Introduction

In the development of DeepSeek Harness (DSH), agents occasionally need to temporarily waive certain policy restrictions. To ensure compliance, relying solely on runtime execution results is not enough; it is also necessary to prove after the fact (offline) that these waivers were strictly confined to approved boundaries. The dsh-policy-waiver-proof plugin provides an offline, deterministic evidence layer for verifying whether published temporary policy exceptions have crossed their boundaries.

Plugin Purpose

This plugin is maintained by developer dongsheng123132. Its core value lies in generating offline evidence to prove whether temporary policy waivers remain within approved boundaries. It does not grant waivers, modify policies, approve tool calls, or execute external commands; instead, it focuses on validating the boundary lifecycle of issued temporary exceptions, including revocation or closure.

Core Features

The plugin provides the following capabilities:
* Offline validation: The validator does not use runtime dependencies or network access.
* Boundary proof: It proves that recorded usage remained within approved principals, revisions, scopes, operation allowlists, time windows, usage limits, and compensating controls.
* Lifecycle management: It validates exemption continuity, effective times, revocation/closure status, and the effectiveness of compensating controls.
* Output format: Reports include only hashes, counts, boolean values, public bounded IDs converted to hashes, and machine-readable verdicts, and reject raw business principals or secret-like material.

Installation and Enablement

Add the plugin using the official installation command:

dsh plugin add github:dongsheng123132/dsh-policy-waiver-proof#COMMIT

Typical Usage

The plugin publishes two toolsets:
1. CLI tools: Published from the DSH bundle, named dsh_policy_waiver_inspect and dsh_policy_waiver_verify.
2. MCP stdio server: A standalone MCP stdio server publishes policy_waiver_inspect and policy_waiver_verify.

The CLI accepts inspect or verify followed by an explicit JSON manifest path. A sample manifest file is located at examples/contained.json. The DSH verification tools read only workspace-relative non-symlink manifests and write output to an explicit workspace-relative artifactDir.

Validation Logic

The plugin validates waiver usage according to strict rules:
1. Continuity: Applied usage must be continuous.
2. Time and ordering: Usage must occur before evaluation and within the waiver window, and before revocation/closure.
3. Constraint matching: Usage must match all bindings and the usage count must be below maxUses.
4. Compensating controls: Usage must have fresh, valid compensating controls.
5. Denial handling: Denied attempts are disclosed but do not consume approved usage limits.
6. Evidence inference: Missing or stale evidence is never silently inferred.

Notes

  • Runtime environment: Node.js 22 or later is required.
  • Manifest requirements: DSH verification tools read only workspace-relative non-symlink manifests. Ensure file paths are correct and have not been tampered with.
  • Permissions and security: The plugin runs with the current DSH process permissions. Review the source code and license before installation.

Summary

dsh-policy-waiver-proof provides DSH with offline audit capabilities for policy compliance. Through hash addresses and machine-readable verdicts, it ensures that temporary policy exceptions are strictly controlled within approved boundaries, making it suitable for scenarios requiring rigorous auditing and compliance. For more details, visit the plugin directory or view the GitHub repository.