable shell scripts, scripts, and MCP configuration. This code is often unaudited, has unrestricted tool access, and may change silently without anyone knowing.
Most existing security tools answer the question: “Is this skill dangerous right now?” dsh-skillnotary answers a different question: “Is it still the one I approved, and is it still allowed to do only what it was originally approved to do?”
Plugin Introduction¶
dsh-skillnotary is a DSH plugin for locking down and verifying the permissions of AI agent skills, preventing them from silently gaining new capabilities. The plugin is maintained by liyixuan201211 and released under the MIT license.
Core Features¶
After installation, the plugin provides the following capabilities:
- Lock skill permissions: Generate a lock file that records the content digest, resolved provenance, and capability set.
- Verify skill integrity: Detect whether
SKILL.mdand its capabilities have drifted from the approved version. - Sign capability attestations: Sign a DSSE envelope containing capability attestations using ed25519.
- Policy governance: Configure allow/deny rules using the
policycommand. - Repair
SKILL.md: Use thefixcommand to automatically write theallowed-toolsactually required by the skill intoSKILL.md. - Apply locked skills: Use the
applycommand to copy locked skills into the Harness directory. - CI gate: Use the
cicommand to integrate the above checks into the CI process.
Install and Enable¶
Before installing or updating an agent skill, it is recommended to first lock it and audit its capabilities. Install the plugin using the following command:
dsh plugin --profile web add github:liyixuan201211/dsh-skillnotary
Typical Usage¶
The plugin includes two built-in skills:
skills/skillnotary/: For the review loop. When adding or updating a skill, runaudit(what it can do),verify(whether it is the approved version), andpolicy(whether it is allowed). If serious issues are detected, installation is blocked.skills/skillnotary-drift-watch/: For continuous monitoring. Schedule periodicverifytasks so that skill changes are detected promptly after review ends.
Examples of common commands:
# 检测能力漂移
skillnotary verify
# 锁定技能
skillnotary lock
# 自动修复 allowed-tools
skillnotary fix
# 运行 CI 门禁检查
skillnotary ci
Notes¶
Before deployment, confirm the following facts:
- No startup code:
cordis.patch.ymlis an empty patch. The plugin does not contain any code that runs when the DSH process starts, avoiding potential security risks from running with elevated privileges. - Not sandbox-based: Detection is based on context-scoped regular expressions over file headers, not sandboxing. This means targeted obfuscation can evade detection, and a report of “no known signals” does not mean “absolutely safe.”
- Scan scope: Only file headers are scanned (1MB files, 64MB skills).
- Signing method: Signing uses DSSE + in-toto and does not involve Sigstore (no Keyless/OIDC or transparent logs).
- Dependencies and compatibility: Depends on TypeScript, has no build step, and requires Node >= 23.6. DSH compatibility requirement is
>=0.1.5-rc.1 <0.2.0. - Lock limitations: The lock file only locks the skill itself and does not restrict runtime sandbox behavior.
Links¶
- GitHub repository: https://github.com/liyixuan201211/dsh-skillnotary
- Plugin directory: https://www.skillhub.cn/plugins/liyixuan201211/dsh-skillnotary