In the DSH ecosystem on October 4, 2026, verifying whether patches are effective typically involves scanners or real-time system queries. These methods introduce uncertainty and dependency on live state. dsh-vulnerability-remediation-proof is designed to address this specific need, providing an offline, deterministic way to verify patch closure.

Plugin Introduction

This plugin is maintained by dongsheng123132 and focuses on providing offline evidence for patch remediation through hash-based verification. It does not perform scanning or installation; instead, it recomputes settlement verdicts from provided receipts. Inputs and reports contain only hashes and restricted public metadata, without hostnames, addresses, scan output, or keys.

Core Features

  1. Offline, deterministic evidence: Runs entirely locally and does not depend on external live state.
  2. Hash-based verification: Validates the validity of remediation artifacts through content addressing.
  3. No real-time system queries: Does not perform host discovery, vulnerability scanning, or patch installation.
  4. Settlement verdict recomputation: Recomputes reviewed settlement verdicts from explicit receipts.

Installation and Enablement

This plugin is installed from a source directory. Compatibility requirements are as follows:

  • DeepSeek Harness (DSH): >= 0.1.2-alpha.4
  • Node.js: >= 22

Typical Usage

In the project root directory, you can run the following commands for testing and verification:

npm test
npm run check

Verify using the provided evidence file:

node bin/dsh-vulnerability-remediation-proof.mjs verify examples/closed.json

In the DSH toolchain, the corresponding commands are:

  • dsh_vulnerability_remediation_inspect
  • dsh_vulnerability_remediation_verify

MCP (Model Context Protocol) exposes equivalent proof-oriented inline tools.

Use Cases and Notes

This plugin is explicitly not a scanner or patch manager. In the DSH ecosystem, DeepSec scans DSH code, upstream-radar monitors dependency vulnerabilities, and the operations platform is responsible for deploying patches. This plugin is only responsible for verifying whether the remediation process meets the zero-residual closure conditions.

When generating reports, the plugin explicitly keeps the following flags set to false:

  • authenticatesReceipts: false
  • provesAssetSetExhaustive: false
  • provesAbsenceOfOtherVulnerabilities: false

Permissions and Security: The plugin runs with the permissions of the current DSH process. Before installing, be sure to review the source code and license (MIT).

Summary

dsh-vulnerability-remediation-proof provides a rigorous method for proving that patch remediation activity covered all claimed assets and reached a zero-residual closed state. It is suited for scenarios that require strict audit trails and security compliance.

  • Directory page: https://www.skillhub.cn/plugins/dongsheng123132/dsh-vulnerability-remediation-proof
  • GitHub: https://github.com/dongsheng123132/dsh-vulnerability-remediation-proof