{
  "schema": "dsh.plugin.report.v1",
  "reportId": "npm:dsh-codex-connect@0.2.0-alpha.1",
  "generatedAt": "2026-10-03T16:50:28.029Z",
  "verifier": {
    "name": "dsh-verified",
    "version": "0.1.0",
    "commit": "b737da1e4edd069bd6d914820d1fee86faf27e83"
  },
  "subject": {
    "spec": "dsh-codex-connect@0.2.0-alpha.1",
    "name": "dsh-codex-connect",
    "version": "0.2.0-alpha.1",
    "registry": "https://registry.npmjs.org",
    "tarball": "https://registry.npmjs.org/dsh-codex-connect/-/dsh-codex-connect-0.2.0-alpha.1.tgz",
    "integrity": "sha512-gS1Xh27k6dU3FeI5XN/sX72pdWy6ypr9MkiAki/u28mmxTS+sqyGRFXTdIR8BUb3J/zKcWQJoadNkv8zR7Qd3g==",
    "shasum": "18bff435d2b254495c3e7542c35ad136cb8a40e2",
    "repository": "git+https://github.com/franksong2702/dsh-codex-connect.git",
    "license": "Apache-2.0",
    "publishedAt": "2026-09-30T14:36:29.251Z",
    "dshBundlePatch": "./cordis.patch.yml"
  },
  "runtime": {
    "dshVersion": "0.2.0-rc.2",
    "nodeVersion": "v24.21.0",
    "os": "linux 6.17.0-1022-azure",
    "arch": "x64"
  },
  "container": {
    "image": "none",
    "imageDigest": null,
    "notes": "executed in a one-off container; the subject was installed, booted and removed there"
  },
  "verdict": "partial",
  "dimensions": {
    "L0_qualification": {
      "id": "L0",
      "status": "pass",
      "summary": "declares dsh.bundle.patch and every declared patch path exists (146 files, 3394494 bytes unpacked)",
      "metrics": {
        "fileCount": 146,
        "unpackedBytes": 3394494,
        "patchPaths": [
          "./cordis.patch.yml"
        ],
        "declaredEnginesDsh": null,
        "shipsSource": false
      },
      "evidenceRefs": [
        "e-resolve",
        "e-tarball",
        "e-l0"
      ],
      "notes": [
        "dsh.manifestVersion is not declared; the reader does not infer a default",
        "tarball ships no src/ paths, so capability findings are limited to build output"
      ]
    },
    "L1_install": {
      "id": "L1",
      "status": "fail",
      "summary": "installation blocked pending dependency build-script approval",
      "metrics": {
        "durationMs": 2627,
        "exitCode": 1,
        "declaredPeers": null,
        "bundlesAfterInstall": [
          "@deepseek-ai/dsh-base"
        ],
        "pendingBuildScripts": [
          "@google/genai@1.52.0",
          "protobufjs@7.6.6"
        ],
        "buildScriptsApproved": 0,
        "diagnosticsLog": "/work/dsh-home/profiles/verify/.plugin-manager/logs/operation-66kXe5/pnpm.log"
      },
      "evidenceRefs": [
        "e-l1-install"
      ],
      "notes": [
        "pnpm refused to run build scripts for 2 package(s) and the install did not complete. This verifier never approves them: approval permits commands with the host user's permissions, which is the user's decision and a finding rather than a chore. The requested scripts are listed in the metrics.",
        "no dependency build script was approved by the verifier; approval permits commands with the host user permissions"
      ]
    },
    "L2_load": {
      "id": "L2",
      "status": "skip",
      "summary": "not run: the subject did not install",
      "evidenceRefs": [],
      "notes": [
        "loading a plugin that is not present would measure nothing"
      ]
    },
    "L3_run": {
      "id": "L3",
      "status": "skip",
      "summary": "not run: the subject did not install",
      "evidenceRefs": [],
      "notes": [
        "a session cannot be attributed to a subject that is not present"
      ]
    },
    "L4_capability": {
      "id": "L4",
      "status": "pass",
      "summary": "5 capability signal(s) present across 9 scanned file(s)",
      "metrics": {
        "scannedFiles": 9,
        "scannedBytes": 1340274,
        "skippedFiles": 0
      },
      "evidenceRefs": [
        "e-l4",
        "e-patch"
      ],
      "notes": [
        "the package ships build output; code inside a bundle cannot be reliably attributed to the author or to an inlined dependency",
        "static analysis cannot see dynamically constructed code or prove intent"
      ]
    },
    "L5_overhead": {
      "id": "L5",
      "status": "inconclusive",
      "summary": "the subject did not install, so there was nothing to activate",
      "metrics": {
        "samples": 0
      },
      "evidenceRefs": [],
      "notes": [
        "no overhead claim is made when the differential could not be completed"
      ]
    },
    "L6_uninstall": {
      "id": "L6",
      "status": "skip",
      "summary": "not run: the subject did not install",
      "evidenceRefs": [],
      "notes": [
        "removal was not attempted because nothing was installed"
      ]
    }
  },
  "capabilities": [
    {
      "id": "eval_or_dynamic_code",
      "present": true,
      "confidence": "medium",
      "attribution": "unknown",
      "notes": "eval or synthesised code; common and often benign, and frequently bundler output",
      "evidence": [
        {
          "file": "package/lib/bin.js",
          "line": 4546,
          "snippet": "schema.callback = new Function(\"return \" + schema.callback)();"
        }
      ]
    },
    {
      "id": "hooks_api_gate",
      "present": true,
      "confidence": "medium",
      "attribution": "unknown",
      "notes": "hooks the API/LLM path, so it can observe or alter provider traffic",
      "evidence": [
        {
          "file": "package/lib/bin.js",
          "line": 6391,
          "snippet": "return this.ctx.waterfall(this, \"llm/stream\", options, () => this.adapterStream(options, prepared));"
        },
        {
          "file": "package/lib/index.js",
          "line": 11325,
          "snippet": "ctx.on(\"llm/stream\", (request, next) => {"
        }
      ]
    },
    {
      "id": "listens_on_port",
      "present": true,
      "confidence": "medium",
      "attribution": "unknown",
      "notes": "opens a listening socket",
      "evidence": [
        {
          "file": "package/lib/bin.js",
          "line": 1620,
          "snippet": "const server = _http.createServer((req, res) => {"
        },
        {
          "file": "package/lib/index.js",
          "line": 502,
          "snippet": "const server = _http.createServer((req, res) => {"
        }
      ]
    },
    {
      "id": "network_egress",
      "present": true,
      "confidence": "medium",
      "attribution": "unknown",
      "notes": "can make outbound network requests",
      "evidence": [
        {
          "file": "package/lib/bin.js",
          "line": 1458,
          "snippet": "return await fetch(input, init);"
        },
        {
          "file": "package/lib/client.js",
          "line": 183,
          "snippet": "const response = await fetch(path, {"
        },
        {
          "file": "package/lib/undici-runtime-Ctml-NLj.js",
          "line": 4,
          "snippet": "const LEGACY_GLOBAL_DISPATCHER = Symbol.for(\"undici.globalDispatcher.1\");"
        },
        {
          "file": "package/lib/index.d.ts",
          "line": 229,
          "snippet": "fetch(input: string | URL | Request, init?: RequestInit, options?: Omit<OpenAICodexBackendFetchOptions, 'lane'>): Promise<Response>;"
        },
        {
          "file": "package/lib/index.js",
          "line": 1,
          "snippet": "import { a as setGlobalDispatcher, i as getGlobalDispatcher, n as ProxyAgent, r as fetch$1, t as Dispatcher } from \"./undici-runtime-Ctml-NLj.js\";"
        }
      ]
    },
    {
      "id": "spawns_process",
      "present": true,
      "confidence": "medium",
      "attribution": "unknown",
      "notes": "spawns or would spawn an operating-system process",
      "evidence": [
        {
          "file": "package/lib/bin.js",
          "line": 4,
          "snippet": "import { spawn } from \"node:child_process\";"
        }
      ]
    },
    {
      "id": "hooks_system_prompt",
      "present": false,
      "confidence": "medium",
      "attribution": "unknown",
      "notes": "hooks system-prompt assembly, so it can influence what the model is told",
      "evidence": []
    },
    {
      "id": "reads_secret_env",
      "present": false,
      "confidence": "high",
      "attribution": "unknown",
      "notes": "reads an environment variable whose name looks credential-shaped",
      "evidence": []
    },
    {
      "id": "runtime_patch",
      "present": false,
      "confidence": "medium",
      "attribution": "unknown",
      "notes": "patches runtime objects rather than only registering its own services",
      "evidence": []
    },
    {
      "id": "watches_filesystem",
      "present": false,
      "confidence": "high",
      "attribution": "unknown",
      "notes": "watches the filesystem; a recursive workspace watch is the documented cause of host stalls",
      "evidence": []
    },
    {
      "id": "writes_outside_workspace",
      "present": false,
      "confidence": "low",
      "attribution": "unknown",
      "notes": "resolves a path outside the workspace (e.g. os.homedir(), DSH_HOME), which is normal for DSH profile handling; static analysis cannot determine whether it also writes there",
      "evidence": []
    }
  ],
  "evidence": [
    {
      "id": "e-resolve",
      "kind": "command",
      "command": "resolve dsh-codex-connect@0.2.0-alpha.1 -> dsh-codex-connect@0.2.0-alpha.1",
      "exitCode": 0,
      "durationMs": 128,
      "excerpt": "{\n  \"name\": \"dsh-codex-connect\",\n  \"version\": \"0.2.0-alpha.1\",\n  \"registry\": \"https://registry.npmjs.org\",\n  \"tarball\": \"https://registry.npmjs.org/dsh-codex-connect/-/dsh-codex-connect-0.2.0-alpha.1.tgz\",\n  \"advertisedIntegrity\": \"sha512-gS1Xh27k6dU3FeI5XN/sX72pdWy6ypr9MkiAki/u28mmxTS+sqyGRFXTdIR8BUb3J/zKcWQJoadNkv8zR7Qd3g==\",\n  \"publishedAt\": \"2026-09-30T14:36:29.251Z\"\n}"
    },
    {
      "id": "e-tarball",
      "kind": "artifact",
      "command": "fetch https://registry.npmjs.org/dsh-codex-connect/-/dsh-codex-connect-0.2.0-alpha.1.tgz",
      "exitCode": 0,
      "durationMs": 38,
      "excerpt": "{\n  \"bytes\": 1564335,\n  \"resolvedIntegrity\": \"sha512-gS1Xh27k6dU3FeI5XN/sX72pdWy6ypr9MkiAki/u28mmxTS+sqyGRFXTdIR8BUb3J/zKcWQJoadNkv8zR7Qd3g==\",\n  \"advertisedIntegrity\": \"sha512-gS1Xh27k6dU3FeI5XN/sX72pdWy6ypr9MkiAki/u28mmxTS+sqyGRFXTdIR8BUb3J/zKcWQJoadNkv8zR7Qd3g==\",\n  \"integrityMatchesRegistry\": true,\n  \"sha256\": \"afe0c5e9cb08d10912ddf215c8b7f601b9a6d51adfa5cb0cb34e2e7ae8c7258a\"\n}",
      "excerptBytes": 384,
      "sha256": "afe0c5e9cb08d10912ddf215c8b7f601b9a6d51adfa5cb0cb34e2e7ae8c7258a"
    },
    {
      "id": "e-l0",
      "kind": "static",
      "command": "read published package.json and verify declared dsh.bundle.patch paths exist",
      "excerpt": "{\n  \"status\": \"pass\",\n  \"reasons\": [],\n  \"declared\": {\n    \"manifestVersion\": null,\n    \"bundlePatch\": [\n      \"./cordis.patch.yml\"\n    ],\n    \"clientPlatform\": \"web\",\n    \"enginesDsh\": null,\n    \"enginesNode\": \"^22.19.0 || >=24.0.0\"\n  },\n  \"missingPatchPaths\": [],\n  \"fileCount\": 146,\n  \"unpackedBytes\": 3394494,\n  \"shipsSource\": false\n}",
      "excerptBytes": 338
    },
    {
      "id": "e-patch",
      "kind": "static",
      "command": "read cordis.patch.yml",
      "excerpt": "# Install the provider without changing the profile's current default model or\n# web-search route. Optional capabilities require explicit profile config.\n- insert:\n    - id: llm-openai-codex\n      name: dsh-codex-connect\n      config:\n        enableProxy: false\n        enableSearch: false\n        enableReserveFallback: false\n        enableNativeCompaction: false\n        enableImageTool: false\n        enableImageGeneration: false\n        enableAutoReview: false\n",
      "excerptBytes": 465,
      "sha256": "a94e0b6c7416471892274477e149159985283097bbde3147a4c83b919a5e6516"
    },
    {
      "id": "e-l4",
      "kind": "static",
      "command": "scan 9 shipped source file(s) for capability signatures",
      "excerpt": "{\n  \"present\": [\n    {\n      \"id\": \"eval_or_dynamic_code\",\n      \"confidence\": \"medium\",\n      \"attribution\": \"unknown\",\n      \"firstEvidence\": {\n        \"file\": \"package/lib/bin.js\",\n        \"line\": 4546,\n        \"snippet\": \"schema.callback = new Function(\\\"return \\\" + schema.callback)();\"\n      }\n    },\n    {\n      \"id\": \"hooks_api_gate\",\n      \"confidence\": \"medium\",\n      \"attribution\": \"unknown\",\n      \"firstEvidence\": {\n        \"file\": \"package/lib/bin.js\",\n        \"line\": 6391,\n        \"snippet\": \"return this.ctx.waterfall(this, \\\"llm/stream\\\", options, () => this.adapterStream(options, prepared));\"\n      }\n    },\n    {\n      \"id\": \"listens_on_port\",\n      \"confidence\": \"medium\",\n      \"attribution\": \"unknown\",\n      \"firstEvidence\": {\n        \"file\": \"package/lib/bin.js\",\n        \"line\": 1620,\n        \"snippet\": \"const server = _http.createServer((req, res) => {\"\n      }\n    },\n    {\n      \"id\": \"network_egress\",\n      \"confidence\": \"medium\",\n      \"attribution\": \"unknown\",\n      \"firstEvidence\": {\n        \"file\": \"package/lib/bin.js\",\n        \"line\": 1458,\n        \"snippet\": \"return await fetch(input, init);\"\n      }\n    },\n    {\n      \"id\": \"spawns_process\",\n      \"confidence\": \"medium\",\n      \"attribution\": \"unknown\",\n      \"firstEvidence\": {\n        \"file\": \"package/lib/bin.js\",\n        \"line\": 4,\n        \"snippet\": \"import { spawn } from \\\"node:child_process\\\";\"\n      }\n    }\n  ],\n  \"scannedFiles\": 9,\n  \"skippedFiles\": 0,\n  \"limits\": [\n    \"the package ships build output; code inside a bundle cannot be reliably attributed to the author or to an inlined dependency\",\n    \"static analysis cannot see dynamically constructed code or prove intent\"\n  ]\n}",
      "excerptBytes": 1688
    },
    {
      "id": "e-l1-install",
      "kind": "command",
      "command": "dsh plugin --profile verify add dsh-codex-connect@0.2.0-alpha.1",
      "exitCode": 1,
      "durationMs": 2627,
      "excerpt": "Progress: resolved 0, reused 0, downloaded 1, added 0\n[WARN] 1 deprecated subdependencies found: node-domexception@1.0.0\nPackages are hard linked from the content-addressable store to the virtual store.\n  Content-addressable store is at: /home/verifier/.local/share/pnpm/store/v11\n  Virtual store is at:             node_modules/.pnpm\nPackages: +97\n++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++\nProgress: resolved 96, reused 0, downloaded 97, added 97, done\n[WARN] Issues with peer dependencies found. Run \"pnpm peers check\" to list them.\n\ndependencies:\n+ dsh-codex-connect 0.2.0-alpha.1\n\ndsh: initialized profile verify at /work/dsh-home/profiles/verify\nError: ERR_PNPM_IGNORED_BUILDS\n\n  × adding a new package\n  ╰─▶ Ignored build scripts: @google/genai@1.52.0, protobufjs@7.6.6\n  help: Run \"pnpm approve-builds\" to pick which dependencies should be allowed\n        to run scripts.\n\ndsh: plugin command failed; diagnostics: /work/dsh-home/profiles/verify/.plugin-manager/logs/operation-66kXe5/pnpm.log\n",
      "excerptBytes": 1045,
      "truncated": false,
      "sha256": "22aa136bb164cb9971b776410682e1c47ed133a0e57a1f15f97bf6c300a8c6e8"
    }
  ],
  "redactions": [],
  "disclaimers": [
    "Verification is not a security audit and not an endorsement. It records what was executed and observed on one machine at one time. Absence of a finding is not a finding of absence."
  ],
  "limits": [
    "the artifact ships no source paths, so capability findings describe build output only; code-level attribution between the author and inlined dependencies is not resolvable from this artifact",
    "the package ships build output; code inside a bundle cannot be reliably attributed to the author or to an inlined dependency",
    "static analysis cannot see dynamically constructed code or prove intent",
    "L5 overhead sampling did not complete, so no cost claim is made",
    "the load result is inferred from exit behaviour and diagnostics rather than a directly read fiber phase",
    "no dependency build script was approved by this executor",
    "overhead is reported only where a delta cleared the significance thresholds; otherwise the result is no-significant-delta",
    "sampling happens inside the host process via NODE_OPTIONS=--import, so process.getActiveResourcesInfo() and process.report.getReport() describe the process under test"
  ],
  "bundlePatch": {
    "path": "cordis.patch.yml",
    "present": true,
    "bytes": 465,
    "entryCount": 2,
    "disablesHostEntries": false,
    "overridesConfig": true,
    "usesJsExpressions": false,
    "findings": [
      {
        "kind": "inserts-entry",
        "line": 3,
        "snippet": "- insert:"
      },
      {
        "kind": "inserts-entry",
        "line": 4,
        "snippet": "- id: llm-openai-codex"
      },
      {
        "kind": "overrides-config",
        "line": 6,
        "snippet": "config:"
      }
    ],
    "notes": [
      "textual analysis: a line number is provided for review, not a YAML object model"
    ]
  }
}
