插件目录 / Security / dsh-file-checksum
dsh-file-checksum
已验证 · 实测可装 yan9651688
功能简介
文件SHA-256/512验证插件
可用 — 实测通过,早期项目
文件SHA-256/512验证插件 实测能干净安装、正常启动。早期项目,但功能可用。
「已验证」表示我们的自动化 CI 在干净 profile 里实际执行了 dsh plugin add 并启动成功——仅此而已。功能描述与版本兼容性均为作者声明。这不是安全审计,也不代表对第三方代码的背书。
README
dsh-file-checksum
A small, read-only DeepSeek Harness plugin that computes SHA-256 or SHA-512 for a file through the active Harness filesystem provider.
Unlike text-hashing tools, file_checksum reads the file's raw bytes without placing its contents in the model conversation. It works with the filesystem mounted by the current DSH profile, including compatible remote providers.
Install
Install directly from GitHub into a profile:
dsh plugin --profile web add github:yan9651688/dsh-file-checksum
For reproducible installs, pin a commit:
dsh plugin --profile web add github:yan9651688/dsh-file-checksum#<commit-sha>
Then start that profile as usual:
dsh --profile web --dump-config
dsh --profile web
This repository ships plain ESM JavaScript, so a GitHub install does not need a prepare build or pnpm allowBuilds entry.
Tool
file_checksum accepts:
| Parameter | Required | Description |
|---|---|---|
file_path |
yes | Absolute path, or a path relative to the current agent session workspace. |
algorithm |
no | sha256 (default) or sha512. |
expected |
no | Expected hexadecimal digest. The tool returns match or mismatch. |
Example prompt:
Use file_checksum to verify dist/app.tgz against this SHA-256: <digest>
The canonical result is structured for Native and Code Mode callers:
{
"path": "/workspace/dist/app.tgz",
"algorithm": "sha256",
"digest": "...",
"bytes": 12345,
"verification": "match"
}
A checksum mismatch is a successful tool result with verification: "mismatch"; missing, non-regular, oversized, or unreadable files are tool errors.
Configuration
The bundle defaults to a 64 MiB whole-file limit:
- insert:
- id: file-checksum
name: dsh-file-checksum
config:
maxBytes: 67108864
Override the row in a later profile patch to choose a different positive integer, up to 256 MiB. The limit exists because the current DSH raw-byte filesystem API returns a complete bounded file rather than a byte stream.
Data and safety
- Reads through
ctx.fs; it does not invoke a shell or bypass the active filesystem provider. - Reads one regular file and never writes or deletes files.
- Declares checksum calls exclusive so one Native or Code Mode batch cannot multiply the configured whole-file memory limit.
- Does not access environment variables, credentials, or the network.
- Returns the digest, byte count, display path, and verification status; it does not return file contents.
- Records the successful or missing read through DSH's
fs/observedevent, matching the built-in file-read behavior. - A digest identifies content integrity. It is not encryption and does not make sensitive data safe to share.
Known limitations
- One file per call; directories and Git tree hashes are not supported.
- Files larger than
maxBytesare rejected rather than streamed or truncated. - Separate agents or sessions may still run calls concurrently; each call can buffer up to
maxBytes. - The plugin is intended for DSH
0.1.0-rc.6and later compatible0.1.xreleases. DeepSeek Harness is still in developer preview, so breaking upstream changes may require a plugin update.
Development
npm install
npm test
npm pack --dry-run
The tests mount the real Cordis context, tool registry, and local DSH filesystem provider. They cover standard hash vectors, binary bytes, expected-digest comparison, session-relative paths, filesystem observations, error cases, and lifecycle cleanup.
License
安装
装一次目录插件,之后本站所有插件都能让 DeepSeek Harness 自动找、自动装:
dsh plugin add dshbase-catalog 然后对 agent 说「帮我装 dsh-file-checksum」,它会在目录里找到并自动安装。文档:dshbase-catalog · 已验证场景包。
该插件是 GitHub 源码(未发 npm)——直接从仓库装:
Web profile:
dsh plugin --profile web add github:yan9651688/dsh-file-checksum Headless(CLI)profile:
dsh plugin --profile headless add github:yan9651688/dsh-file-checksum 实测报告
验证通过:从 GitHub 源码完成 L1 安装 + L2 加载 + L3 运行(dsh 0.1.0-rc.6)。
使用场景
加固 agent 或其工作区——扫描、净化或审计——先拦下不可信内容和代码。
适合谁
在意供应链和提示注入风险、想要内置防护的人。
二次开发建议
检测器和策略是缝——加规则、作用域或更丰富的被标记项审计日志。