Method limitation. This historical execution used a container with network access and published container paths and replay fixture text. The no-egress and redaction conditions were not met. See the security incident.
sha512-XO0zQb3iHxK7IGGygfiGDxI3t4HUEBNLK4knqYmh8KuT2cbCWzmH+4PViaIgVPsiytC7mXN5p94u5fJc3VNsBw==
| name | dsh-find-plugin |
|---|---|
| version | 0.4.0 |
| integrity | sha512-XO0zQb3iHxK7IGGygfiGDxI3t4HUEBNLK4knqYmh8KuT2cbCWzmH+4PViaIgVPsiytC7mXN5p94u5fJc3VNsBw== |
| repository | git+https://github.com/awesome-dsh-plugin/dsh-find-plugin.git |
| declared bundle patch | "./cordis.patch.yml" |
| declared engines.dsh | not declared — declarative and unenforced |
| DSH | 0.2.0-rc.2 |
|---|---|
| Node | v24.21.0 |
| OS / arch | linux 6.17.0-1022-azure x64 |
| verifier | dsh-verified 0.1.0 b07a7e8d0093 |
| generated | 2026-10-03T15:57:40.152Z |
| status | summary | evidence | |
|---|---|---|---|
L0 |
pass | declares dsh.bundle.patch and every declared patch path exists (15 files, 151561 bytes unpacked)
dsh.manifestVersion is not declared; the reader does not infer a default metrics{
"fileCount": 15,
"unpackedBytes": 151561,
"patchPaths": [
"./cordis.patch.yml"
],
"declaredEnginesDsh": null,
"shipsSource": true
} |
e-resolve, e-tarball, e-l0 |
L1 |
fail | peer-incompatible with the pinned runtime
DSH refused the install: the plugin's declared peerDependencies on @deepseek-ai/dsh* do not match the runtime. An exact-version exemption would bypass this check; granting one is a user decision and is not done here. no dependency build script was approved by the verifier; approval permits commands with the host user permissions metrics{
"durationMs": 1639,
"exitCode": 1,
"declaredPeers": {
"@deepseek-ai/dsh-tools": "^0.1.0-rc.6 || ^0.1.1-rc.1 || ^0.1.2-alpha.2 || ^0.1.3-alpha.2 || ^0.1.5-alpha.1 || ^0.1.6-alpha.1 || ^0.1.7-alpha.1"
},
"bundlesAfterInstall": [
"@deepseek-ai/dsh-base"
],
"pendingBuildScripts": [],
"buildScriptsApproved": 0,
"diagnosticsLog": "/work/dsh-home/profiles/verify/.plugin-manager/logs/operation-jqcPJ1/pnpm.log"
} |
e-l1-install |
L2 |
skip | not run: the subject did not install
loading a plugin that is not present would measure nothing |
no evidence cited |
L3 |
skip | not run: the subject did not install
a session cannot be attributed to a subject that is not present |
no evidence cited |
L4 |
pass | 2 capability signal(s) present across 9 scanned file(s)
static analysis cannot see dynamically constructed code or prove intent metrics{
"scannedFiles": 9,
"scannedBytes": 53201,
"skippedFiles": 0
} |
e-l4, e-patch |
L5 |
inconclusive | the subject did not install, so there was nothing to activate
no overhead claim is made when the differential could not be completed metrics{
"samples": 0
} |
no evidence cited |
L6 |
skip | not run: the subject did not install
removal was not attempted because nothing was installed |
no evidence cited |
| capability | confidence | attribution | first evidence |
|---|---|---|---|
network_egress | medium | author-source | package/src/github.ts:164 |
writes_outside_workspace | low | author-source | package/src/registry.ts:73 |
Capability is not intent. A signature records what the code can reach for, not what it does.
No overhead measurement was published for this report.
| id | kind | artifact |
|---|---|---|
e-resolve |
command exit 0 83 ms | resolve dsh-find-plugin@0.4.0 -> dsh-find-plugin@0.4.0
{
"name": "dsh-find-plugin",
"version": "0.4.0",
"registry": "https://registry.npmjs.org",
"tarball": "https://registry.npmjs.org/dsh-find-plugin/-/dsh-find-plugin-0.4.0.tgz",
"advertisedIntegrity": "sha512-XO0zQb3iHxK7IGGygfiGDxI3t4HUEBNLK4knqYmh8KuT2cbCWzmH+4PViaIgVPsiytC7mXN5p94u5fJc3VNsBw==",
"publishedAt": "2026-09-25T14:59:44.271Z"
}
|
e-tarball |
artifact exit 0 20 ms | fetch https://registry.npmjs.org/dsh-find-plugin/-/dsh-find-plugin-0.4.0.tgz
{
"bytes": 45308,
"resolvedIntegrity": "sha512-XO0zQb3iHxK7IGGygfiGDxI3t4HUEBNLK4knqYmh8KuT2cbCWzmH+4PViaIgVPsiytC7mXN5p94u5fJc3VNsBw==",
"advertisedIntegrity": "sha512-XO0zQb3iHxK7IGGygfiGDxI3t4HUEBNLK4knqYmh8KuT2cbCWzmH+4PViaIgVPsiytC7mXN5p94u5fJc3VNsBw==",
"integrityMatchesRegistry": true,
"sha256": "39fc2dfd519b53bc71c9d4fb8cb7faa678d2c14ffb77c6df38daf0eedf0b56a0"
}
|
e-l0 |
static | read published package.json and verify declared dsh.bundle.patch paths exist
{
"status": "pass",
"reasons": [],
"declared": {
"manifestVersion": null,
"bundlePatch": [
"./cordis.patch.yml"
],
"clientPlatform": null,
"enginesDsh": null,
"enginesNode": null
},
"missingPatchPaths": [],
"fileCount": 15,
"unpackedBytes": 151561,
"shipsSource": true
}
|
e-patch |
static | read cordis.patch.yml
# dsh bundle patch: inserts this plugin into a profile's layer stack.
- insert:
- id: find-dsh-plugin
name: 'dsh-find-plugin'
|
e-l4 |
static | scan 9 shipped source file(s) for capability signatures
{
"present": [
{
"id": "network_egress",
"confidence": "medium",
"attribution": "author-source",
"firstEvidence": {
"file": "package/src/github.ts",
"line": 164,
"snippet": "res = await fetch(url, { headers, signal: signalFor() })"
}
},
{
"id": "writes_outside_workspace",
"confidence": "low",
"attribution": "author-source",
"firstEvidence": {
"file": "package/src/registry.ts",
"line": 73,
"snippet": "const fromEnv = process.env.DSH_HOME"
}
}
],
"scannedFiles": 9,
"skippedFiles": 0,
"limits": [
"static analysis cannot see dynamically constructed code or prove intent"
]
}
|
e-l1-install |
command exit 1 1639 ms | dsh plugin --profile verify add dsh-find-plugin@0.4.0
dsh: initialized profile verify at /work/dsh-home/profiles/verify
dsh: installation rejected: Plugin dsh-find-plugin@0.4.0 is incompatible with dsh 0.2.0-rc.2: peerDependencies {"@deepseek-ai/dsh-tools":"^0.1.0-rc.6 || ^0.1.1-rc.1 || ^0.1.2-alpha.2 || ^0.1.3-alpha.2 || ^0.1.5-alpha.1 || ^0.1.6-alpha.1 || ^0.1.7-alpha.1"}. Running it may cause crashes or data loss. Update the plugin or install a plugin version compatible with this dsh runtime. To accept this risk explicitly, grant the exact-version exemption for dsh-find-plugin@0.4.0 on dsh 0.2.0-rc.2 with `dsh plugin allow-version` or the plugin manager, then retry the installation or restart dsh. Exact-version exemption: not active.
dsh: nothing was installed.
dsh: to accept the risk, run: dsh plugin --profile verify allow-version dsh-find-plugin@0.4.0 --dsh-version 0.2.0-rc.2 --accept-risk
dsh: plugin command failed; diagnostics: /work/dsh-home/profiles/verify/.plugin-manager/logs/operation-jqcPJ1/pnpm.log
|