Introduction

In the plugin-based ecosystem of DeepSeek Harness (DSH), developers often need to address the verification of identity consistency within an execution chain. Traditional access control and signature verification typically focus on “who holds the permission,” whereas this plugin focuses on “whether every link in the execution chain is consistently bound to the same anonymous principal and tenant throughout.” dsh-principal-binding-proof aims to provide an offline, content-addressed evidence mechanism to prove the consistency of principal binding in the execution chain (from principal to artifact).

What Kind of Plugin Is This?

This plugin belongs to the administrative security category, is named dsh-principal-binding-proof, is maintained by user dongsheng123132, and follows the MIT license.

The core problem it solves is: in the DSH execution chain (principal → session → agent → tool call → runtime → artifact), how to verify whether the anonymous principal and tenant remain bound consistently throughout, without tampering or confusion.

Core Capabilities

This plugin confirms the validity of principal binding by verifying a series of explicitly recorded data points:
1. Verifies explicitly recorded hashes, revision versions, and key epochs.
2. Checks evidence freshness, issuer allowlist, expiration, and revocation status.
3. Confirms adjacency and a unique acyclic chain.
4. Detects anomalies such as principal swaps, cross-tenant confusion, expired identities, typos or broken bindings, unauthorized issuers, and end-artifact mismatches.

Installation and Enablement

Run the following command from the project root directory to add this plugin:

dsh plugin --profile proof add .

Typical Usage

After installation, you can use the plugin in the following ways:

npm test
npm run check
node bin/dsh-principal-binding-proof.mjs verify examples/bound.json

Applicable Scenarios and Boundaries

Applicable scenarios: Suitable for scenarios that require auditing agent execution chains to ensure evidence-chain integrity and identity consistency.

Important boundaries:
1. Not an authentication/authorization tool: This is not an authentication, authorization, signature verification, access control, or remote transport tool. It grants no authority, does not read accounts, credentials, prompts, or business payloads, and does not execute commands.
2. DSH tool set: DSH provides two main tools: dsh_principal_binding_inspect and dsh_principal_binding_verify. MCP exposes inline equivalent proof operations.
3. Workspace verification limits: Workspace verification accepts only relative, non-symbolic linked paths, writes deterministic content-addressed reports under an explicit artifactDir, and then performs SHA-256 reread verification.
4. Dependency requirements: This plugin requires DSH version >= 0.1.2-alpha.4 and Node.js version >= 22.

Ecosystem Context

The DSH philosophy is “everything is a plugin.” The community directory is an independent site with no official affiliation to DeepSeek or Huanfang.

References