In the DeepSeek Harness (DSH) ecosystem, the system generates the official default tool architecture catalog at startup. Existing tools such as dsh-mcp-lens already provide large MCP catalog compression and architecture budget checking. This plugin does not do these things. It validates deployment-specific, explicitly recorded envelopes: for example, after an upgrade, whether owner/native surfaces and reader/native surfaces still fully expose approved tool identities and schemas.

Features

This plugin generates offline content-addressed evidence proving that the actually recorded, model-visible tool surfaces comply with the approved lock across agent scopes, permission modes, and presentation modes.

Core capabilities include:
* Validate deployment-specific, explicitly recorded envelopes.
* Detect drift: missing or unexpected surfaces, scope/permission/presentation mismatches, tool additions or removals, schema changes, ordering drift, stale or future observations, duplicate identities, and version mismatches.
* Expose dsh_tool_surface_inspect and dsh_tool_surface_verify through the DSH bundle.
* Provide an inline, MCP server-based equivalent solution without filesystem access.

Usage

The CLI provides two main subcommands.

Inspect the tool surface:

dsh-tool-surface-proof inspect --manifest surface.json

Verify the tool surface:

dsh-tool-surface-proof verify --workspace-root . --manifest surface.json --artifact-dir artifacts

The verifier reads a workspace-relative regular file, rejects symbolic links and path traversal, makes no network requests or subprocesses, and writes a content-addressed JSON report to an explicitly specified artifact directory.

Limitations and Notes

This plugin does not capture real-time runtime state, grant or deny permissions, execute commands, connect to MCP servers, or prove recorder honesty. It relies on trusted deployment-specific recorders to create observation envelopes.

Reports include only SHA-256 identities, counts, and drift categories. They never return tool names, descriptions, schemas, or raw business content.

Technical Specifications

  • License: MIT
  • Compatibility: DSH >= 0.1.2-alpha.4, Node >= 22
  • Installation: The official installation command is not provided. Please refer to the GitHub repository for the source code.

Summary

For teams that need to prove that deployment-specific tool surfaces comply with approved locks without exposing tool names or business logic, this plugin provides a mechanism. It focuses on deployment-scope consistency, not runtime permissions or execution.