The DeepSeek Harness (DSH) ecosystem embraces the “everything is a plugin” philosophy. When building agents or supply chain verification workflows, a key question is how to confirm that the build process strictly adheres to declared boundaries without relying on live sandboxes or online network verification. The dsh-build-hermeticity-proof plugin aims to provide an offline, hash-based deterministic evidence layer for verifying whether recorded build accesses remain strictly within the declared closure of files, environment, network, clock, and randomness.
This plugin is maintained by dongsheng123132 and belongs to the admin-security category. It is an offline deterministic evidence layer designed for the DeepSeek Harness supply chain. Its core value is verifying the internal integrity and policy compliance of build access receipts using only hash values, without executing the build or making network requests during verification.
Core Features¶
- Offline hash proof: Verifies build access scopes using hashes only, without online verification.
- Comprehensive boundary checks: Validates file reads and writes, environment variable reads, network access, clock access, and randomness access.
- Deterministic content addressing: Generates deterministic content-addressed output.
- Lightweight validator: The validator has no runtime dependencies, does not spawn child processes, and does not initiate network requests.
Installation and Enablement¶
Before use, ensure Node.js 22 or later is installed in your environment. Install the plugin with the following command:
dsh plugin add github:dongsheng123132/dsh-build-hermeticity-proof#COMMIT
Typical Usage¶
The plugin exposes dsh_build_hermeticity_inspect and dsh_build_hermeticity_verify (from the headless core), and also exposes build_hermeticity_inspect and build_hermeticity_verify through a standalone MCP stdio server. The CLI accepts an inspect or verify command and requires an explicit JSON path.
Reports contain only hashes, counts, booleans, classifications, and verdicts. The validator rejects secret-shaped material, raw logs, and body/content fields.
With the example examples/hermetic, the validator reads a workspace-relative non-symlink manifest, writes to an explicit workspace-relative artifactDir, and verifies integrity by reading it back.
Applicable Scenarios and Considerations¶
- Applicable scenarios: Suitable for scenarios that require verifying internal integrity and policy compliance of build evidence, especially when offline verification is required.
- Limitations:
- The plugin does not execute builds and does not enforce sandboxing. It does not authenticate receipts, nor prove that unrecorded access could not have occurred.
- The plugin does not prove reproducibility. A
hermeticverdict only means the provided receipt is internally complete and policy-compliant. - Under the v1 deny-network policy, observed network access will fail.
- Ecosystem note: The DSH philosophy is “everything is a plugin”. The community directory is an independent site and has no official affiliation with DeepSeek / High-Flyer.
The plugin provides a verification layer for build boundaries through offline hash proof. To view the source code or obtain more information, visit its GitHub repository or community directory page.