dsh-windows-readiness-proof
Run the following command in DeepSeek Harness:
dsh plugin install dongsheng123132/dsh-windows-readiness-proof
Paste the following prompt into your AI chat to install this plugin:
Run the install command in your DeepSeek Harness terminal to add the Windows readiness verification plugin sourced from https://github.com/dongsheng123132/dsh-windows-readiness-proof .
About this plugin
Before rolling out DeepSeek Harness on a managed Windows host, the critical question is whether the OS build, security posture, filesystem constraints, session environment, and identity configuration truly satisfy the runtime prerequisites. dsh-windows-readiness-proof exists for exactly that moment. It is an evidence verifier, not a collector or remediation tool: it never runs PowerShell, reads the registry, modifies Group Policy, creates Defender exclusions, edits WDAC or AppLocker, installs software, restarts services, or probes the network. Instead it receives a SHA-256-pinned, sanitized observation snapshot and evaluates it line by line against an explicit readiness manifest, returning a deterministic pass or fail verdict.
Verification coverage is thorough yet tightly scoped. It checks Windows product type, architecture, build number, and pending-reboot status; Node, DSH, and PowerShell edition and version with language mode; classified WDAC, AppLocker, Defender, execution policy, Credential Guard, and TLS 1.2 posture; long-path support, atomic rename, workspace and temp ACL class, and symlink policy; non-interactive session, opaque identity class, writable profile, and recovery configuration; free workspace and temp storage; and connectivity identities represented solely by endpoint SHA-256 plus status, TLS, and proxy classes. Any missing, stale, future-dated, malformed, secret-shaped, identity-bearing, path-escaping, symlinked, or policy-mismatched evidence triggers a fail-closed rejection. Reports expose only opaque identities, hashes, classification labels, reason codes, and control status—never usernames, domains, registry paths, raw command output, credentials, or unredacted observations.
The plugin is well suited for enterprise IT and security teams, CI pipelines that require auditable artifacts, and compliance workflows that must prove a Windows environment is ready before cross-organizational handoff. It forms a clean complement to Harness Doctor (which diagnoses local DSH, Codex, and OpenClaw installation health) and Windows desktop-control skills (which execute UI and PowerShell actions): it does exactly one job—turning a pre-collected readiness fact set into a deterministic, reviewable audit conclusion under an explicit policy.
Use Cases
- Enterprise IT teams validating managed Windows hosts meet Harness prerequisites before bulk rollout
- CI pipelines gating deployment on a deterministic readiness verdict
- Compliance audits producing reviewable readiness artifacts instead of manual checklists
Best For
- Enterprise IT and security operations teams
- CI/CD engineers requiring auditable deployment artifacts
- Compliance reviewers validating cross-organizational handoffs
Related Plugins
Adds an Auto approval mode on the official workspace-write sandbox, classifying semantic risks, asking when ambiguous, and denying destructive operations.
Undo/rollback system for DSH: config & plugin snapshots, one-click undo/redo/restore, message-level revert, secret masking, safe mode, and offline WebUI/GUI/CLI rescue tools for when DSH won't start.
Packages all 87 SKILL.md files from upstream reverse-skill as a DeepSeek Harness plugin that auto-registers them for authorized reverse engineering, penetration testing, and security research.
Dockyard DSH is a native DeepSeek Harness plugin that unifies official OAuth/client sessions for Codex, Antigravity, Grok, Claude, and Cursor, providing account pool, model catalog, and quota status.