插件目录 / Developer / dsh-windows-readiness-proof
dsh-windows-readiness-proof
已验证 · 实测可装 dongsheng123132
功能简介
托管Windows主机上净化DSH观察的内容寻址就绪证明
可用 — 实测通过,早期项目
托管Windows主机上净化DSH观察的内容寻址就绪证明 实测能干净安装、正常启动。早期项目,但功能可用。
「已验证」表示我们的自动化 CI 在干净 profile 里实际执行了 dsh plugin add 并启动成功——仅此而已。功能描述与版本兼容性均为作者声明。这不是安全审计,也不代表对第三方代码的背书。
README
dsh-windows-readiness-proof
dsh-windows-readiness-proof evaluates a SHA-256-pinned, sanitized observation of a managed Windows host against explicit DeepSeek Harness readiness requirements.
It is an evidence verifier, not a collector or remediation tool. It never runs PowerShell, reads the registry, changes Group Policy, creates Defender exclusions, edits WDAC/AppLocker, installs software, restarts services, or probes the network.
What it proves
An explicit manifest fixes an opaque machine digest, snapshot revision, observation bytes, evaluation time, maximum evidence age, and requirements for:
- Windows product type, architecture, build, and pending reboot;
- Node, DSH, PowerShell edition/version, and language mode;
- classified WDAC, AppLocker, Defender, execution policy, Credential Guard, and TLS 1.2 posture;
- long paths, atomic rename, workspace/temp ACL class, and symlink policy;
- non-interactive session, opaque identity class, writable profile, and recovery configuration;
- free workspace/temp storage;
- required connectivity identities represented only by endpoint SHA-256 plus status/TLS/proxy classes.
Missing, stale, future, malformed, secret-shaped, identity-bearing, path-escaping, symlinked, or policy-mismatched evidence fails closed. Reports expose only opaque identities, hashes, classifications, reason codes, and control status锟斤拷not usernames, domains, endpoints, registry paths, command output, credentials, or raw observations.
Complementary boundary
Harness Doctor diagnoses local DSH/Codex/OpenClaw installation health. Windows desktop-control skills execute UI and PowerShell actions. This plugin does neither: it verifies a pre-collected enterprise readiness fact set under a reviewable policy and produces a deterministic artifact suitable for CI or audit.
CLI
dsh-windows-readiness-proof inspect --workspace . --manifest manifest.json
dsh-windows-readiness-proof verify --workspace . --manifest manifest.json --artifactDir artifacts
Exit 0 means verified; exit 2 means a readiness or evidence failure.
DSH / MCP tools
The DSH entry is a namespace plugin (name / inject / apply) with no default export. This is part of the shipped compatibility contract: the real Cordis Loader must retain the tools injection when a stock Web profile loads the bundle. The plugin smoke and structural check fail if a default export is reintroduced.
For a built DSH checkout and an isolated Web profile containing this bundle, run DSH_CHECKOUT=/path/to/dsh DSH_HOME=/path/to/isolated-home npm run smoke:web-loader. The smoke starts the real stock Web profile with a bounded, credential-free environment and requires an actual readiness URL.
dsh_windows_readiness_inspectdsh_windows_readiness_verify- MCP aliases:
windows_readiness_inspect,windows_readiness_verify
dsh plugin --profile windows-readiness add github:dongsheng123132/dsh-windows-readiness-proof#<commit>
See examples/README.md for a synthetic, non-collecting example. MIT licensed.
安装
装一次目录插件,之后本站所有插件都能让 DeepSeek Harness 自动找、自动装:
dsh plugin add dshbase-catalog 然后对 agent 说「帮我装 dsh-windows-readiness-proof」,它会在目录里找到并自动安装。文档:dshbase-catalog · 已验证场景包。
该插件是 GitHub 源码(未发 npm)——直接从仓库装:
Web profile:
dsh plugin --profile web add github:dongsheng123132/dsh-windows-readiness-proof Headless(CLI)profile:
dsh plugin --profile headless add github:dongsheng123132/dsh-windows-readiness-proof 实测报告
验证通过:从 GitHub 源码完成 L1 安装 + L2 加载 + L3 运行(dsh 0.1.0-rc.6)。
使用场景
扩展 agent 的编码能力面——给它一个新工具、工作流或集成,让它接手以前做不了的开发任务。
适合谁
想让 dsh 在真实代码库上像队友一样干活的开发者——能改、能跑、能验证,而不只是回答问题。
二次开发建议
工具/命令面就是缝:暴露更多 SDK 能力、加更聪明的上下文接线,或收紧改代码与验证之间的循环。