Method limitation. This historical execution used a container with network access and published container paths and replay fixture text. The no-egress and redaction conditions were not met. See the security incident.
sha512-7s9yTorn9FquZTDoOfC1U0QuXvdANEbBOX9yuIlITFksAFkycjDDsPq7xBpWP6O1tILtezYMZnUyEX37vvVJ+w==
| name | dsh-tiddlywiki |
|---|---|
| version | 0.30.57 |
| integrity | sha512-7s9yTorn9FquZTDoOfC1U0QuXvdANEbBOX9yuIlITFksAFkycjDDsPq7xBpWP6O1tILtezYMZnUyEX37vvVJ+w== |
| repository | git+https://github.com/bbqisbbq/dsh-tiddlywiki.git |
| declared bundle patch | "./cordis.patch.yml" |
| declared engines.dsh | not declared — declarative and unenforced |
| DSH | 0.2.0-rc.2 |
|---|---|
| Node | v24.21.0 |
| OS / arch | linux 6.17.0-1022-azure x64 |
| verifier | dsh-verified 0.1.0 ec8d77c8d74d |
| generated | 2026-10-03T16:31:50.044Z |
| status | summary | evidence | |
|---|---|---|---|
L0 |
pass | declares dsh.bundle.patch and every declared patch path exists (171 files, 5315378 bytes unpacked)
dsh.manifestVersion is not declared; the reader does not infer a default metrics{
"fileCount": 171,
"unpackedBytes": 5315378,
"patchPaths": [
"./cordis.patch.yml"
],
"declaredEnginesDsh": null,
"shipsSource": true
} |
e-resolve, e-tarball, e-l0 |
L1 |
pass | installed
the CLI completed the install with exit code 0 no dependency build script was approved by the verifier; approval permits commands with the host user permissions metrics{
"durationMs": 2701,
"exitCode": 0,
"declaredPeers": null,
"bundlesAfterInstall": [
"@deepseek-ai/dsh-base",
"dsh-tiddlywiki"
],
"pendingBuildScripts": [],
"buildScriptsApproved": 0,
"diagnosticsLog": null
} |
e-l1-install |
L2 |
pass | booted, mounted and stayed alive
the process was still running when the wall-clock bound reached it and reported no failure diagnostics, so the bundle was neither skipped nor rejected the fiber phase is not read directly: an early exit with diagnostics is the load-failure signal, and a boot that settles and waits is the success signal metrics{
"bootBoundMs": 25000,
"durationMs": 26788,
"signal": null
} |
e-l2-boot |
L3 |
pass | a session completed with no credential
the model call was served by the official replay adapter from a fixture authored in this repository; no provider was contacted and no credential was present probe task, stated verbatim: "reply with any text" metrics{
"replayAdapter": "@deepseek-ai/dsh-llm-replay@0.2.0-rc.2",
"probeTask": "reply with any text",
"events": {
"session": "session-bf6f6d63-79e5-4705-9922-212ee745e76c",
"turnEndReason": {
"kind": "completed"
},
"finalText": "Replay fixture: no provider was called.",
"textEventCount": 1,
"error": null,
"exitCode": 0,
"durationMs": 3531,
"eventCount": 7
}
} |
e-l3-session |
L4 |
pass | 6 capability signal(s) present across 155 scanned file(s)
the package ships build output; code inside a bundle cannot be reliably attributed to the author or to an inlined dependency static analysis cannot see dynamically constructed code or prove intent metrics{
"scannedFiles": 155,
"scannedBytes": 3418122,
"skippedFiles": 0
} |
e-l4, e-patch |
L5 |
pass | no significant delta across 6 sampled run(s)
no metric moved beyond the significance thresholds; that is the finding differential attribution: baseline profile first, then the subject activated, same container and order thresholds are coarse on purpose — order-of-magnitude watcher changes, RSS growth beyond 100 MiB, steady state more than 2 s later metrics{
"samples": 6,
"baseline": {
"atMs": 8040,
"rss": 199069696,
"heapUsed": 68374688,
"external": 5188103,
"activeTotal": 10,
"watchers": 7,
"timers": 0,
"libuvHandles": 22,
"libuvActiveHandles": 17,
"fds": 20
},
"activated": {
"atMs": 8032,
"rss": 205598720,
"heapUsed": 49221336,
"external": 4381803,
"activeTotal": 13,
"watchers": 8,
"timers": 1,
"libuvHandles": 25,
"libuvActiveHandles": 21,
"fds": 21
},
"delta": {
"atMs": -8,
"rss": 6529024,
"heapUsed": -19153352,
"external": -806300,
"activeTotal": 3,
"watchers": 1,
"timers": 1,
"libuvHandles": 3,
"libuvActiveHandles": 4,
"fds": 1
}
} |
e-l5-overhead |
L6 |
pass | removed without residue
the profile retains no bundle selection, dependency entry or files for the subject metrics{
"residue": [],
"durationMs": 447
} |
e-l6-remove |
| capability | confidence | attribution | first evidence |
|---|---|---|---|
hooks_system_prompt | medium | author-source | package/src/index.ts:71 |
listens_on_port | high | author-source | package/src/host/clip-bridge.ts:198 |
network_egress | medium | author-source | package/src/host/git.ts:380 |
spawns_process | high | author-source | package/src/host/git.ts:29 |
watches_filesystem | high | author-source | package/src/host/wiki-instance.ts:181 |
writes_outside_workspace | low | author-source | package/src/sdk.ts:23 |
Capability is not intent. A signature records what the code can reach for, not what it does.
{
"status": "no-significant-delta",
"samples": 6,
"baseline": {
"atMs": 8040,
"rss": 199069696,
"heapUsed": 68374688,
"external": 5188103,
"activeTotal": 10,
"watchers": 7,
"timers": 0,
"libuvHandles": 22,
"libuvActiveHandles": 17,
"fds": 20
},
"activated": {
"atMs": 8032,
"rss": 205598720,
"heapUsed": 49221336,
"external": 4381803,
"activeTotal": 13,
"watchers": 8,
"timers": 1,
"libuvHandles": 25,
"libuvActiveHandles": 21,
"fds": 21
},
"delta": {
"atMs": -8,
"rss": 6529024,
"heapUsed": -19153352,
"external": -806300,
"activeTotal": 3,
"watchers": 1,
"timers": 1,
"libuvHandles": 3,
"libuvActiveHandles": 4,
"fds": 1
},
"significant": []
}
| id | kind | artifact |
|---|---|---|
e-resolve |
command exit 0 258 ms | resolve dsh-tiddlywiki@0.30.57 -> dsh-tiddlywiki@0.30.57
{
"name": "dsh-tiddlywiki",
"version": "0.30.57",
"registry": "https://registry.npmjs.org",
"tarball": "https://registry.npmjs.org/dsh-tiddlywiki/-/dsh-tiddlywiki-0.30.57.tgz",
"advertisedIntegrity": "sha512-7s9yTorn9FquZTDoOfC1U0QuXvdANEbBOX9yuIlITFksAFkycjDDsPq7xBpWP6O1tILtezYMZnUyEX37vvVJ+w==",
"publishedAt": "2026-09-29T18:35:02.118Z"
}
|
e-tarball |
artifact exit 0 71 ms | fetch https://registry.npmjs.org/dsh-tiddlywiki/-/dsh-tiddlywiki-0.30.57.tgz
{
"bytes": 1742951,
"resolvedIntegrity": "sha512-7s9yTorn9FquZTDoOfC1U0QuXvdANEbBOX9yuIlITFksAFkycjDDsPq7xBpWP6O1tILtezYMZnUyEX37vvVJ+w==",
"advertisedIntegrity": "sha512-7s9yTorn9FquZTDoOfC1U0QuXvdANEbBOX9yuIlITFksAFkycjDDsPq7xBpWP6O1tILtezYMZnUyEX37vvVJ+w==",
"integrityMatchesRegistry": true,
"sha256": "6851ac700da92dd803d7db65274b54ed1ec52192b1a70207ee8daf5c958d3595"
}
|
e-l0 |
static | read published package.json and verify declared dsh.bundle.patch paths exist
{
"status": "pass",
"reasons": [],
"declared": {
"manifestVersion": null,
"bundlePatch": [
"./cordis.patch.yml"
],
"clientPlatform": "web",
"enginesDsh": null,
"enginesNode": ">=22"
},
"missingPatchPaths": [],
"fileCount": 171,
"unpackedBytes": 5315378,
"shipsSource": true
}
|
e-patch |
static | read cordis.patch.yml
# dsh-tiddlywiki bundle patch: inserts the plugin row into the web profile
# roster. Applied as a profile bundle layer (the `dsh.bundle.patch` manifest
# field) over dsh-base; activate with
# `dsh plugin --profile web add link:<path-to-this-package>` and restart dsh web.
#
# The row is a bare plugin by package name: the node half (exports ".") runs
# in the host process (WikiServer, routes, tiddlywiki_* tools, prompt section,
# auto-commit), and the `dsh.client` declaration in package.json makes the
# browser half (exports "./client", served at /plugins/dsh-tiddlywiki/client.js)
# load in the web GUI.
- insert:
- id: dsh-tiddlywiki
name: dsh-tiddlywiki
|
e-l4 |
static | scan 155 shipped source file(s) for capability signatures
{
"present": [
{
"id": "hooks_system_prompt",
"confidence": "medium",
"attribution": "author-source",
"firstEvidence": {
"file": "package/src/index.ts",
"line": 71,
"snippet": "export const inject = ['tools', 'systemPrompt']"
}
},
{
"id": "listens_on_port",
"confidence": "high",
"attribution": "author-source",
"firstEvidence": {
"file": "package/src/host/clip-bridge.ts",
"line": 198,
"snippet": "const server = createServer((req, res) => {"
}
},
{
"id": "network_egress",
"confidence": "medium",
"attribution": "author-source",
"firstEvidence": {
"file": "package/src/host/git.ts",
"line": 380,
"snippet": "async fetch(dir: string): Promise<GitActionResult> {"
}
},
{
"id": "spawns_process",
"confidence": "high",
"attribution": "author-source",
"firstEvidence": {
"file": "package/src/host/git.ts",
"line": 29,
"snippet": "import { execFile } from 'node:child_process'"
}
},
{
"id": "watches_filesystem",
"confidence": "high",
"attribution": "author-source",
"firstEvidence": {
"file": "package/src/host/wiki-instance.ts",
"line": 181,
"snippet": "const watcher = watch(dir, { persistent: false }, () => onChange())"
}
},
{
"id": "writes_outside_workspace",
"confidence": "low",
"attribution": "author-source",
"firstEvidence": {
"file": "package/src/sdk.ts",
"line": 23,
"snippet": "const override = process.env.DSH_HOME"
}
}
],
"scannedFiles": 155,
"skippedFiles": 0,
"limits": [
"the package ships build output; code inside a bundle cannot be reliably attributed to the author or to an inlined dependency",
"static analysis cannot see dynamically constructed code or prove intent"
]
}
|
e-l1-install |
command exit 0 2701 ms | dsh plugin --profile verify add dsh-tiddlywiki@0.30.57
Progress: resolved 0, reused 0, downloaded 1, added 0 Downloading tiddlywiki@5.4.1: 0.00 B/16.55 MB Packages are hard linked from the content-addressable store to the virtual store. Content-addressable store is at: /home/verifier/.local/share/pnpm/store/v11 Virtual store is at: node_modules/.pnpm Packages: +2 ++ Progress: resolved 2, reused 0, downloaded 2, added 2, done dependencies: + dsh-tiddlywiki 0.30.57 Done in 931ms using pnpm v12.8.1 dsh: initialized profile verify at /work/dsh-home/profiles/verify |
e-l2-boot |
command exit 0 26788 ms | dsh --profile verify
[dsh-tiddlywiki] 拆库 skill:kept(/work/dsh-home/skills/dsh-tiddlywiki-wiki-split/SKILL.md) [dsh-tiddlywiki] single 模式 · 1 个知识库(来源:default) [dsh-tiddlywiki] 已启动:main [dsh-tiddlywiki] clip bridge listening on 127.0.0.1:8618 (enabled=false) [dsh-tiddlywiki] enabled tiddlywiki/markdown for this wiki |
e-l6-remove |
command exit 0 447 ms | dsh plugin --profile verify remove dsh-tiddlywiki
Packages: -2 -- dependencies: - dsh-tiddlywiki 0.30.57 Done in 184ms using pnpm v12.8.1 |
e-l5-overhead |
sample | dsh --profile <baseline|activated> with the host sampler injected via NODE_OPTIONS=--import
{
"method": "differential",
"status": "no-significant-delta",
"samples": 6,
"baselineMedian": {
"atMs": 8040,
"rss": 199069696,
"heapUsed": 68374688,
"external": 5188103,
"activeTotal": 10,
"watchers": 7,
"timers": 0,
"libuvHandles": 22,
"libuvActiveHandles": 17,
"fds": 20
},
"activatedMedian": {
"atMs": 8032,
"rss": 205598720,
"heapUsed": 49221336,
"external": 4381803,
"activeTotal": 13,
"watchers": 8,
"timers": 1,
"libuvHandles": 25,
"libuvActiveHandles": 21,
"fds": 21
},
"delta": {
"atMs": -8,
"rss": 6529024,
"heapUsed": -19153352,
"external": -806300,
"activeTotal": 3,
"watchers": 1,
"timers": 1,
"libuvHandles": 3,
"libuvActiveHandles": 4,
"fds": 1
},
"significant": []
}
|
e-l3-session |
command exit 0 3531 ms | dsh --profile l3 --patch /work/fixtures/replay/l3-overlay.yml --json reply with any text
[dsh-tiddlywiki] 拆库 skill:kept(/work/dsh-home/skills/dsh-tiddlywiki-wiki-split/SKILL.md)
[dsh-tiddlywiki] single 模式 · 1 个知识库(来源:default)
{"type":"session","sessionId":"session-bf6f6d63-79e5-4705-9922-212ee745e76c","cwd":"/work"}
{"type":"status","phase":"turn_start","turn":1}
{"type":"status","phase":"step_start","turn":1,"step":1}
{"type":"text","text":"Replay fixture: no provider was called."}
{"type":"status","phase":"step_end","turn":1,"step":1}
{"type":"status","phase":"turn_end","turn":1,"reason":{"kind":"completed"}}
{"type":"final","text":"Replay fixture: no provider was called."}
[dsh-tiddlywiki] 已启动:main
|