DeepSeek Harness Plugin Hub

Publish and manage complete Harness Profiles. Discover Plugins for your next setup.

Explore

PluginsPresetsDocsNews

Community

Publish a pluginContactReport an issue

Resources

Plugin Hub on GitHubDeepSeek HarnessSystem statusPrivacy notice
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

Independent and unofficial. Not affiliated with, authorized by, or endorsed by DeepSeek.

Audit Bundle — DSH Plugin for DeepSeek Harness
DeepSeek Harness Plugin Hub
ProfilesPluginsCategoriesNewsDocsSign inManage Profiles
ProfilesPluginsCategoriesNewsDocsSign in
← Plugins
A

dsh-audit-bundle

Audit Bundle

Content-addressed audit indexes across independent DeepSeek Harness evidence producers

The plugin will be installed here. Keep web if you are unsure.

npx -y @deepseek-ai/dsh plugin --profile web add github:dongsheng123132/dsh-audit-bundle#afb35ee32a4c50a511d018553759504c86037bda
READMECompatibilityVersions

Compatibility and provenance

Audit Bundle is published as dsh-audit-bundle and currently resolves to version 0.2.1. The Hub verifies its manifest and preserves the exact installation source for reproducible installs.

DSH compatibility
*
Runtime surfaces
any
Release source
github
Registry updated
9/7/2026

Versions

0.2.1stable
9/7/2026
0.2.0stable
8/20/2026

Related plugins

Loading related plugins…

Latest
0.2.1
DSH
*
HMR
Process restart
Tree shaking
Safe tree shaking not declared
Unpacked size
Unavailable
Files
Unavailable
Surface
any
License
MIT
Source
github
GitHub
★ 3
Weekly downloads
0
Last push
9/7/2026
View source ↗
README badge

Click the badge to copy Markdown for your README.

Do you maintain this Plugin?Claim benefit · Priority security scan

Verify the GitHub repository declared in package.json to manage this listing. After you claim it, Hub will prioritize a security scan of the current version and publish the result when it passes.

Claim this Plugin →
Report an issue

Related plugins

More verified plugins in security-access.

Pocketdsh-pocketPut DeepSeek Harness in your pocket: one package, one settings page, and scan a QR code on your phone to access DSH on your computer in sync (LAN + public network, real-time screen mirroring).DSCODE@toddzheng024/dscode-bundleA complete DeepSeek coding agent with persistent shell, Ultra collaboration and automatic permission review.Auto Reviewdsh-auto-reviewSecond-model AI auto-review for DeepSeek Harness approval requests: a read-only reviewer subagent decides allow/deny on the approval answerer chain, with fail-closed fallback and full session-log audit.Codex Subscriptiondsh-codex-subscriptionUse ChatGPT and Codex subscriptions in DeepSeek Harness with OAuth, quota, safe resets, web search, images, and Fast mode

README

dsh-audit-bundle

Content-addressed audit indexes across independent DeepSeek Harness evidence producers.

Version 0.2 adds a formal proof-only Codex MCP surface, host-neutral DSH ToolDefinitions, real ToolRuntime calls and a stock Web Loader regression test. The package exposes namespace exports only and does not bundle a second DSH runtime.

This plugin is not an SBOM scanner, signer, audit logger, policy engine or archive. Existing tools already scan dependencies and individual 2Origin plugins already produce release, runtime, recovery, lineage and policy evidence. The missing layer is a small verifier that proves a particular subject/revision has enough pinned evidence from allowed, independent producers to cover declared controls.

Contract

An explicit manifest declares:

  • one subject ID and revision;
  • required controls with minimum eligible evidence, minimum distinct producers and allowed evidence types;
  • evidence files pinned by SHA-256;
  • JSON Pointers that bind every evidence file to the subject and revision;
  • value-hash assertions, so expected or observed values never enter the audit index.

Verification fails closed for missing, stale or invalid JSON evidence, subject/revision mismatch, failed assertions, disallowed types, insufficient evidence or insufficient independent producers. The output contains IDs, types, producers, paths into JSON, hashes, statuses, coverage and a deterministic SHA-256 pair-tree Merkle root. It never copies evidence bodies or assertion values.

Files must be workspace-relative regular files. Symlinks, path escape, oversized input and excessive structure are rejected. The plugin performs no network calls or child processes and writes only a content-addressed JSON index under the explicit artifactDir, followed by read-back verification.

CLI

node bin/dsh-audit-bundle.mjs inspect --workspace examples/basic --manifest audit.manifest.json
node bin/dsh-audit-bundle.mjs verify --workspace examples/basic --manifest audit.manifest.json --artifactDir artifacts

The CLI emits one JSON object. A failed audit verdict exits 2; invalid usage exits 1.

DeepSeek Harness and MCP

The DSH bundle registers dsh_audit_bundle_inspect and dsh_audit_bundle_verify. These workspace-bounded tools dereference pinned evidence and can write the content-addressed index. The companion stdio MCP server registers audit_bundle_inspect and audit_bundle_verify through .mcp.json, but accepts only an inline manifest and structural JSONL receipts containing IDs, hashes, producer/subject bindings and assertion digests. MCP never reads files, dereferences evidence, executes actions or writes artifacts; it reports evidenceContentVerification: not-performed. Use DSH or CLI for real evidence-content verification.

dsh plugin --profile audit-bundle add github:dongsheng123132/dsh-audit-bundle#<commit>
dsh --profile audit-bundle --dump-config

Verification

npm ci
npm test
npm run check
npm run smoke:plugin
npm run smoke:mcp
DSH_CHECKOUT=/path/to/built/deepseek-harness npm run smoke:dsh
DSH_CHECKOUT=/path/to/built/deepseek-harness DSH_HOME=/path/to/isolated-home npm run smoke:web-loader
python C:/Users/ZhuanZ/.codex/skills/.system/plugin-creator/scripts/validate_plugin.py .

CI runs on Ubuntu and Windows. Node.js 22 or newer. MIT licensed.