DeepSeek Harness Plugin Hub

Publish and manage complete Harness Profiles. Discover Plugins for your next setup.

Explore

PluginsPresetsDocsNews

Community

Publish a pluginContactReport an issue

Resources

Plugin Hub on GitHubDeepSeek HarnessSystem statusPrivacy notice
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

Independent and unofficial. Not affiliated with, authorized by, or endorsed by DeepSeek.

Windows Readiness Proof — DSH Plugin for DeepSeek Harness
DeepSeek Harness Plugin Hub
ProfilesPluginsCategoriesNewsDocsSign inManage Profiles
ProfilesPluginsCategoriesNewsDocsSign in
← Plugins
W

dsh-windows-readiness-proof

Windows Readiness Proof

Content-addressed readiness proof for sanitized DeepSeek Harness observations on managed Windows hosts

The plugin will be installed here. Keep web if you are unsure.

npx -y @deepseek-ai/dsh plugin --profile web add github:dongsheng123132/dsh-windows-readiness-proof#415a07edb924ee7465e92536e8ca4aef48a9c8b5
READMECompatibilityVersions

Compatibility and provenance

Windows Readiness Proof is published as dsh-windows-readiness-proof and currently resolves to version 0.1.2. The Hub verifies its manifest and preserves the exact installation source for reproducible installs.

DSH compatibility
*
Runtime surfaces
any
Release source
github
Registry updated
9/7/2026

Versions

0.1.2stable
9/7/2026

Related plugins

Loading related plugins…

Latest
0.1.2
DSH
*
HMR
Process restart
Tree shaking
Safe tree shaking not declared
Unpacked size
Unavailable
Files
Unavailable
Surface
any
License
MIT
Source
github
GitHub
★ 2
Weekly downloads
0
Last push
9/7/2026
View source ↗
README badge

Click the badge to copy Markdown for your README.

Do you maintain this Plugin?Claim benefit · Priority security scan

Verify the GitHub repository declared in package.json to manage this listing. After you claim it, Hub will prioritize a security scan of the current version and publish the result when it passes.

Claim this Plugin →
Report an issue

Related plugins

More verified plugins in security-access.

Doctor@linxin666/dsh-doctorTransactional rescue mode for DSH profiles with a supervised launcher, isolated recovery capsule, deterministic repairs, health monitoring, and a local Web recovery consoleMobiledsh-mobileDeepSeek Harness mobile adaptation and secure access plugin, supporting LAN, remote connections, Android App, and mobile browsers.DSCODE@toddzheng024/dscode-bundleA complete DeepSeek coding agent with persistent shell, Ultra collaboration and automatic permission review.Auto Reviewdsh-auto-reviewSecond-model AI auto-review for DeepSeek Harness approval requests: a read-only reviewer subagent decides allow/deny on the approval answerer chain, with fail-closed fallback and full session-log audit.

README

dsh-windows-readiness-proof

dsh-windows-readiness-proof evaluates a SHA-256-pinned, sanitized observation of a managed Windows host against explicit DeepSeek Harness readiness requirements.

It is an evidence verifier, not a collector or remediation tool. It never runs PowerShell, reads the registry, changes Group Policy, creates Defender exclusions, edits WDAC/AppLocker, installs software, restarts services, or probes the network.

What it proves

An explicit manifest fixes an opaque machine digest, snapshot revision, observation bytes, evaluation time, maximum evidence age, and requirements for:

  • Windows product type, architecture, build, and pending reboot;
  • Node, DSH, PowerShell edition/version, and language mode;
  • classified WDAC, AppLocker, Defender, execution policy, Credential Guard, and TLS 1.2 posture;
  • long paths, atomic rename, workspace/temp ACL class, and symlink policy;
  • non-interactive session, opaque identity class, writable profile, and recovery configuration;
  • free workspace/temp storage;
  • required connectivity identities represented only by endpoint SHA-256 plus status/TLS/proxy classes.

Missing, stale, future, malformed, secret-shaped, identity-bearing, path-escaping, symlinked, or policy-mismatched evidence fails closed. Reports expose only opaque identities, hashes, classifications, reason codes, and control status—not usernames, domains, endpoints, registry paths, command output, credentials, or raw observations.

Complementary boundary

Harness Doctor diagnoses local DSH/Codex/OpenClaw installation health. Windows desktop-control skills execute UI and PowerShell actions. This plugin does neither: it verifies a pre-collected enterprise readiness fact set under a reviewable policy and produces a deterministic artifact suitable for CI or audit.

CLI

dsh-windows-readiness-proof inspect --workspace . --manifest manifest.json
dsh-windows-readiness-proof verify --workspace . --manifest manifest.json --artifactDir artifacts

Exit 0 means verified; exit 2 means a readiness or evidence failure.

DSH / MCP tools

The DSH entry is a namespace plugin (name / inject / apply) with no default export. This is part of the shipped compatibility contract: the real Cordis Loader must retain the tools injection when a stock Web profile loads the bundle. The plugin smoke and structural check fail if a default export is reintroduced.

For a built DSH checkout and an isolated Web profile containing this bundle, run DSH_CHECKOUT=/path/to/dsh DSH_HOME=/path/to/isolated-home npm run smoke:web-loader. The smoke starts the real stock Web profile with a bounded, credential-free environment and requires an actual readiness URL.

  • dsh_windows_readiness_inspect
  • dsh_windows_readiness_verify
  • MCP aliases: windows_readiness_inspect, windows_readiness_verify
dsh plugin --profile windows-readiness add github:dongsheng123132/dsh-windows-readiness-proof#<commit>

See examples/README.md for a synthetic, non-collecting example. MIT licensed.