← all reports

npm:dsh-free-search@0.7.2

dsh-verified: verified — npm:dsh-free-search@0.7.2. Verification is not a security audit and not an endorsement. It records what was executed and observed on one machine at one time. Historical method limitation: this execution had network access and published container paths and replay fixture text. dsh plugin dsh plugin verified verified

Stale. the latest tag points at 0.8.1, while this report covers 0.7.2

Method limitation. This historical execution used a container with network access and published container paths and replay fixture text. The no-egress and redaction conditions were not met. See the security incident.

sha512-keV1VsfTIT10vSU4IfNFhGsDAbEwsoh4EZSriYR4DKb1x/CJsqtMlHOkCIuucDIysIPytCepgyj+FtRQaAkhUQ==

Subject

namedsh-free-search
version0.7.2
integritysha512-keV1VsfTIT10vSU4IfNFhGsDAbEwsoh4EZSriYR4DKb1x/CJsqtMlHOkCIuucDIysIPytCepgyj+FtRQaAkhUQ==
repositorygit+https://github.com/DDDMUC/dsh-free-search.git
declared bundle patch"cordis.patch.yml"
declared engines.dshnot declared — declarative and unenforced

Environment

DSH0.2.0-rc.2
Nodev24.21.0
OS / archlinux 6.17.0-1022-azure x64
verifierdsh-verified 0.1.0 ec8d77c8d74d
generated2026-10-03T16:25:32.784Z

Dimensions

statussummaryevidence
L0 pass declares dsh.bundle.patch and every declared patch path exists (6 files, 333748 bytes unpacked)

dsh.manifestVersion is not declared; the reader does not infer a default

tarball ships no src/ paths, so capability findings are limited to build output

metrics
{
  "fileCount": 6,
  "unpackedBytes": 333748,
  "patchPaths": [
    "cordis.patch.yml"
  ],
  "declaredEnginesDsh": null,
  "shipsSource": false
}
e-resolve, e-tarball, e-l0
L1 pass installed

the CLI completed the install with exit code 0

no dependency build script was approved by the verifier; approval permits commands with the host user permissions

metrics
{
  "durationMs": 2158,
  "exitCode": 0,
  "declaredPeers": null,
  "bundlesAfterInstall": [
    "@deepseek-ai/dsh-base",
    "dsh-free-search"
  ],
  "pendingBuildScripts": [],
  "buildScriptsApproved": 0,
  "diagnosticsLog": null
}
e-l1-install
L2 pass booted, mounted and stayed alive

the process was still running when the wall-clock bound reached it and reported no failure diagnostics, so the bundle was neither skipped nor rejected

the fiber phase is not read directly: an early exit with diagnostics is the load-failure signal, and a boot that settles and waits is the success signal

metrics
{
  "bootBoundMs": 25000,
  "durationMs": 25064,
  "signal": null
}
e-l2-boot
L3 pass a session completed with no credential

the model call was served by the official replay adapter from a fixture authored in this repository; no provider was contacted and no credential was present

probe task, stated verbatim: "reply with any text"

metrics
{
  "replayAdapter": "@deepseek-ai/dsh-llm-replay@0.2.0-rc.2",
  "probeTask": "reply with any text",
  "events": {
    "session": "session-f6a698ca-002a-4705-a518-6709b8757398",
    "turnEndReason": {
      "kind": "completed"
    },
    "finalText": "Replay fixture: no provider was called.",
    "textEventCount": 1,
    "error": null,
    "exitCode": 0,
    "durationMs": 1293,
    "eventCount": 7
  }
}
e-l3-session
L4 pass 4 capability signal(s) present across 2 scanned file(s)

static analysis cannot see dynamically constructed code or prove intent

metrics
{
  "scannedFiles": 2,
  "scannedBytes": 267449,
  "skippedFiles": 0
}
e-l4, e-patch
L5 pass no significant delta across 6 sampled run(s)

no metric moved beyond the significance thresholds; that is the finding

differential attribution: baseline profile first, then the subject activated, same container and order

thresholds are coarse on purpose — order-of-magnitude watcher changes, RSS growth beyond 100 MiB, steady state more than 2 s later

metrics
{
  "samples": 6,
  "baseline": {
    "atMs": 8040,
    "rss": 199585792,
    "heapUsed": 68402016,
    "external": 5188103,
    "activeTotal": 10,
    "watchers": 7,
    "timers": 0,
    "libuvHandles": 22,
    "libuvActiveHandles": 17,
    "fds": 20
  },
  "activated": {
    "atMs": 8040,
    "rss": 204492800,
    "heapUsed": 45759752,
    "external": 4428430,
    "activeTotal": 11,
    "watchers": 8,
    "timers": 0,
    "libuvHandles": 23,
    "libuvActiveHandles": 18,
    "fds": 20
  },
  "delta": {
    "atMs": 0,
    "rss": 4907008,
    "heapUsed": -22642264,
    "external": -759673,
    "activeTotal": 1,
    "watchers": 1,
    "timers": 0,
    "libuvHandles": 1,
    "libuvActiveHandles": 1,
    "fds": 0
  }
}
e-l5-overhead
L6 pass removed without residue

the profile retains no bundle selection, dependency entry or files for the subject

metrics
{
  "residue": [],
  "durationMs": 268
}
e-l6-remove

Capability (L4, static)

capabilityconfidenceattributionfirst evidence
hooks_system_promptmediumunknownpackage/lib/index.js:3827
network_egressmediumunknownpackage/lib/client.js:361
spawns_processmediumunknownpackage/lib/index.js:7
writes_outside_workspacelowunknownpackage/lib/index.js:2666

Capability is not intent. A signature records what the code can reach for, not what it does.

Overhead (L5, dynamic)

{
  "status": "no-significant-delta",
  "samples": 6,
  "baseline": {
    "atMs": 8040,
    "rss": 199585792,
    "heapUsed": 68402016,
    "external": 5188103,
    "activeTotal": 10,
    "watchers": 7,
    "timers": 0,
    "libuvHandles": 22,
    "libuvActiveHandles": 17,
    "fds": 20
  },
  "activated": {
    "atMs": 8040,
    "rss": 204492800,
    "heapUsed": 45759752,
    "external": 4428430,
    "activeTotal": 11,
    "watchers": 8,
    "timers": 0,
    "libuvHandles": 23,
    "libuvActiveHandles": 18,
    "fds": 20
  },
  "delta": {
    "atMs": 0,
    "rss": 4907008,
    "heapUsed": -22642264,
    "external": -759673,
    "activeTotal": 1,
    "watchers": 1,
    "timers": 0,
    "libuvHandles": 1,
    "libuvActiveHandles": 1,
    "fds": 0
  },
  "significant": []
}

Evidence

idkindartifact
e-resolve command exit 0 188 ms resolve dsh-free-search@0.7.2 -> dsh-free-search@0.7.2
{
  "name": "dsh-free-search",
  "version": "0.7.2",
  "registry": "https://registry.npmjs.org",
  "tarball": "https://registry.npmjs.org/dsh-free-search/-/dsh-free-search-0.7.2.tgz",
  "advertisedIntegrity": "sha512-keV1VsfTIT10vSU4IfNFhGsDAbEwsoh4EZSriYR4DKb1x/CJsqtMlHOkCIuucDIysIPytCepgyj+FtRQaAkhUQ==",
  "publishedAt": "2026-10-03T14:25:41.842Z"
}
e-tarball artifact exit 0 34 ms fetch https://registry.npmjs.org/dsh-free-search/-/dsh-free-search-0.7.2.tgz
{
  "bytes": 85391,
  "resolvedIntegrity": "sha512-keV1VsfTIT10vSU4IfNFhGsDAbEwsoh4EZSriYR4DKb1x/CJsqtMlHOkCIuucDIysIPytCepgyj+FtRQaAkhUQ==",
  "advertisedIntegrity": "sha512-keV1VsfTIT10vSU4IfNFhGsDAbEwsoh4EZSriYR4DKb1x/CJsqtMlHOkCIuucDIysIPytCepgyj+FtRQaAkhUQ==",
  "integrityMatchesRegistry": true,
  "sha256": "a9bc34917d1158fa354479017493df65035df35dd7756cfd6b4a51c80b27a603"
}
e-l0 static read published package.json and verify declared dsh.bundle.patch paths exist
{
  "status": "pass",
  "reasons": [],
  "declared": {
    "manifestVersion": null,
    "bundlePatch": [
      "cordis.patch.yml"
    ],
    "clientPlatform": "web",
    "enginesDsh": null,
    "enginesNode": ">=20"
  },
  "missingPatchPaths": [],
  "fileCount": 6,
  "unpackedBytes": 333748,
  "shipsSource": false
}
e-patch static read cordis.patch.yml
# dsh-free-search — free web search providers (no API key needed)
# Registers the plugin into ctx.web + a settings bridge served at
# /api/dsh-free-search-settings.
# The engine is chosen from the sidebar Plugins page -> Free Search row config
# (plugins.row.config, DSH 0.1.7-rc.1+), from the /free-search-engine command,
# or directly via this entry's config, e.g.:
#   provider: bing        # engine id: ddg / bing / baidu / kimi / aliyun / doubao / openai / gemini / claude / auto / multi / ...
#   (openai/gemini/claude are model-based and bill per search; they run only when selected explicitly)
#   region: cn-zh         # DuckDuckGo region
#   bingMarket: zh-CN     # Bing market
# A legacy ~/.dsh/settings.yaml "free-search:" section is migrated into this
# entry's config once at startup (see README).
# Failed/empty engines automatically fall back to the next free engine.
#
# NOTE (2026-10, issue #51): this bundle does NOT touch `web.searchProvider`.
# The plugin takes the search provider over at runtime instead — when the field
# is unset or still the shipped default (`deepseek-official`) it points it at its
# own provider id (`ddg`); when another provider was chosen explicitly it leaves
# it alone and only warns.
#
# A static `- id: web  config: searchProvider: ddg` used to live here. It was
# removed because it created a dangling reference: a patch replaces the whole
# row config, so rows that came from a *disabled* or skipped plugin left
# `searchProvider: ddg` behind while nothing registered `ddg` — every web search
# then failed with `configured web provider "ddg" is not registered`. Leaving the
# base default (`deepseek-official`) in place means a disabled plugin degrades to
# the official provider instead of breaking search outright.
- insert:
    - id: web-search-free
      name: dsh-free-search
      config:
        provider: bing
        disabledEngines: []
        bingMarket: zh-CN
e-l4 static scan 2 shipped source file(s) for capability signatures
{
  "present": [
    {
      "id": "hooks_system_prompt",
      "confidence": "medium",
      "attribution": "unknown",
      "firstEvidence": {
        "file": "package/lib/index.js",
        "line": 3827,
        "snippet": "ctx.inject([\"systemPrompt\"], (sctx) => {"
      }
    },
    {
      "id": "network_egress",
      "confidence": "medium",
      "attribution": "unknown",
      "firstEvidence": {
        "file": "package/lib/client.js",
        "line": 361,
        "snippet": "const response = await fetch(`${BRIDGE_PREFIX}/describe`, {"
      }
    },
    {
      "id": "spawns_process",
      "confidence": "medium",
      "attribution": "unknown",
      "firstEvidence": {
        "file": "package/lib/index.js",
        "line": 7,
        "snippet": "import { exec } from \"node:child_process\";"
      }
    },
    {
      "id": "writes_outside_workspace",
      "confidence": "low",
      "attribution": "unknown",
      "firstEvidence": {
        "file": "package/lib/index.js",
        "line": 2666,
        "snippet": "return process.env.DSH_HOME ?? path.join(os.homedir(), \".dsh\");"
      }
    }
  ],
  "scannedFiles": 2,
  "skippedFiles": 0,
  "limits": [
    "static analysis cannot see dynamically constructed code or prove intent"
  ]
}
e-l1-install command exit 0 2158 ms dsh plugin --profile verify add dsh-free-search@0.7.2
Progress: resolved 0, reused 0, downloaded 1, added 0
Added 1 entry to minimumReleaseAgeExclude in pnpm-workspace.yaml (set minimumReleaseAgeStrict to true to gate these updates with a prompt):
  dsh-free-search@0.7.2
Packages are hard linked from the content-addressable store to the virtual store.
  Content-addressable store is at: /home/verifier/.local/share/pnpm/store/v11
  Virtual store is at:             node_modules/.pnpm
Packages: +4
++++
Progress: resolved 4, reused 0, downloaded 4, added 4, done

dependencies:
+ dsh-free-search 0.7.2

Done in 383ms using pnpm v12.8.1
dsh: initialized profile verify at /work/dsh-home/profiles/verify
e-l2-boot command exit 0 25064 ms dsh --profile verify
e-l6-remove command exit 0 268 ms dsh plugin --profile verify remove dsh-free-search
Packages: -4
----

dependencies:
- dsh-free-search 0.7.2

Done in 12ms using pnpm v12.8.1
e-l5-overhead sample dsh --profile <baseline|activated> with the host sampler injected via NODE_OPTIONS=--import
{
  "method": "differential",
  "status": "no-significant-delta",
  "samples": 6,
  "baselineMedian": {
    "atMs": 8040,
    "rss": 199585792,
    "heapUsed": 68402016,
    "external": 5188103,
    "activeTotal": 10,
    "watchers": 7,
    "timers": 0,
    "libuvHandles": 22,
    "libuvActiveHandles": 17,
    "fds": 20
  },
  "activatedMedian": {
    "atMs": 8040,
    "rss": 204492800,
    "heapUsed": 45759752,
    "external": 4428430,
    "activeTotal": 11,
    "watchers": 8,
    "timers": 0,
    "libuvHandles": 23,
    "libuvActiveHandles": 18,
    "fds": 20
  },
  "delta": {
    "atMs": 0,
    "rss": 4907008,
    "heapUsed": -22642264,
    "external": -759673,
    "activeTotal": 1,
    "watchers": 1,
    "timers": 0,
    "libuvHandles": 1,
    "libuvActiveHandles": 1,
    "fds": 0
  },
  "significant": []
}
e-l3-session command exit 0 1293 ms dsh --profile l3 --patch /work/fixtures/replay/l3-overlay.yml --json reply with any text
{"type":"session","sessionId":"session-f6a698ca-002a-4705-a518-6709b8757398","cwd":"/work"}
{"type":"status","phase":"turn_start","turn":1}
{"type":"status","phase":"step_start","turn":1,"step":1}
{"type":"text","text":"Replay fixture: no provider was called."}
{"type":"status","phase":"step_end","turn":1,"step":1}
{"type":"status","phase":"turn_end","turn":1,"reason":{"kind":"completed"}}
{"type":"final","text":"Replay fixture: no provider was called."}

Limits

Disclaimers

raw report JSON · badge · dispute this report