← all reports

npm:@nanmicoder/dsh-agent-teams@0.1.22

dsh-verified: verified — npm:@nanmicoder/dsh-agent-teams@0.1.22. Verification is not a security audit and not an endorsement. It records what was executed and observed on one machine at one time. Historical method limitation: this execution had network access and published container paths and replay fixture text. dsh plugin dsh plugin verified verified

Method limitation. This historical execution used a container with network access and published container paths and replay fixture text. The no-egress and redaction conditions were not met. See the security incident.

sha512-JF6bpHf+BYQbe14+yH1uM5EeviRZmi72gGZiIvS/5R8FHq6/i5+H+dXoy7s6CNQVRhM4NWjw4XsC8tSjwDksvQ==

Subject

name@nanmicoder/dsh-agent-teams
version0.1.22
integritysha512-JF6bpHf+BYQbe14+yH1uM5EeviRZmi72gGZiIvS/5R8FHq6/i5+H+dXoy7s6CNQVRhM4NWjw4XsC8tSjwDksvQ==
repositorygit+https://github.com/NanmiCoder/dsh-agent-teams.git
declared bundle patch"./cordis.patch.yml"
declared engines.dshnot declared — declarative and unenforced

Environment

DSH0.2.0-rc.2
Nodev24.21.0
OS / archlinux 6.17.0-1022-azure x64
verifierdsh-verified 0.1.0 ec8d77c8d74d
generated2026-10-03T16:18:35.568Z

Dimensions

statussummaryevidence
L0 pass declares dsh.bundle.patch and every declared patch path exists (113 files, 3188817 bytes unpacked)

dsh.manifestVersion is not declared; the reader does not infer a default

tarball ships no src/ paths, so capability findings are limited to build output

metrics
{
  "fileCount": 113,
  "unpackedBytes": 3188817,
  "patchPaths": [
    "./cordis.patch.yml"
  ],
  "declaredEnginesDsh": null,
  "shipsSource": false
}
e-resolve, e-tarball, e-l0
L1 pass installed

the CLI completed the install with exit code 0

no dependency build script was approved by the verifier; approval permits commands with the host user permissions

metrics
{
  "durationMs": 2335,
  "exitCode": 0,
  "declaredPeers": null,
  "bundlesAfterInstall": [
    "@deepseek-ai/dsh-base",
    "@nanmicoder/dsh-agent-teams"
  ],
  "pendingBuildScripts": [],
  "buildScriptsApproved": 0,
  "diagnosticsLog": null
}
e-l1-install
L2 pass booted, mounted and stayed alive

the process was still running when the wall-clock bound reached it and reported no failure diagnostics, so the bundle was neither skipped nor rejected

the fiber phase is not read directly: an early exit with diagnostics is the load-failure signal, and a boot that settles and waits is the success signal

metrics
{
  "bootBoundMs": 25000,
  "durationMs": 25069,
  "signal": null
}
e-l2-boot
L3 pass a session completed with no credential

the model call was served by the official replay adapter from a fixture authored in this repository; no provider was contacted and no credential was present

probe task, stated verbatim: "reply with any text"

metrics
{
  "replayAdapter": "@deepseek-ai/dsh-llm-replay@0.2.0-rc.2",
  "probeTask": "reply with any text",
  "events": {
    "session": "session-ae5ec025-ea8e-4185-a557-79fdfb1a67fd",
    "turnEndReason": {
      "kind": "completed"
    },
    "finalText": "Replay fixture: no provider was called.",
    "textEventCount": 1,
    "error": null,
    "exitCode": 0,
    "durationMs": 1335,
    "eventCount": 7
  }
}
e-l3-session
L4 pass 2 capability signal(s) present across 67 scanned file(s)

the package ships build output; code inside a bundle cannot be reliably attributed to the author or to an inlined dependency

static analysis cannot see dynamically constructed code or prove intent

metrics
{
  "scannedFiles": 67,
  "scannedBytes": 950346,
  "skippedFiles": 0
}
e-l4, e-patch
L5 pass no significant delta across 6 sampled run(s)

no metric moved beyond the significance thresholds; that is the finding

differential attribution: baseline profile first, then the subject activated, same container and order

thresholds are coarse on purpose — order-of-magnitude watcher changes, RSS growth beyond 100 MiB, steady state more than 2 s later

metrics
{
  "samples": 6,
  "baseline": {
    "atMs": 8040,
    "rss": 199614464,
    "heapUsed": 68410664,
    "external": 5188103,
    "activeTotal": 10,
    "watchers": 7,
    "timers": 0,
    "libuvHandles": 22,
    "libuvActiveHandles": 17,
    "fds": 20
  },
  "activated": {
    "atMs": 8041,
    "rss": 205447168,
    "heapUsed": 46288904,
    "external": 4362894,
    "activeTotal": 11,
    "watchers": 8,
    "timers": 0,
    "libuvHandles": 23,
    "libuvActiveHandles": 18,
    "fds": 20
  },
  "delta": {
    "atMs": 1,
    "rss": 5832704,
    "heapUsed": -22121760,
    "external": -825209,
    "activeTotal": 1,
    "watchers": 1,
    "timers": 0,
    "libuvHandles": 1,
    "libuvActiveHandles": 1,
    "fds": 0
  }
}
e-l5-overhead
L6 pass removed without residue

the profile retains no bundle selection, dependency entry or files for the subject

metrics
{
  "residue": [],
  "durationMs": 271
}
e-l6-remove

Capability (L4, static)

capabilityconfidenceattributionfirst evidence
hooks_system_promptmediumunknownpackage/lib/index.js:39
network_egressmediumunknownpackage/lib/client/activity-monitor.js:133

Capability is not intent. A signature records what the code can reach for, not what it does.

Overhead (L5, dynamic)

{
  "status": "no-significant-delta",
  "samples": 6,
  "baseline": {
    "atMs": 8040,
    "rss": 199614464,
    "heapUsed": 68410664,
    "external": 5188103,
    "activeTotal": 10,
    "watchers": 7,
    "timers": 0,
    "libuvHandles": 22,
    "libuvActiveHandles": 17,
    "fds": 20
  },
  "activated": {
    "atMs": 8041,
    "rss": 205447168,
    "heapUsed": 46288904,
    "external": 4362894,
    "activeTotal": 11,
    "watchers": 8,
    "timers": 0,
    "libuvHandles": 23,
    "libuvActiveHandles": 18,
    "fds": 20
  },
  "delta": {
    "atMs": 1,
    "rss": 5832704,
    "heapUsed": -22121760,
    "external": -825209,
    "activeTotal": 1,
    "watchers": 1,
    "timers": 0,
    "libuvHandles": 1,
    "libuvActiveHandles": 1,
    "fds": 0
  },
  "significant": []
}

Evidence

idkindartifact
e-resolve command exit 0 314 ms resolve @nanmicoder/dsh-agent-teams@0.1.22 -> @nanmicoder/dsh-agent-teams@0.1.22
{
  "name": "@nanmicoder/dsh-agent-teams",
  "version": "0.1.22",
  "registry": "https://registry.npmjs.org",
  "tarball": "https://registry.npmjs.org/@nanmicoder/dsh-agent-teams/-/dsh-agent-teams-0.1.22.tgz",
  "advertisedIntegrity": "sha512-JF6bpHf+BYQbe14+yH1uM5EeviRZmi72gGZiIvS/5R8FHq6/i5+H+dXoy7s6CNQVRhM4NWjw4XsC8tSjwDksvQ==",
  "publishedAt": "2026-09-29T13:52:39.905Z"
}
e-tarball artifact exit 0 205 ms fetch https://registry.npmjs.org/@nanmicoder/dsh-agent-teams/-/dsh-agent-teams-0.1.22.tgz
{
  "bytes": 2099312,
  "resolvedIntegrity": "sha512-JF6bpHf+BYQbe14+yH1uM5EeviRZmi72gGZiIvS/5R8FHq6/i5+H+dXoy7s6CNQVRhM4NWjw4XsC8tSjwDksvQ==",
  "advertisedIntegrity": "sha512-JF6bpHf+BYQbe14+yH1uM5EeviRZmi72gGZiIvS/5R8FHq6/i5+H+dXoy7s6CNQVRhM4NWjw4XsC8tSjwDksvQ==",
  "integrityMatchesRegistry": true,
  "sha256": "bdc19f0b017955625f3ab339a73465d7beac518df36dcd7c1b6ceb45a18f099d"
}
e-l0 static read published package.json and verify declared dsh.bundle.patch paths exist
{
  "status": "pass",
  "reasons": [],
  "declared": {
    "manifestVersion": null,
    "bundlePatch": [
      "./cordis.patch.yml"
    ],
    "clientPlatform": "web",
    "enginesDsh": null,
    "enginesNode": "^22.19.0 || >=24"
  },
  "missingPatchPaths": [],
  "fileCount": 113,
  "unpackedBytes": 3188817,
  "shipsSource": false
}
e-patch static read cordis.patch.yml
# dsh-agent-teams bundle patch: mounts the agent-teams plugin into the host
# composition of a dsh profile. The plugin registers its `agent_teams_*` tools
# into the shared `tools` registry and one usage section into the global
# system prompt, so every session of the profile can drive AgentTeams through
# natural language ("用 AgentTeams 做 X").
#
# Install: `dsh plugin --profile <name> add <this package>` (npm or a local
# path). The `dsh plugin` command pnpm-installs the package into the profile
# and reconciles it into the profile's `dsh.profile.bundles` layer list.
- insert:
    - id: agent-teams
      # Node-resolvable package name — must stay in sync with package.json
      # `name`. Quoted because `@` is a reserved indicator in YAML and cannot
      # open a plain scalar.
      name: '@nanmicoder/dsh-agent-teams'
      config:
        # Team state lives under `<session workspace>/<stateDir>/<teamId>/`
        # (team.json + inbox/*.jsonl mailboxes).
        stateDir: .agent-teams
        # Provider used to spawn member subagents ('spawn' or 'fork').
        memberProvider: spawn
e-l4 static scan 67 shipped source file(s) for capability signatures
{
  "present": [
    {
      "id": "hooks_system_prompt",
      "confidence": "medium",
      "attribution": "unknown",
      "firstEvidence": {
        "file": "package/lib/index.js",
        "line": 39,
        "snippet": "export const inject = ['tools', 'llm', 'subagents', 'systemPrompt', 'agents'];"
      }
    },
    {
      "id": "network_egress",
      "confidence": "medium",
      "attribution": "unknown",
      "firstEvidence": {
        "file": "package/lib/client/activity-monitor.js",
        "line": 133,
        "snippet": "const fetchState = runtime.fetchState ?? ((url, init) => fetch(url, init));"
      }
    }
  ],
  "scannedFiles": 67,
  "skippedFiles": 0,
  "limits": [
    "the package ships build output; code inside a bundle cannot be reliably attributed to the author or to an inlined dependency",
    "static analysis cannot see dynamically constructed code or prove intent"
  ]
}
e-l1-install command exit 0 2335 ms dsh plugin --profile verify add @nanmicoder/dsh-agent-teams@0.1.22
Progress: resolved 1, reused 0, downloaded 0, added 0
Packages are hard linked from the content-addressable store to the virtual store.
  Content-addressable store is at: /home/verifier/.local/share/pnpm/store/v11
  Virtual store is at:             node_modules/.pnpm
Packages: +1
+
Progress: resolved 1, reused 0, downloaded 1, added 1, done

dependencies:
+ @nanmicoder/dsh-agent-teams 0.1.22

Done in 390ms using pnpm v12.8.1
dsh: initialized profile verify at /work/dsh-home/profiles/verify
e-l2-boot command exit 0 25069 ms dsh --profile verify
e-l6-remove command exit 0 271 ms dsh plugin --profile verify remove @nanmicoder/dsh-agent-teams
Packages: -1
-

dependencies:
- @nanmicoder/dsh-agent-teams 0.1.22

Done in 11ms using pnpm v12.8.1
e-l5-overhead sample dsh --profile <baseline|activated> with the host sampler injected via NODE_OPTIONS=--import
{
  "method": "differential",
  "status": "no-significant-delta",
  "samples": 6,
  "baselineMedian": {
    "atMs": 8040,
    "rss": 199614464,
    "heapUsed": 68410664,
    "external": 5188103,
    "activeTotal": 10,
    "watchers": 7,
    "timers": 0,
    "libuvHandles": 22,
    "libuvActiveHandles": 17,
    "fds": 20
  },
  "activatedMedian": {
    "atMs": 8041,
    "rss": 205447168,
    "heapUsed": 46288904,
    "external": 4362894,
    "activeTotal": 11,
    "watchers": 8,
    "timers": 0,
    "libuvHandles": 23,
    "libuvActiveHandles": 18,
    "fds": 20
  },
  "delta": {
    "atMs": 1,
    "rss": 5832704,
    "heapUsed": -22121760,
    "external": -825209,
    "activeTotal": 1,
    "watchers": 1,
    "timers": 0,
    "libuvHandles": 1,
    "libuvActiveHandles": 1,
    "fds": 0
  },
  "significant": []
}
e-l3-session command exit 0 1335 ms dsh --profile l3 --patch /work/fixtures/replay/l3-overlay.yml --json reply with any text
{"type":"session","sessionId":"session-ae5ec025-ea8e-4185-a557-79fdfb1a67fd","cwd":"/work"}
{"type":"status","phase":"turn_start","turn":1}
{"type":"status","phase":"step_start","turn":1,"step":1}
{"type":"text","text":"Replay fixture: no provider was called."}
{"type":"status","phase":"step_end","turn":1,"step":1}
{"type":"status","phase":"turn_end","turn":1,"reason":{"kind":"completed"}}
{"type":"final","text":"Replay fixture: no provider was called."}

Limits

Disclaimers

raw report JSON · badge · dispute this report