{
  "schema": "dsh.plugin.report.v1",
  "reportId": "npm:dsh-whale-widget@0.3.18",
  "generatedAt": "2026-10-03T16:13:47.135Z",
  "verifier": {
    "name": "dsh-verified",
    "version": "0.1.0",
    "commit": "ec8d77c8d74dce7dfc3070ef2ab081e28d154612"
  },
  "subject": {
    "spec": "dsh-whale-widget@0.3.18",
    "name": "dsh-whale-widget",
    "version": "0.3.18",
    "registry": "https://registry.npmjs.org",
    "tarball": "https://registry.npmjs.org/dsh-whale-widget/-/dsh-whale-widget-0.3.18.tgz",
    "integrity": "sha512-2RMevYiKTa2P+FzLutXlpTmQ9coWRbRQ7eG1b07MbkxB1HXXWbN/lqn0MZgDu49AILeJqmGivwB0S0H09pc9xQ==",
    "shasum": "aecd830c05b47b04ff85d887a6fabd4c1e8187bc",
    "repository": "git+https://github.com/MeteorNOX/DeepSeek-Balance-Whale-Widget.git",
    "license": "MIT",
    "publishedAt": "2026-10-02T14:07:30.408Z",
    "dshBundlePatch": "./cordis.patch.yml"
  },
  "runtime": {
    "dshVersion": "0.2.0-rc.2",
    "nodeVersion": "v24.21.0",
    "os": "linux 6.17.0-1022-azure",
    "arch": "x64"
  },
  "container": {
    "image": "none",
    "imageDigest": null,
    "notes": "executed in a one-off container; the subject was installed, booted and removed there"
  },
  "verdict": "verified",
  "dimensions": {
    "L0_qualification": {
      "id": "L0",
      "status": "pass",
      "summary": "declares dsh.bundle.patch and every declared patch path exists (20 files, 5978436 bytes unpacked)",
      "metrics": {
        "fileCount": 20,
        "unpackedBytes": 5978436,
        "patchPaths": [
          "./cordis.patch.yml"
        ],
        "declaredEnginesDsh": null,
        "shipsSource": false
      },
      "evidenceRefs": [
        "e-resolve",
        "e-tarball",
        "e-l0"
      ],
      "notes": [
        "dsh.manifestVersion is not declared; the reader does not infer a default",
        "tarball ships no src/ paths, so capability findings are limited to build output"
      ]
    },
    "L1_install": {
      "id": "L1",
      "status": "pass",
      "summary": "installed",
      "metrics": {
        "durationMs": 2102,
        "exitCode": 0,
        "declaredPeers": null,
        "bundlesAfterInstall": [
          "@deepseek-ai/dsh-base",
          "dsh-whale-widget"
        ],
        "pendingBuildScripts": [],
        "buildScriptsApproved": 0,
        "diagnosticsLog": null
      },
      "evidenceRefs": [
        "e-l1-install"
      ],
      "notes": [
        "the CLI completed the install with exit code 0",
        "no dependency build script was approved by the verifier; approval permits commands with the host user permissions"
      ]
    },
    "L2_load": {
      "id": "L2",
      "status": "pass",
      "summary": "booted, mounted and stayed alive",
      "metrics": {
        "bootBoundMs": 25000,
        "durationMs": 25065,
        "signal": null
      },
      "evidenceRefs": [
        "e-l2-boot"
      ],
      "notes": [
        "the process was still running when the wall-clock bound reached it and reported no failure diagnostics, so the bundle was neither skipped nor rejected",
        "the fiber phase is not read directly: an early exit with diagnostics is the load-failure signal, and a boot that settles and waits is the success signal"
      ]
    },
    "L3_run": {
      "id": "L3",
      "status": "pass",
      "summary": "a session completed with no credential",
      "metrics": {
        "replayAdapter": "@deepseek-ai/dsh-llm-replay@0.2.0-rc.2",
        "probeTask": "reply with any text",
        "events": {
          "session": "session-8ada2682-3a8f-46bf-8968-9aedc44f6e7c",
          "turnEndReason": {
            "kind": "completed"
          },
          "finalText": "Replay fixture: no provider was called.",
          "textEventCount": 1,
          "error": null,
          "exitCode": 0,
          "durationMs": 1260,
          "eventCount": 7
        }
      },
      "evidenceRefs": [
        "e-l3-session"
      ],
      "notes": [
        "the model call was served by the official replay adapter from a fixture authored in this repository; no provider was contacted and no credential was present",
        "probe task, stated verbatim: \"reply with any text\""
      ]
    },
    "L4_capability": {
      "id": "L4",
      "status": "pass",
      "summary": "2 capability signal(s) present across 3 scanned file(s)",
      "metrics": {
        "scannedFiles": 3,
        "scannedBytes": 1098241,
        "skippedFiles": 0
      },
      "evidenceRefs": [
        "e-l4",
        "e-patch"
      ],
      "notes": [
        "static analysis cannot see dynamically constructed code or prove intent"
      ]
    },
    "L5_overhead": {
      "id": "L5",
      "status": "pass",
      "summary": "no significant delta across 6 sampled run(s)",
      "metrics": {
        "samples": 6,
        "baseline": {
          "atMs": 8040,
          "rss": 199372800,
          "heapUsed": 68312168,
          "external": 5188103,
          "activeTotal": 10,
          "watchers": 7,
          "timers": 0,
          "libuvHandles": 22,
          "libuvActiveHandles": 17,
          "fds": 20
        },
        "activated": {
          "atMs": 8039,
          "rss": 200069120,
          "heapUsed": 69769192,
          "external": 5189831,
          "activeTotal": 11,
          "watchers": 8,
          "timers": 0,
          "libuvHandles": 23,
          "libuvActiveHandles": 18,
          "fds": 20
        },
        "delta": {
          "atMs": -1,
          "rss": 696320,
          "heapUsed": 1457024,
          "external": 1728,
          "activeTotal": 1,
          "watchers": 1,
          "timers": 0,
          "libuvHandles": 1,
          "libuvActiveHandles": 1,
          "fds": 0
        }
      },
      "evidenceRefs": [
        "e-l5-overhead"
      ],
      "notes": [
        "no metric moved beyond the significance thresholds; that is the finding",
        "differential attribution: baseline profile first, then the subject activated, same container and order",
        "thresholds are coarse on purpose — order-of-magnitude watcher changes, RSS growth beyond 100 MiB, steady state more than 2 s later"
      ]
    },
    "L6_uninstall": {
      "id": "L6",
      "status": "pass",
      "summary": "removed without residue",
      "metrics": {
        "residue": [],
        "durationMs": 264
      },
      "evidenceRefs": [
        "e-l6-remove"
      ],
      "notes": [
        "the profile retains no bundle selection, dependency entry or files for the subject"
      ]
    }
  },
  "capabilities": [
    {
      "id": "network_egress",
      "present": true,
      "confidence": "medium",
      "attribution": "unknown",
      "notes": "can make outbound network requests",
      "evidence": [
        {
          "file": "package/lib/index.js",
          "line": 1206,
          "snippet": "res = await fetch(BALANCE_URL, {"
        },
        {
          "file": "package/assets/whale-widget.js",
          "line": 155,
          "snippet": "dshwvAudioBuffers[url] = fetch(url, { cache: 'no-store' })"
        }
      ]
    },
    {
      "id": "writes_outside_workspace",
      "present": true,
      "confidence": "low",
      "attribution": "unknown",
      "notes": "resolves a path outside the workspace (e.g. os.homedir(), DSH_HOME), which is normal for DSH profile handling; static analysis cannot determine whether it also writes there",
      "evidence": [
        {
          "file": "package/lib/index.js",
          "line": 22,
          "snippet": "const DSH_HOME = process.env.DSH_HOME || path.join(os.homedir(), '.dsh')"
        }
      ]
    },
    {
      "id": "eval_or_dynamic_code",
      "present": false,
      "confidence": "medium",
      "attribution": "unknown",
      "notes": "eval or synthesised code; common and often benign, and frequently bundler output",
      "evidence": []
    },
    {
      "id": "hooks_api_gate",
      "present": false,
      "confidence": "medium",
      "attribution": "unknown",
      "notes": "hooks the API/LLM path, so it can observe or alter provider traffic",
      "evidence": []
    },
    {
      "id": "hooks_system_prompt",
      "present": false,
      "confidence": "medium",
      "attribution": "unknown",
      "notes": "hooks system-prompt assembly, so it can influence what the model is told",
      "evidence": []
    },
    {
      "id": "listens_on_port",
      "present": false,
      "confidence": "high",
      "attribution": "unknown",
      "notes": "opens a listening socket",
      "evidence": []
    },
    {
      "id": "reads_secret_env",
      "present": false,
      "confidence": "high",
      "attribution": "unknown",
      "notes": "reads an environment variable whose name looks credential-shaped",
      "evidence": []
    },
    {
      "id": "runtime_patch",
      "present": false,
      "confidence": "medium",
      "attribution": "unknown",
      "notes": "patches runtime objects rather than only registering its own services",
      "evidence": []
    },
    {
      "id": "spawns_process",
      "present": false,
      "confidence": "high",
      "attribution": "unknown",
      "notes": "spawns or would spawn an operating-system process",
      "evidence": []
    },
    {
      "id": "watches_filesystem",
      "present": false,
      "confidence": "high",
      "attribution": "unknown",
      "notes": "watches the filesystem; a recursive workspace watch is the documented cause of host stalls",
      "evidence": []
    }
  ],
  "evidence": [
    {
      "id": "e-resolve",
      "kind": "command",
      "command": "resolve dsh-whale-widget@0.3.18 -> dsh-whale-widget@0.3.18",
      "exitCode": 0,
      "durationMs": 192,
      "excerpt": "{\n  \"name\": \"dsh-whale-widget\",\n  \"version\": \"0.3.18\",\n  \"registry\": \"https://registry.npmjs.org\",\n  \"tarball\": \"https://registry.npmjs.org/dsh-whale-widget/-/dsh-whale-widget-0.3.18.tgz\",\n  \"advertisedIntegrity\": \"sha512-2RMevYiKTa2P+FzLutXlpTmQ9coWRbRQ7eG1b07MbkxB1HXXWbN/lqn0MZgDu49AILeJqmGivwB0S0H09pc9xQ==\",\n  \"publishedAt\": \"2026-10-02T14:07:30.408Z\"\n}"
    },
    {
      "id": "e-tarball",
      "kind": "artifact",
      "command": "fetch https://registry.npmjs.org/dsh-whale-widget/-/dsh-whale-widget-0.3.18.tgz",
      "exitCode": 0,
      "durationMs": 94,
      "excerpt": "{\n  \"bytes\": 4900866,\n  \"resolvedIntegrity\": \"sha512-2RMevYiKTa2P+FzLutXlpTmQ9coWRbRQ7eG1b07MbkxB1HXXWbN/lqn0MZgDu49AILeJqmGivwB0S0H09pc9xQ==\",\n  \"advertisedIntegrity\": \"sha512-2RMevYiKTa2P+FzLutXlpTmQ9coWRbRQ7eG1b07MbkxB1HXXWbN/lqn0MZgDu49AILeJqmGivwB0S0H09pc9xQ==\",\n  \"integrityMatchesRegistry\": true,\n  \"sha256\": \"81045aa394d3dadd5100d52159697e8381f82f63d65f4d2c57029b558dcc0efd\"\n}",
      "excerptBytes": 384,
      "sha256": "81045aa394d3dadd5100d52159697e8381f82f63d65f4d2c57029b558dcc0efd"
    },
    {
      "id": "e-l0",
      "kind": "static",
      "command": "read published package.json and verify declared dsh.bundle.patch paths exist",
      "excerpt": "{\n  \"status\": \"pass\",\n  \"reasons\": [],\n  \"declared\": {\n    \"manifestVersion\": null,\n    \"bundlePatch\": [\n      \"./cordis.patch.yml\"\n    ],\n    \"clientPlatform\": null,\n    \"enginesDsh\": null,\n    \"enginesNode\": null\n  },\n  \"missingPatchPaths\": [],\n  \"fileCount\": 20,\n  \"unpackedBytes\": 5978436,\n  \"shipsSource\": false\n}",
      "excerptBytes": 318
    },
    {
      "id": "e-patch",
      "kind": "static",
      "command": "read cordis.patch.yml",
      "excerpt": "# ============================================================================\n# dsh-whale-widget —— DSH bundle patch\n# ============================================================================\n# 这是插件的\"挂载声明\"。DSH 启动时按 bundle 层栈叠加各插件 patch，\n# 本文件会把鲸鱼余额挂件插入 Web profile 的配置树。\n#\n# 安装方式（不再需要手工复制/手工改 profile patch）：\n#   dsh plugin --profile web add dsh-whale-widget\n# 或本地开发安装：\n#   dsh plugin --profile web add link:<本目录绝对路径>\n# ============================================================================\n\n- insert:\n    - id: dsh-whale-widget\n      name: dsh-whale-widget\n",
      "excerptBytes": 719,
      "sha256": "86dd2bdb919d8e98a63fb7b9ad44b5ea38ef0a86994b87060b0b6ca3c38e6ef1"
    },
    {
      "id": "e-l4",
      "kind": "static",
      "command": "scan 3 shipped source file(s) for capability signatures",
      "excerpt": "{\n  \"present\": [\n    {\n      \"id\": \"network_egress\",\n      \"confidence\": \"medium\",\n      \"attribution\": \"unknown\",\n      \"firstEvidence\": {\n        \"file\": \"package/lib/index.js\",\n        \"line\": 1206,\n        \"snippet\": \"res = await fetch(BALANCE_URL, {\"\n      }\n    },\n    {\n      \"id\": \"writes_outside_workspace\",\n      \"confidence\": \"low\",\n      \"attribution\": \"unknown\",\n      \"firstEvidence\": {\n        \"file\": \"package/lib/index.js\",\n        \"line\": 22,\n        \"snippet\": \"const DSH_HOME = process.env.DSH_HOME || path.join(os.homedir(), '.dsh')\"\n      }\n    }\n  ],\n  \"scannedFiles\": 3,\n  \"skippedFiles\": 0,\n  \"limits\": [\n    \"static analysis cannot see dynamically constructed code or prove intent\"\n  ]\n}",
      "excerptBytes": 713
    },
    {
      "id": "e-l1-install",
      "kind": "command",
      "command": "dsh plugin --profile verify add dsh-whale-widget@0.3.18",
      "exitCode": 0,
      "durationMs": 2102,
      "excerpt": "Progress: resolved 1, reused 0, downloaded 0, added 0\nPackages are hard linked from the content-addressable store to the virtual store.\n  Content-addressable store is at: /home/verifier/.local/share/pnpm/store/v11\n  Virtual store is at:             node_modules/.pnpm\nPackages: +1\n+\nProgress: resolved 1, reused 0, downloaded 1, added 1, done\n\ndependencies:\n+ dsh-whale-widget 0.3.18\n\nDone in 301ms using pnpm v12.8.1\ndsh: initialized profile verify at /work/dsh-home/profiles/verify\n",
      "excerptBytes": 484,
      "truncated": false,
      "sha256": "3382d2224c4d04bb27ea0b46896c8048e9e13f3fce04743e6f9707897216e75b"
    },
    {
      "id": "e-l2-boot",
      "kind": "command",
      "command": "dsh --profile verify",
      "exitCode": 0,
      "durationMs": 25065,
      "excerpt": "",
      "excerptBytes": 0,
      "truncated": false,
      "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
    },
    {
      "id": "e-l6-remove",
      "kind": "command",
      "command": "dsh plugin --profile verify remove dsh-whale-widget",
      "exitCode": 0,
      "durationMs": 264,
      "excerpt": "Packages: -1\n-\n\ndependencies:\n- dsh-whale-widget 0.3.18\n\nDone in 10ms using pnpm v12.8.1\n",
      "excerptBytes": 89,
      "truncated": false,
      "sha256": "f706f8bb1bf898cace982aeb173a8e4609327386e1c3acef40faa53e031d99ee"
    },
    {
      "id": "e-l5-overhead",
      "kind": "sample",
      "command": "dsh --profile <baseline|activated> with the host sampler injected via NODE_OPTIONS=--import",
      "excerpt": "{\n  \"method\": \"differential\",\n  \"status\": \"no-significant-delta\",\n  \"samples\": 6,\n  \"baselineMedian\": {\n    \"atMs\": 8040,\n    \"rss\": 199372800,\n    \"heapUsed\": 68312168,\n    \"external\": 5188103,\n    \"activeTotal\": 10,\n    \"watchers\": 7,\n    \"timers\": 0,\n    \"libuvHandles\": 22,\n    \"libuvActiveHandles\": 17,\n    \"fds\": 20\n  },\n  \"activatedMedian\": {\n    \"atMs\": 8039,\n    \"rss\": 200069120,\n    \"heapUsed\": 69769192,\n    \"external\": 5189831,\n    \"activeTotal\": 11,\n    \"watchers\": 8,\n    \"timers\": 0,\n    \"libuvHandles\": 23,\n    \"libuvActiveHandles\": 18,\n    \"fds\": 20\n  },\n  \"delta\": {\n    \"atMs\": -1,\n    \"rss\": 696320,\n    \"heapUsed\": 1457024,\n    \"external\": 1728,\n    \"activeTotal\": 1,\n    \"watchers\": 1,\n    \"timers\": 0,\n    \"libuvHandles\": 1,\n    \"libuvActiveHandles\": 1,\n    \"fds\": 0\n  },\n  \"significant\": []\n}"
    },
    {
      "id": "e-l3-session",
      "kind": "command",
      "command": "dsh --profile l3 --patch /work/fixtures/replay/l3-overlay.yml --json reply with any text",
      "exitCode": 0,
      "durationMs": 1260,
      "excerpt": "{\"type\":\"session\",\"sessionId\":\"session-8ada2682-3a8f-46bf-8968-9aedc44f6e7c\",\"cwd\":\"/work\"}\n{\"type\":\"status\",\"phase\":\"turn_start\",\"turn\":1}\n{\"type\":\"status\",\"phase\":\"step_start\",\"turn\":1,\"step\":1}\n{\"type\":\"text\",\"text\":\"Replay fixture: no provider was called.\"}\n{\"type\":\"status\",\"phase\":\"step_end\",\"turn\":1,\"step\":1}\n{\"type\":\"status\",\"phase\":\"turn_end\",\"turn\":1,\"reason\":{\"kind\":\"completed\"}}\n{\"type\":\"final\",\"text\":\"Replay fixture: no provider was called.\"}\n",
      "excerptBytes": 459,
      "truncated": false,
      "sha256": "6b1d731bcd2771cc40eb239e0a88d1882c7ceb7a0949be2fa0cf61c7c4324924"
    }
  ],
  "redactions": [],
  "disclaimers": [
    "Verification is not a security audit and not an endorsement. It records what was executed and observed on one machine at one time. Absence of a finding is not a finding of absence."
  ],
  "limits": [
    "the artifact ships no source paths, so capability findings describe build output only; code-level attribution between the author and inlined dependencies is not resolvable from this artifact",
    "static analysis cannot see dynamically constructed code or prove intent",
    "L3 ran against a replayed transcript from a fixture authored by the verifier, not against a provider: it establishes that a session completes without a credential, not that the plugin behaves correctly against a live model",
    "the load result is inferred from exit behaviour and diagnostics rather than a directly read fiber phase",
    "no dependency build script was approved by this executor",
    "overhead is reported only where a delta cleared the significance thresholds; otherwise the result is no-significant-delta",
    "sampling happens inside the host process via NODE_OPTIONS=--import, so process.getActiveResourcesInfo() and process.report.getReport() describe the process under test"
  ],
  "bundlePatch": {
    "path": "cordis.patch.yml",
    "present": true,
    "bytes": 719,
    "entryCount": 2,
    "disablesHostEntries": false,
    "overridesConfig": false,
    "usesJsExpressions": false,
    "findings": [
      {
        "kind": "inserts-entry",
        "line": 13,
        "snippet": "- insert:"
      },
      {
        "kind": "inserts-entry",
        "line": 14,
        "snippet": "- id: dsh-whale-widget"
      }
    ],
    "notes": [
      "textual analysis: a line number is provided for review, not a YAML object model"
    ]
  },
  "overhead": {
    "method": "differential",
    "status": "no-significant-delta",
    "samples": 6,
    "baseline": {
      "atMs": 8040,
      "rss": 199372800,
      "heapUsed": 68312168,
      "external": 5188103,
      "activeTotal": 10,
      "watchers": 7,
      "timers": 0,
      "libuvHandles": 22,
      "libuvActiveHandles": 17,
      "fds": 20
    },
    "activated": {
      "atMs": 8039,
      "rss": 200069120,
      "heapUsed": 69769192,
      "external": 5189831,
      "activeTotal": 11,
      "watchers": 8,
      "timers": 0,
      "libuvHandles": 23,
      "libuvActiveHandles": 18,
      "fds": 20
    },
    "delta": {
      "atMs": -1,
      "rss": 696320,
      "heapUsed": 1457024,
      "external": 1728,
      "activeTotal": 1,
      "watchers": 1,
      "timers": 0,
      "libuvHandles": 1,
      "libuvActiveHandles": 1,
      "fds": 0
    },
    "significant": [],
    "resourceKinds": {
      "baseline": {
        "PipeWrap": 3,
        "FSEventWrap": 7,
        "async": 3,
        "timer": 2,
        "check": 2,
        "idle": 1,
        "prepare": 1,
        "pipe": 3,
        "signal": 2,
        "fs_event": 7,
        "loop": 1
      },
      "activated": {
        "PipeWrap": 3,
        "FSEventWrap": 8,
        "async": 3,
        "timer": 2,
        "check": 2,
        "idle": 1,
        "prepare": 1,
        "pipe": 3,
        "signal": 2,
        "fs_event": 8,
        "loop": 1
      }
    }
  }
}
