← all reports

npm:dsh-mnemon@0.5.23

dsh-verified: verified — npm:dsh-mnemon@0.5.23. Verification is not a security audit and not an endorsement. It records what was executed and observed on one machine at one time. Historical method limitation: this execution had network access and published container paths and replay fixture text. dsh plugin dsh plugin verified verified

Stale. the latest tag points at 0.5.24, while this report covers 0.5.23

Method limitation. This historical execution used a container with network access and published container paths and replay fixture text. The no-egress and redaction conditions were not met. See the security incident.

sha512-Ey0rlzroEj1OpKmjU5NWaCrNLL0ujI4/8m5AjT+mZRA2fQERuL84gr1xDJ0RE8fK1WhzqRiwrV4pVTCXAGvirA==

Subject

namedsh-mnemon
version0.5.23
integritysha512-Ey0rlzroEj1OpKmjU5NWaCrNLL0ujI4/8m5AjT+mZRA2fQERuL84gr1xDJ0RE8fK1WhzqRiwrV4pVTCXAGvirA==
repositorygit+https://github.com/omdsh-dev/dsh-mnemon.git
declared bundle patch"./cordis.patch.yml"
declared engines.dshnot declared — declarative and unenforced

Environment

DSH0.2.0-rc.2
Nodev24.21.0
OS / archlinux 6.17.0-1022-azure x64
verifierdsh-verified 0.1.0 ec8d77c8d74d
generated2026-10-03T16:23:19.346Z

Dimensions

statussummaryevidence
L0 pass declares dsh.bundle.patch and every declared patch path exists (59 files, 1519875 bytes unpacked)

dsh.manifestVersion is not declared; the reader does not infer a default

metrics
{
  "fileCount": 59,
  "unpackedBytes": 1519875,
  "patchPaths": [
    "./cordis.patch.yml"
  ],
  "declaredEnginesDsh": null,
  "shipsSource": true
}
e-resolve, e-tarball, e-l0
L1 pass installed

the CLI completed the install with exit code 0

no dependency build script was approved by the verifier; approval permits commands with the host user permissions

metrics
{
  "durationMs": 2421,
  "exitCode": 0,
  "declaredPeers": null,
  "bundlesAfterInstall": [
    "@deepseek-ai/dsh-base",
    "dsh-mnemon"
  ],
  "pendingBuildScripts": [],
  "buildScriptsApproved": 0,
  "diagnosticsLog": null
}
e-l1-install
L2 pass booted, mounted and stayed alive

the process was still running when the wall-clock bound reached it and reported no failure diagnostics, so the bundle was neither skipped nor rejected

the fiber phase is not read directly: an early exit with diagnostics is the load-failure signal, and a boot that settles and waits is the success signal

metrics
{
  "bootBoundMs": 25000,
  "durationMs": 25066,
  "signal": null
}
e-l2-boot
L3 pass a session completed with no credential

the model call was served by the official replay adapter from a fixture authored in this repository; no provider was contacted and no credential was present

probe task, stated verbatim: "reply with any text"

metrics
{
  "replayAdapter": "@deepseek-ai/dsh-llm-replay@0.2.0-rc.2",
  "probeTask": "reply with any text",
  "events": {
    "session": "session-213ede21-1424-49ed-a85d-32f95c8e8247",
    "turnEndReason": {
      "kind": "completed"
    },
    "finalText": "Replay fixture: no provider was called.",
    "textEventCount": 1,
    "error": null,
    "exitCode": 0,
    "durationMs": 1480,
    "eventCount": 7
  }
}
e-l3-session
L4 pass 5 capability signal(s) present across 50 scanned file(s)

the package ships build output; code inside a bundle cannot be reliably attributed to the author or to an inlined dependency

static analysis cannot see dynamically constructed code or prove intent

metrics
{
  "scannedFiles": 50,
  "scannedBytes": 1467754,
  "skippedFiles": 0
}
e-l4, e-patch
L5 pass no significant delta across 6 sampled run(s)

no metric moved beyond the significance thresholds; that is the finding

differential attribution: baseline profile first, then the subject activated, same container and order

thresholds are coarse on purpose — order-of-magnitude watcher changes, RSS growth beyond 100 MiB, steady state more than 2 s later

metrics
{
  "samples": 6,
  "baseline": {
    "atMs": 8040,
    "rss": 199122944,
    "heapUsed": 68590120,
    "external": 5188103,
    "activeTotal": 10,
    "watchers": 7,
    "timers": 0,
    "libuvHandles": 22,
    "libuvActiveHandles": 17,
    "fds": 20
  },
  "activated": {
    "atMs": 8039,
    "rss": 219471872,
    "heapUsed": 95159832,
    "external": 4704038,
    "activeTotal": 11,
    "watchers": 8,
    "timers": 0,
    "libuvHandles": 23,
    "libuvActiveHandles": 18,
    "fds": 20
  },
  "delta": {
    "atMs": -1,
    "rss": 20348928,
    "heapUsed": 26569712,
    "external": -484065,
    "activeTotal": 1,
    "watchers": 1,
    "timers": 0,
    "libuvHandles": 1,
    "libuvActiveHandles": 1,
    "fds": 0
  }
}
e-l5-overhead
L6 pass removed without residue

the profile retains no bundle selection, dependency entry or files for the subject

metrics
{
  "residue": [],
  "durationMs": 275
}
e-l6-remove

Capability (L4, static)

capabilityconfidenceattributionfirst evidence
eval_or_dynamic_codemediumunknownpackage/lib/testing.js:223
hooks_system_promptmediumunknownpackage/lib/index.js:2613
network_egressmediumunknownpackage/lib/index.js:6452
spawns_processmediumunknownpackage/lib/index.js:19
writes_outside_workspacelowunknownpackage/lib/index.js:522

Capability is not intent. A signature records what the code can reach for, not what it does.

Overhead (L5, dynamic)

{
  "status": "no-significant-delta",
  "samples": 6,
  "baseline": {
    "atMs": 8040,
    "rss": 199122944,
    "heapUsed": 68590120,
    "external": 5188103,
    "activeTotal": 10,
    "watchers": 7,
    "timers": 0,
    "libuvHandles": 22,
    "libuvActiveHandles": 17,
    "fds": 20
  },
  "activated": {
    "atMs": 8039,
    "rss": 219471872,
    "heapUsed": 95159832,
    "external": 4704038,
    "activeTotal": 11,
    "watchers": 8,
    "timers": 0,
    "libuvHandles": 23,
    "libuvActiveHandles": 18,
    "fds": 20
  },
  "delta": {
    "atMs": -1,
    "rss": 20348928,
    "heapUsed": 26569712,
    "external": -484065,
    "activeTotal": 1,
    "watchers": 1,
    "timers": 0,
    "libuvHandles": 1,
    "libuvActiveHandles": 1,
    "fds": 0
  },
  "significant": []
}

Evidence

idkindartifact
e-resolve command exit 0 193 ms resolve dsh-mnemon@0.5.23 -> dsh-mnemon@0.5.23
{
  "name": "dsh-mnemon",
  "version": "0.5.23",
  "registry": "https://registry.npmjs.org",
  "tarball": "https://registry.npmjs.org/dsh-mnemon/-/dsh-mnemon-0.5.23.tgz",
  "advertisedIntegrity": "sha512-Ey0rlzroEj1OpKmjU5NWaCrNLL0ujI4/8m5AjT+mZRA2fQERuL84gr1xDJ0RE8fK1WhzqRiwrV4pVTCXAGvirA==",
  "publishedAt": "2026-10-03T12:47:58.797Z"
}
e-tarball artifact exit 0 44 ms fetch https://registry.npmjs.org/dsh-mnemon/-/dsh-mnemon-0.5.23.tgz
{
  "bytes": 351825,
  "resolvedIntegrity": "sha512-Ey0rlzroEj1OpKmjU5NWaCrNLL0ujI4/8m5AjT+mZRA2fQERuL84gr1xDJ0RE8fK1WhzqRiwrV4pVTCXAGvirA==",
  "advertisedIntegrity": "sha512-Ey0rlzroEj1OpKmjU5NWaCrNLL0ujI4/8m5AjT+mZRA2fQERuL84gr1xDJ0RE8fK1WhzqRiwrV4pVTCXAGvirA==",
  "integrityMatchesRegistry": true,
  "sha256": "ad23be5b0c5751447710e65f03ef4ad3b6ef25dd2e959ceebe59cb869651c571"
}
e-l0 static read published package.json and verify declared dsh.bundle.patch paths exist
{
  "status": "pass",
  "reasons": [],
  "declared": {
    "manifestVersion": null,
    "bundlePatch": [
      "./cordis.patch.yml"
    ],
    "clientPlatform": "web",
    "enginesDsh": null,
    "enginesNode": ">=20"
  },
  "missingPatchPaths": [],
  "fileCount": 59,
  "unpackedBytes": 1519875,
  "shipsSource": true
}
e-patch static read cordis.patch.yml
# Mount the Mnemon bridge into a DSH profile. A profile's final patch may
# replace this config row as a whole; use user settings or environment
# variables for one-field overrides such as cliPath.
- insert:
    # Keep the v0.4 `mnemon` Entry as the public configuration target while
    # making every v0.5 component inherit its enabled state. The expression
    # reads the core row's own flag (rather than its effective state) to avoid
    # recursing through this ancestor gate. The group itself prepares the
    # Starter's dependency resolution before it imports its children.
    - id: mnemon-bundle
      name: dsh-mnemon/bundle
      group: true
      disabled: !!js >-
        ((entry) => entry.options.disabled?.__jsExpr
          ? Boolean(entry.evaluate(entry.options.disabled.__jsExpr))
          : Boolean(entry.options.disabled))
        ([...loader.entries()].find(entry => entry.options.id === 'mnemon'))
      config:
        - id: mnemon
          # Core/Host and default settings. Sources own their independent Entries.
          name: dsh-mnemon
          config:
            routingGuidance: true
            lifecycleEnabled: true
            recallMode: guided
            writebackMode: guided
            idleReviewMs: 30000
            tabEnabled: true
            writeEnabled: true
            remoteAccess: read-only
            timeoutMs: 10000
            defaultRecallLimit: 10
            embedding:
              enabled: false
              endpoint: http://localhost:11434
              model: nomic-embed-text
            recallQuality:
              policy: strict-v1
              lowScoreThreshold: 0.25
              highScoreThreshold: 0.6
              candidateMultiplier: 3
              maxMediumResults: 4
              maxUnknownResults: 2
        - id: mnemon-source-runtime
          name: dsh-mnemon-source-runtime
        - id: mnemon-source-documents
          name: dsh-mnemon-source-documents
        - id: mnemon-source-memory-spaces
          name: dsh-mnemon-source-memory-spaces
        
e-l4 static scan 50 shipped source file(s) for capability signatures
{
  "present": [
    {
      "id": "eval_or_dynamic_code",
      "confidence": "medium",
      "attribution": "unknown",
      "firstEvidence": {
        "file": "package/lib/testing.js",
        "line": 223,
        "snippet": "new Function(\"window\", readFileSync(path, \"utf8\"))(window);"
      }
    },
    {
      "id": "hooks_system_prompt",
      "confidence": "medium",
      "attribution": "unknown",
      "firstEvidence": {
        "file": "package/lib/index.js",
        "line": 2613,
        "snippet": "ctx.inject([\"systemPrompt\"], (prompted) => {"
      }
    },
    {
      "id": "network_egress",
      "confidence": "medium",
      "attribution": "unknown",
      "firstEvidence": {
        "file": "package/lib/index.js",
        "line": 6452,
        "snippet": "const response = await fetch(url, {"
      }
    },
    {
      "id": "spawns_process",
      "confidence": "medium",
      "attribution": "unknown",
      "firstEvidence": {
        "file": "package/lib/index.js",
        "line": 19,
        "snippet": "import { spawn } from \"node:child_process\";"
      }
    },
    {
      "id": "writes_outside_workspace",
      "confidence": "low",
      "attribution": "unknown",
      "firstEvidence": {
        "file": "package/lib/index.js",
        "line": 522,
        "snippet": "const globalRoot = process.env.MNEMON_DATA_DIR?.trim() || \"~/.mnemon\";"
      }
    }
  ],
  "scannedFiles": 50,
  "skippedFiles": 0,
  "limits": [
    "the package ships build output; code inside a bundle cannot be reliably attributed to the author or to an inlined dependency",
    "static analysis cannot see dynamically constructed code or prove intent"
  ]
}
e-l1-install command exit 0 2421 ms dsh plugin --profile verify add dsh-mnemon@0.5.23
Progress: resolved 0, reused 0, downloaded 1, added 0
Added 5 entries to minimumReleaseAgeExclude in pnpm-workspace.yaml (set minimumReleaseAgeStrict to true to gate these updates with a prompt):
  dsh-mnemon-provider-holographic@0.5.6
  dsh-mnemon-source-documents@0.5.9
  dsh-mnemon-source-memory-spaces@0.5.15
  dsh-mnemon-source-runtime@0.5.12
  dsh-mnemon@0.5.23
Packages are hard linked from the content-addressable store to the virtual store.
  Content-addressable store is at: /home/verifier/.local/share/pnpm/store/v11
  Virtual store is at:             node_modules/.pnpm
Packages: +25
+++++++++++++++++++++++++
Progress: resolved 25, reused 0, downloaded 25, added 25, done
[WARN] Issues with peer dependencies found. Run "pnpm peers check" to list them.

dependencies:
+ dsh-mnemon 0.5.23

Done in 532ms using pnpm v12.8.1
dsh: initialized profile verify at /work/dsh-home/profiles/verify
e-l2-boot command exit 0 25066 ms dsh --profile verify
e-l6-remove command exit 0 275 ms dsh plugin --profile verify remove dsh-mnemon
Packages: -25
-------------------------

dependencies:
- dsh-mnemon 0.5.23

Done in 28ms using pnpm v12.8.1
e-l5-overhead sample dsh --profile <baseline|activated> with the host sampler injected via NODE_OPTIONS=--import
{
  "method": "differential",
  "status": "no-significant-delta",
  "samples": 6,
  "baselineMedian": {
    "atMs": 8040,
    "rss": 199122944,
    "heapUsed": 68590120,
    "external": 5188103,
    "activeTotal": 10,
    "watchers": 7,
    "timers": 0,
    "libuvHandles": 22,
    "libuvActiveHandles": 17,
    "fds": 20
  },
  "activatedMedian": {
    "atMs": 8039,
    "rss": 219471872,
    "heapUsed": 95159832,
    "external": 4704038,
    "activeTotal": 11,
    "watchers": 8,
    "timers": 0,
    "libuvHandles": 23,
    "libuvActiveHandles": 18,
    "fds": 20
  },
  "delta": {
    "atMs": -1,
    "rss": 20348928,
    "heapUsed": 26569712,
    "external": -484065,
    "activeTotal": 1,
    "watchers": 1,
    "timers": 0,
    "libuvHandles": 1,
    "libuvActiveHandles": 1,
    "fds": 0
  },
  "significant": []
}
e-l3-session command exit 0 1480 ms dsh --profile l3 --patch /work/fixtures/replay/l3-overlay.yml --json reply with any text
{"type":"session","sessionId":"session-213ede21-1424-49ed-a85d-32f95c8e8247","cwd":"/work"}
{"type":"status","phase":"turn_start","turn":1}
{"type":"status","phase":"step_start","turn":1,"step":1}
{"type":"text","text":"Replay fixture: no provider was called."}
{"type":"status","phase":"step_end","turn":1,"step":1}
{"type":"status","phase":"turn_end","turn":1,"reason":{"kind":"completed"}}
{"type":"final","text":"Replay fixture: no provider was called."}

Limits

Disclaimers

raw report JSON · badge · dispute this report