← all reports

npm:dsh-plugin-wallpaper-engine@1.2.0

dsh-verified: verified — npm:dsh-plugin-wallpaper-engine@1.2.0. Verification is not a security audit and not an endorsement. It records what was executed and observed on one machine at one time. Historical method limitation: this execution had network access and published container paths and replay fixture text. dsh plugin dsh plugin verified verified

Stale. the latest tag points at 1.3.1, while this report covers 1.2.0

Method limitation. This historical execution used a container with network access and published container paths and replay fixture text. The no-egress and redaction conditions were not met. See the security incident.

sha512-WgY1pLh2zbGyLSPJP1aSKq42hntF8PnrAlSeQWqpZwPoLdMByL/9Abth9ELlhw+t0odXNs4Fbiyljju0MF0tfA==

Subject

namedsh-plugin-wallpaper-engine
version1.2.0
integritysha512-WgY1pLh2zbGyLSPJP1aSKq42hntF8PnrAlSeQWqpZwPoLdMByL/9Abth9ELlhw+t0odXNs4Fbiyljju0MF0tfA==
repositorygit+https://github.com/elysia395/dsh-wallpaper-engine.git
declared bundle patch"./cordis.patch.yml"
declared engines.dsh>=0.2.0-rc.1 — declarative and unenforced

Environment

DSH0.2.0-rc.2
Nodev24.21.0
OS / archlinux 6.17.0-1022-azure x64
verifierdsh-verified 0.1.0 ec8d77c8d74d
generated2026-10-03T16:28:41.376Z

Dimensions

statussummaryevidence
L0 pass declares dsh.bundle.patch and every declared patch path exists (47 files, 3662488 bytes unpacked)

dsh.manifestVersion is not declared; the reader does not infer a default

tarball ships no src/ paths, so capability findings are limited to build output

metrics
{
  "fileCount": 47,
  "unpackedBytes": 3662488,
  "patchPaths": [
    "./cordis.patch.yml"
  ],
  "declaredEnginesDsh": ">=0.2.0-rc.1",
  "shipsSource": false
}
e-resolve, e-tarball, e-l0
L1 pass installed

the CLI completed the install with exit code 0

no dependency build script was approved by the verifier; approval permits commands with the host user permissions

metrics
{
  "durationMs": 2036,
  "exitCode": 0,
  "declaredPeers": null,
  "bundlesAfterInstall": [
    "@deepseek-ai/dsh-base",
    "dsh-plugin-wallpaper-engine"
  ],
  "pendingBuildScripts": [],
  "buildScriptsApproved": 0,
  "diagnosticsLog": null
}
e-l1-install
L2 pass booted, mounted and stayed alive

the process was still running when the wall-clock bound reached it and reported no failure diagnostics, so the bundle was neither skipped nor rejected

the fiber phase is not read directly: an early exit with diagnostics is the load-failure signal, and a boot that settles and waits is the success signal

metrics
{
  "bootBoundMs": 25000,
  "durationMs": 25065,
  "signal": null
}
e-l2-boot
L3 pass a session completed with no credential

the model call was served by the official replay adapter from a fixture authored in this repository; no provider was contacted and no credential was present

probe task, stated verbatim: "reply with any text"

metrics
{
  "replayAdapter": "@deepseek-ai/dsh-llm-replay@0.2.0-rc.2",
  "probeTask": "reply with any text",
  "events": {
    "session": "session-98ade1c0-7be9-40e8-b816-e099bf909a10",
    "turnEndReason": {
      "kind": "completed"
    },
    "finalText": "Replay fixture: no provider was called.",
    "textEventCount": 1,
    "error": null,
    "exitCode": 0,
    "durationMs": 1253,
    "eventCount": 7
  }
}
e-l3-session
L4 pass 4 capability signal(s) present across 31 scanned file(s)

the package ships build output; code inside a bundle cannot be reliably attributed to the author or to an inlined dependency

static analysis cannot see dynamically constructed code or prove intent

metrics
{
  "scannedFiles": 31,
  "scannedBytes": 3348335,
  "skippedFiles": 0
}
e-l4, e-patch
L5 pass no significant delta across 6 sampled run(s)

no metric moved beyond the significance thresholds; that is the finding

differential attribution: baseline profile first, then the subject activated, same container and order

thresholds are coarse on purpose — order-of-magnitude watcher changes, RSS growth beyond 100 MiB, steady state more than 2 s later

metrics
{
  "samples": 6,
  "baseline": {
    "atMs": 8042,
    "rss": 199413760,
    "heapUsed": 68444568,
    "external": 5188103,
    "activeTotal": 10,
    "watchers": 7,
    "timers": 0,
    "libuvHandles": 22,
    "libuvActiveHandles": 17,
    "fds": 20
  },
  "activated": {
    "atMs": 8039,
    "rss": 200183808,
    "heapUsed": 71759872,
    "external": 5271558,
    "activeTotal": 11,
    "watchers": 8,
    "timers": 0,
    "libuvHandles": 23,
    "libuvActiveHandles": 18,
    "fds": 20
  },
  "delta": {
    "atMs": -3,
    "rss": 770048,
    "heapUsed": 3315304,
    "external": 83455,
    "activeTotal": 1,
    "watchers": 1,
    "timers": 0,
    "libuvHandles": 1,
    "libuvActiveHandles": 1,
    "fds": 0
  }
}
e-l5-overhead
L6 pass removed without residue

the profile retains no bundle selection, dependency entry or files for the subject

metrics
{
  "residue": [],
  "durationMs": 263
}
e-l6-remove

Capability (L4, static)

capabilityconfidenceattributionfirst evidence
eval_or_dynamic_codelowbuild-outputpackage/lib/webwallgl/assets/renderer-DTLW1Gf0.js:261
listens_on_portmediumunknownpackage/lib/index.js:3417
network_egressmediumunknownpackage/lib/routes/github-stars.js:41
spawns_processmediumunknownpackage/lib/index.js:67

Capability is not intent. A signature records what the code can reach for, not what it does.

Overhead (L5, dynamic)

{
  "status": "no-significant-delta",
  "samples": 6,
  "baseline": {
    "atMs": 8042,
    "rss": 199413760,
    "heapUsed": 68444568,
    "external": 5188103,
    "activeTotal": 10,
    "watchers": 7,
    "timers": 0,
    "libuvHandles": 22,
    "libuvActiveHandles": 17,
    "fds": 20
  },
  "activated": {
    "atMs": 8039,
    "rss": 200183808,
    "heapUsed": 71759872,
    "external": 5271558,
    "activeTotal": 11,
    "watchers": 8,
    "timers": 0,
    "libuvHandles": 23,
    "libuvActiveHandles": 18,
    "fds": 20
  },
  "delta": {
    "atMs": -3,
    "rss": 770048,
    "heapUsed": 3315304,
    "external": 83455,
    "activeTotal": 1,
    "watchers": 1,
    "timers": 0,
    "libuvHandles": 1,
    "libuvActiveHandles": 1,
    "fds": 0
  },
  "significant": []
}

Evidence

idkindartifact
e-resolve command exit 0 177 ms resolve dsh-plugin-wallpaper-engine@1.2.0 -> dsh-plugin-wallpaper-engine@1.2.0
{
  "name": "dsh-plugin-wallpaper-engine",
  "version": "1.2.0",
  "registry": "https://registry.npmjs.org",
  "tarball": "https://registry.npmjs.org/dsh-plugin-wallpaper-engine/-/dsh-plugin-wallpaper-engine-1.2.0.tgz",
  "advertisedIntegrity": "sha512-WgY1pLh2zbGyLSPJP1aSKq42hntF8PnrAlSeQWqpZwPoLdMByL/9Abth9ELlhw+t0odXNs4Fbiyljju0MF0tfA==",
  "publishedAt": "2026-10-02T00:29:42.919Z"
}
e-tarball artifact exit 0 66 ms fetch https://registry.npmjs.org/dsh-plugin-wallpaper-engine/-/dsh-plugin-wallpaper-engine-1.2.0.tgz
{
  "bytes": 1585336,
  "resolvedIntegrity": "sha512-WgY1pLh2zbGyLSPJP1aSKq42hntF8PnrAlSeQWqpZwPoLdMByL/9Abth9ELlhw+t0odXNs4Fbiyljju0MF0tfA==",
  "advertisedIntegrity": "sha512-WgY1pLh2zbGyLSPJP1aSKq42hntF8PnrAlSeQWqpZwPoLdMByL/9Abth9ELlhw+t0odXNs4Fbiyljju0MF0tfA==",
  "integrityMatchesRegistry": true,
  "sha256": "5562b2f99702a0b54cd8c683b2a3996d99dcdbf2a0571a2c7e9bd3839ef2c49e"
}
e-l0 static read published package.json and verify declared dsh.bundle.patch paths exist
{
  "status": "pass",
  "reasons": [],
  "declared": {
    "manifestVersion": null,
    "bundlePatch": [
      "./cordis.patch.yml"
    ],
    "clientPlatform": "web",
    "enginesDsh": ">=0.2.0-rc.1",
    "enginesNode": ">=18"
  },
  "missingPatchPaths": [],
  "fileCount": 47,
  "unpackedBytes": 3662488,
  "shipsSource": false
}
e-patch static read cordis.patch.yml
# dsh-plugin-wallpaper-engine bundle patch.
#
# Applied over the dsh-web-app layer. This bundle contributes ONE host row
# (the plugin that scans Wallpaper Engine and serves its media) and relies on
# its `dsh.client` manifest (in package.json) to load the browser half that
# draws the wallpaper behind the DSH GUI and adds the settings UI.
#
# A patch replaces the targeted row's whole `config`, so only additive
# `insert` rows appear here (we never override an existing shipped row).

- insert:
    # Host half: discovers the local Wallpaper Engine install (Steam app 431960),
    # enumerates Scene/Video/Web wallpapers from the Workshop + default projects
    # (Application wallpapers are listed but never rendered),
    # and serves their media + a JSON inventory over same-origin HTTP routes
    # the browser half fetches directly (GET /wallpaper-engine/inventory, /media,
    # /preview, …; docs/ROUTE-INDEX.md is the authoritative table — it is generated
    # and machine-checked, so the route count is deliberately not repeated here).
    - id: wallpaper-engine
      name: 'dsh-plugin-wallpaper-engine'
      # webServer is a hard dependency (`inject = ['webServer']` in lib/index.js):
      # the Loader waits for the HTTP server to mount, so a headless/TUI profile
      # without one does not load this bundle at all.
e-l4 static scan 31 shipped source file(s) for capability signatures
{
  "present": [
    {
      "id": "eval_or_dynamic_code",
      "confidence": "low",
      "attribution": "build-output",
      "firstEvidence": {
        "file": "package/lib/webwallgl/assets/renderer-DTLW1Gf0.js",
        "line": 261,
        "snippet": "`);for(const k of l)u.push(...o(k));let d=!1;if(e.limitrows&&e.maxrows>0&&u.length>e.maxrows&&(u=u.slice(0,e.maxrows),d=!0,e.limituseellipsis)){let k=u[e.maxrows-1];for(;k.length>0&&n(k+\"…\")>c;)k=k.sl…"
      }
    },
    {
      "id": "listens_on_port",
      "confidence": "medium",
      "attribution": "unknown",
      "firstEvidence": {
        "file": "package/lib/index.js",
        "line": 3417,
        "snippet": "server = createServer((req, res) => {"
      }
    },
    {
      "id": "network_egress",
      "confidence": "medium",
      "attribution": "unknown",
      "firstEvidence": {
        "file": "package/lib/routes/github-stars.js",
        "line": 41,
        "snippet": "const res = await fetch(url, {"
      }
    },
    {
      "id": "spawns_process",
      "confidence": "medium",
      "attribution": "unknown",
      "firstEvidence": {
        "file": "package/lib/index.js",
        "line": 67,
        "snippet": "import { execFile, execFileSync, spawn } from 'node:child_process';"
      }
    }
  ],
  "scannedFiles": 31,
  "skippedFiles": 0,
  "limits": [
    "the package ships build output; code inside a bundle cannot be reliably attributed to the author or to an inlined dependency",
    "static analysis cannot see dynamically constructed code or prove intent"
  ]
}
e-l1-install command exit 0 2036 ms dsh plugin --profile verify add dsh-plugin-wallpaper-engine@1.2.0
Progress: resolved 1, reused 0, downloaded 0, added 0
Packages are hard linked from the content-addressable store to the virtual store.
  Content-addressable store is at: /home/verifier/.local/share/pnpm/store/v11
  Virtual store is at:             node_modules/.pnpm
Packages: +1
+
Progress: resolved 1, reused 0, downloaded 1, added 1, done
[WARN] Issues with peer dependencies found. Run "pnpm peers check" to list them.

dependencies:
+ dsh-plugin-wallpaper-engine 1.2.0

Done in 269ms using pnpm v12.8.1
dsh: initialized profile verify at /work/dsh-home/profiles/verify
e-l2-boot command exit 0 25065 ms dsh --profile verify
dsh: warning: 1 entry did not activate
wallpaper-engine (dsh-plugin-wallpaper-engine): pending (waiting for service: webServer)
e-l6-remove command exit 0 263 ms dsh plugin --profile verify remove dsh-plugin-wallpaper-engine
Packages: -1
-

dependencies:
- dsh-plugin-wallpaper-engine 1.2.0

Done in 10ms using pnpm v12.8.1
e-l5-overhead sample dsh --profile <baseline|activated> with the host sampler injected via NODE_OPTIONS=--import
{
  "method": "differential",
  "status": "no-significant-delta",
  "samples": 6,
  "baselineMedian": {
    "atMs": 8042,
    "rss": 199413760,
    "heapUsed": 68444568,
    "external": 5188103,
    "activeTotal": 10,
    "watchers": 7,
    "timers": 0,
    "libuvHandles": 22,
    "libuvActiveHandles": 17,
    "fds": 20
  },
  "activatedMedian": {
    "atMs": 8039,
    "rss": 200183808,
    "heapUsed": 71759872,
    "external": 5271558,
    "activeTotal": 11,
    "watchers": 8,
    "timers": 0,
    "libuvHandles": 23,
    "libuvActiveHandles": 18,
    "fds": 20
  },
  "delta": {
    "atMs": -3,
    "rss": 770048,
    "heapUsed": 3315304,
    "external": 83455,
    "activeTotal": 1,
    "watchers": 1,
    "timers": 0,
    "libuvHandles": 1,
    "libuvActiveHandles": 1,
    "fds": 0
  },
  "significant": []
}
e-l3-session command exit 0 1253 ms dsh --profile l3 --patch /work/fixtures/replay/l3-overlay.yml --json reply with any text
{"type":"session","sessionId":"session-98ade1c0-7be9-40e8-b816-e099bf909a10","cwd":"/work"}
{"type":"status","phase":"turn_start","turn":1}
{"type":"status","phase":"step_start","turn":1,"step":1}
{"type":"text","text":"Replay fixture: no provider was called."}
{"type":"status","phase":"step_end","turn":1,"step":1}
{"type":"status","phase":"turn_end","turn":1,"reason":{"kind":"completed"}}
{"type":"final","text":"Replay fixture: no provider was called."}
dsh: warning: 1 entry did not activate
wallpaper-engine (dsh-plugin-wallpaper-engine): pending (waiting for service: webServer)

Limits

Disclaimers

raw report JSON · badge · dispute this report