Introduction¶
A common problem in code audits is the following: after introducing an open-source code snippet and modifying it, does it remain legally bound by the upstream license? After extensive modifications, the expressive form of the code may become completely different, while the underlying logic and syntactic structure may retain a high degree of similarity. The DeepSeek Harness (DSH) plugin code-ownership-audit addresses this pain point through purely local AST (Abstract Syntax Tree) static analysis.
Core Features¶
The core capabilities of the plugin include:
- Pure AST statistical analysis: It compares AST nodes in the code rather than relying on simple text line matching, allowing it to identify deep-level logical similarities.
- Zero third-party dependencies: The audit engine relies only on the Python standard library and does not introduce external packages.
- Local execution, zero privacy leakage: The code does not leave the local machine, no LLM is called, and there is no network access (free tier).
- Dual-form sharing: The Agent Skill and DSH Plugin share the same
audit.pyengine; choose the one that suits your needs. - Tiered reports: It offers two output levels: a free preview and a paid full version.
- x402 protocol payment: The paid tier supports verification through the Alipay AI Wallet; it only verifies funds and issues a credential, without storing the code.
- Clean engineering: The DSH plugin layer is pure ESM JavaScript, with zero build and zero runtime dependencies.
Installation and Enabling¶
In a DSH environment, you can add the plugin directly using the official installation command:
dsh plugin --profile web add github:ffseika0304/code-ownership-audit
After installation, restart the profile to activate the bundle layer:
dsh --profile web
The plugin then appears in the model-visible skill directory. Once enabled, you can ask questions directly in the conversation, for example:
- “Run a code ownership health check for me”
- “Use code-ownership-audit to check the ownership status of ./my-code relative to ./upstream”
Typical Usage¶
You can run audit.py directly in the terminal. The target and the reference can each be a single .py file or an entire directory.
1. Free preview (recommended for quick screening):
python audit.py <your code> --reference <upstream code> --tier preview
This tier outputs the total number of risks, the distribution by type, and a one-sentence summary. It runs fully offline.
2. Full report (for formal delivery or self-audit):
python audit.py <your code> --reference <upstream code> --tier full
This tier outputs specific line numbers, remediation suggestions, exportable md/json files, and a server-signed audit credential.
Reports and Pricing¶
The plugin offers two report tiers, with the following differences:
- Free preview: Free and unlimited. It includes the total number of risks, the distribution by type, and a one-sentence summary. It runs fully offline and does not produce line numbers or suggestion fields.
- Full report: ¥0.2 per use. It includes code locations, specific line numbers, itemized remediation suggestions, md/json export, and a server-signed audit credential.
The locally computed results for the full report remain readable; the paid unlock is a signed, certified deliverable, intended for archiving or delivery to the client.
Privacy and Security¶
- Network access: The free tier has zero network access; only the paid tier’s payment step accesses the payment oracle over the network.
- Data storage: It does not receive or store any code.
- Model calls: It does not call any LLM.
- Signature verification: Receipts are verified offline using an embedded public key; any field tampering will cause verification to fail.
Notes¶
This tool provides technical facts (which expressions are identical and to what degree); it does not constitute legal advice. For final legal determinations, please consult professionals. This project is not affiliated with DeepSeek AI and is not an official plugin.
Conclusion¶
code-ownership-audit is suitable for scenarios such as incorporating open-source code, performing clean-room rewrites, or conducting a pre-delivery self-audit. Its local processing approach and clear report tiering make it a powerful auxiliary tool for compliance audits.