Method limitation. This historical execution used a container with network access and published container paths and replay fixture text. The no-egress and redaction conditions were not met. See the security incident.
sha512-gS1Xh27k6dU3FeI5XN/sX72pdWy6ypr9MkiAki/u28mmxTS+sqyGRFXTdIR8BUb3J/zKcWQJoadNkv8zR7Qd3g==
| name | dsh-codex-connect |
|---|---|
| version | 0.2.0-alpha.1 |
| integrity | sha512-gS1Xh27k6dU3FeI5XN/sX72pdWy6ypr9MkiAki/u28mmxTS+sqyGRFXTdIR8BUb3J/zKcWQJoadNkv8zR7Qd3g== |
| repository | git+https://github.com/franksong2702/dsh-codex-connect.git |
| declared bundle patch | "./cordis.patch.yml" |
| declared engines.dsh | not declared — declarative and unenforced |
| DSH | 0.2.0-rc.2 |
|---|---|
| Node | v24.21.0 |
| OS / arch | linux 6.17.0-1022-azure x64 |
| verifier | dsh-verified 0.1.0 b737da1e4edd |
| generated | 2026-10-03T16:50:28.029Z |
| status | summary | evidence | |
|---|---|---|---|
L0 |
pass | declares dsh.bundle.patch and every declared patch path exists (146 files, 3394494 bytes unpacked)
dsh.manifestVersion is not declared; the reader does not infer a default tarball ships no src/ paths, so capability findings are limited to build output metrics{
"fileCount": 146,
"unpackedBytes": 3394494,
"patchPaths": [
"./cordis.patch.yml"
],
"declaredEnginesDsh": null,
"shipsSource": false
} |
e-resolve, e-tarball, e-l0 |
L1 |
fail | installation blocked pending dependency build-script approval
pnpm refused to run build scripts for 2 package(s) and the install did not complete. This verifier never approves them: approval permits commands with the host user's permissions, which is the user's decision and a finding rather than a chore. The requested scripts are listed in the metrics. no dependency build script was approved by the verifier; approval permits commands with the host user permissions metrics{
"durationMs": 2627,
"exitCode": 1,
"declaredPeers": null,
"bundlesAfterInstall": [
"@deepseek-ai/dsh-base"
],
"pendingBuildScripts": [
"@google/genai@1.52.0",
"protobufjs@7.6.6"
],
"buildScriptsApproved": 0,
"diagnosticsLog": "/work/dsh-home/profiles/verify/.plugin-manager/logs/operation-66kXe5/pnpm.log"
} |
e-l1-install |
L2 |
skip | not run: the subject did not install
loading a plugin that is not present would measure nothing |
no evidence cited |
L3 |
skip | not run: the subject did not install
a session cannot be attributed to a subject that is not present |
no evidence cited |
L4 |
pass | 5 capability signal(s) present across 9 scanned file(s)
the package ships build output; code inside a bundle cannot be reliably attributed to the author or to an inlined dependency static analysis cannot see dynamically constructed code or prove intent metrics{
"scannedFiles": 9,
"scannedBytes": 1340274,
"skippedFiles": 0
} |
e-l4, e-patch |
L5 |
inconclusive | the subject did not install, so there was nothing to activate
no overhead claim is made when the differential could not be completed metrics{
"samples": 0
} |
no evidence cited |
L6 |
skip | not run: the subject did not install
removal was not attempted because nothing was installed |
no evidence cited |
| capability | confidence | attribution | first evidence |
|---|---|---|---|
eval_or_dynamic_code | medium | unknown | package/lib/bin.js:4546 |
hooks_api_gate | medium | unknown | package/lib/bin.js:6391 |
listens_on_port | medium | unknown | package/lib/bin.js:1620 |
network_egress | medium | unknown | package/lib/bin.js:1458 |
spawns_process | medium | unknown | package/lib/bin.js:4 |
Capability is not intent. A signature records what the code can reach for, not what it does.
No overhead measurement was published for this report.
| id | kind | artifact |
|---|---|---|
e-resolve |
command exit 0 128 ms | resolve dsh-codex-connect@0.2.0-alpha.1 -> dsh-codex-connect@0.2.0-alpha.1
{
"name": "dsh-codex-connect",
"version": "0.2.0-alpha.1",
"registry": "https://registry.npmjs.org",
"tarball": "https://registry.npmjs.org/dsh-codex-connect/-/dsh-codex-connect-0.2.0-alpha.1.tgz",
"advertisedIntegrity": "sha512-gS1Xh27k6dU3FeI5XN/sX72pdWy6ypr9MkiAki/u28mmxTS+sqyGRFXTdIR8BUb3J/zKcWQJoadNkv8zR7Qd3g==",
"publishedAt": "2026-09-30T14:36:29.251Z"
}
|
e-tarball |
artifact exit 0 38 ms | fetch https://registry.npmjs.org/dsh-codex-connect/-/dsh-codex-connect-0.2.0-alpha.1.tgz
{
"bytes": 1564335,
"resolvedIntegrity": "sha512-gS1Xh27k6dU3FeI5XN/sX72pdWy6ypr9MkiAki/u28mmxTS+sqyGRFXTdIR8BUb3J/zKcWQJoadNkv8zR7Qd3g==",
"advertisedIntegrity": "sha512-gS1Xh27k6dU3FeI5XN/sX72pdWy6ypr9MkiAki/u28mmxTS+sqyGRFXTdIR8BUb3J/zKcWQJoadNkv8zR7Qd3g==",
"integrityMatchesRegistry": true,
"sha256": "afe0c5e9cb08d10912ddf215c8b7f601b9a6d51adfa5cb0cb34e2e7ae8c7258a"
}
|
e-l0 |
static | read published package.json and verify declared dsh.bundle.patch paths exist
{
"status": "pass",
"reasons": [],
"declared": {
"manifestVersion": null,
"bundlePatch": [
"./cordis.patch.yml"
],
"clientPlatform": "web",
"enginesDsh": null,
"enginesNode": "^22.19.0 || >=24.0.0"
},
"missingPatchPaths": [],
"fileCount": 146,
"unpackedBytes": 3394494,
"shipsSource": false
}
|
e-patch |
static | read cordis.patch.yml
# Install the provider without changing the profile's current default model or
# web-search route. Optional capabilities require explicit profile config.
- insert:
- id: llm-openai-codex
name: dsh-codex-connect
config:
enableProxy: false
enableSearch: false
enableReserveFallback: false
enableNativeCompaction: false
enableImageTool: false
enableImageGeneration: false
enableAutoReview: false
|
e-l4 |
static | scan 9 shipped source file(s) for capability signatures
{
"present": [
{
"id": "eval_or_dynamic_code",
"confidence": "medium",
"attribution": "unknown",
"firstEvidence": {
"file": "package/lib/bin.js",
"line": 4546,
"snippet": "schema.callback = new Function(\"return \" + schema.callback)();"
}
},
{
"id": "hooks_api_gate",
"confidence": "medium",
"attribution": "unknown",
"firstEvidence": {
"file": "package/lib/bin.js",
"line": 6391,
"snippet": "return this.ctx.waterfall(this, \"llm/stream\", options, () => this.adapterStream(options, prepared));"
}
},
{
"id": "listens_on_port",
"confidence": "medium",
"attribution": "unknown",
"firstEvidence": {
"file": "package/lib/bin.js",
"line": 1620,
"snippet": "const server = _http.createServer((req, res) => {"
}
},
{
"id": "network_egress",
"confidence": "medium",
"attribution": "unknown",
"firstEvidence": {
"file": "package/lib/bin.js",
"line": 1458,
"snippet": "return await fetch(input, init);"
}
},
{
"id": "spawns_process",
"confidence": "medium",
"attribution": "unknown",
"firstEvidence": {
"file": "package/lib/bin.js",
"line": 4,
"snippet": "import { spawn } from \"node:child_process\";"
}
}
],
"scannedFiles": 9,
"skippedFiles": 0,
"limits": [
"the package ships build output; code inside a bundle cannot be reliably attributed to the author or to an inlined dependency",
"static analysis cannot see dynamically constructed code or prove intent"
]
}
|
e-l1-install |
command exit 1 2627 ms | dsh plugin --profile verify add dsh-codex-connect@0.2.0-alpha.1
Progress: resolved 0, reused 0, downloaded 1, added 0
[WARN] 1 deprecated subdependencies found: node-domexception@1.0.0
Packages are hard linked from the content-addressable store to the virtual store.
Content-addressable store is at: /home/verifier/.local/share/pnpm/store/v11
Virtual store is at: node_modules/.pnpm
Packages: +97
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Progress: resolved 96, reused 0, downloaded 97, added 97, done
[WARN] Issues with peer dependencies found. Run "pnpm peers check" to list them.
dependencies:
+ dsh-codex-connect 0.2.0-alpha.1
dsh: initialized profile verify at /work/dsh-home/profiles/verify
Error: ERR_PNPM_IGNORED_BUILDS
× adding a new package
╰─▶ Ignored build scripts: @google/genai@1.52.0, protobufjs@7.6.6
help: Run "pnpm approve-builds" to pick which dependencies should be allowed
to run scripts.
dsh: plugin command failed; diagnostics: /work/dsh-home/profiles/verify/.plugin-manager/logs/operation-66kXe5/pnpm.log
|