Preamble

In the DeepSeek Harness (DSH) environment, a “skill” is typically a folder containing SKILL.md, along with runnable shell scripts, scripts, and MCP configuration. This code is often unaudited, has unrestricted tool access, and may change silently without anyone knowing.

Most existing security tools answer the question: “Is this skill dangerous right now?” dsh-skillnotary answers a different question: “Is it still the one I approved, and is it still allowed to do only what it was originally approved to do?”

Plugin Introduction

dsh-skillnotary is a DSH plugin for locking down and verifying the permissions of AI agent skills, preventing them from silently gaining new capabilities. The plugin is maintained by liyixuan201211 and released under the MIT license.

Core Features

After installation, the plugin provides the following capabilities:

  • Lock skill permissions: Generate a lock file that records the content digest, resolved provenance, and capability set.
  • Verify skill integrity: Detect whether SKILL.md and its capabilities have drifted from the approved version.
  • Sign capability attestations: Sign a DSSE envelope containing capability attestations using ed25519.
  • Policy governance: Configure allow/deny rules using the policy command.
  • Repair SKILL.md: Use the fix command to automatically write the allowed-tools actually required by the skill into SKILL.md.
  • Apply locked skills: Use the apply command to copy locked skills into the Harness directory.
  • CI gate: Use the ci command to integrate the above checks into the CI process.

Install and Enable

Before installing or updating an agent skill, it is recommended to first lock it and audit its capabilities. Install the plugin using the following command:

dsh plugin --profile web add github:liyixuan201211/dsh-skillnotary

Typical Usage

The plugin includes two built-in skills:

  • skills/skillnotary/: For the review loop. When adding or updating a skill, run audit (what it can do), verify (whether it is the approved version), and policy (whether it is allowed). If serious issues are detected, installation is blocked.
  • skills/skillnotary-drift-watch/: For continuous monitoring. Schedule periodic verify tasks so that skill changes are detected promptly after review ends.

Examples of common commands:

# 检测能力漂移
skillnotary verify

# 锁定技能
skillnotary lock

# 自动修复 allowed-tools
skillnotary fix

# 运行 CI 门禁检查
skillnotary ci

Notes

Before deployment, confirm the following facts:

  • No startup code: cordis.patch.yml is an empty patch. The plugin does not contain any code that runs when the DSH process starts, avoiding potential security risks from running with elevated privileges.
  • Not sandbox-based: Detection is based on context-scoped regular expressions over file headers, not sandboxing. This means targeted obfuscation can evade detection, and a report of “no known signals” does not mean “absolutely safe.”
  • Scan scope: Only file headers are scanned (1MB files, 64MB skills).
  • Signing method: Signing uses DSSE + in-toto and does not involve Sigstore (no Keyless/OIDC or transparent logs).
  • Dependencies and compatibility: Depends on TypeScript, has no build step, and requires Node >= 23.6. DSH compatibility requirement is >=0.1.5-rc.1 <0.2.0.
  • Lock limitations: The lock file only locks the skill itself and does not restrict runtime sandbox behavior.

Links

  • GitHub repository: https://github.com/liyixuan201211/dsh-skillnotary
  • Plugin directory: https://www.skillhub.cn/plugins/liyixuan201211/dsh-skillnotary