In the DeepSeek Harness (DSH) ecosystem, the system generates the official default tool architecture catalog at startup. Existing tools such as dsh-mcp-lens already provide large MCP catalog compression and architecture budget checking. This plugin does not do these things. It validates deployment-specific, explicitly recorded envelopes: for example, after an upgrade, whether owner/native surfaces and reader/native surfaces still fully expose approved tool identities and schemas.
Features¶
This plugin generates offline content-addressed evidence proving that the actually recorded, model-visible tool surfaces comply with the approved lock across agent scopes, permission modes, and presentation modes.
Core capabilities include:
* Validate deployment-specific, explicitly recorded envelopes.
* Detect drift: missing or unexpected surfaces, scope/permission/presentation mismatches, tool additions or removals, schema changes, ordering drift, stale or future observations, duplicate identities, and version mismatches.
* Expose dsh_tool_surface_inspect and dsh_tool_surface_verify through the DSH bundle.
* Provide an inline, MCP server-based equivalent solution without filesystem access.
Usage¶
The CLI provides two main subcommands.
Inspect the tool surface:
dsh-tool-surface-proof inspect --manifest surface.json
Verify the tool surface:
dsh-tool-surface-proof verify --workspace-root . --manifest surface.json --artifact-dir artifacts
The verifier reads a workspace-relative regular file, rejects symbolic links and path traversal, makes no network requests or subprocesses, and writes a content-addressed JSON report to an explicitly specified artifact directory.
Limitations and Notes¶
This plugin does not capture real-time runtime state, grant or deny permissions, execute commands, connect to MCP servers, or prove recorder honesty. It relies on trusted deployment-specific recorders to create observation envelopes.
Reports include only SHA-256 identities, counts, and drift categories. They never return tool names, descriptions, schemas, or raw business content.
Technical Specifications¶
- License: MIT
- Compatibility: DSH >= 0.1.2-alpha.4, Node >= 22
- Installation: The official installation command is not provided. Please refer to the GitHub repository for the source code.
Summary¶
For teams that need to prove that deployment-specific tool surfaces comply with approved locks without exposing tool names or business logic, this plugin provides a mechanism. It focuses on deployment-scope consistency, not runtime permissions or execution.