← all reports

npm:@roarpeng/graphflow@2.2.0

dsh-verified: partial — npm:@roarpeng/graphflow@2.2.0. Verification is not a security audit and not an endorsement. It records what was executed and observed on one machine at one time. Historical method limitation: this execution had network access and published container paths and replay fixture text. dsh plugin dsh plugin partial partial

Method limitation. This historical execution used a container with network access and published container paths and replay fixture text. The no-egress and redaction conditions were not met. See the security incident.

sha512-IyY6QjSNuQLojcV92qR44ILiXwu0n/yeaQDd0zzOC18iMRqybt1wIiI7FCcPmUDInlvLd4rEnM49AYsW/AF4NA==

Subject

name@roarpeng/graphflow
version2.2.0
integritysha512-IyY6QjSNuQLojcV92qR44ILiXwu0n/yeaQDd0zzOC18iMRqybt1wIiI7FCcPmUDInlvLd4rEnM49AYsW/AF4NA==
repositorygit+https://github.com/Roarpeng/GraphFlow.git
declared bundle patch"./cordis.patch.yml"
declared engines.dshnot declared — declarative and unenforced

Environment

DSH0.2.0-rc.2
Nodev24.21.0
OS / archlinux 6.17.0-1022-azure x64
verifierdsh-verified 0.1.0 b737da1e4edd
generated2026-10-03T16:49:48.347Z

Dimensions

statussummaryevidence
L0 pass declares dsh.bundle.patch and every declared patch path exists (1204 files, 24261577 bytes unpacked)

dsh.manifestVersion is not declared; the reader does not infer a default

metrics
{
  "fileCount": 1204,
  "unpackedBytes": 24261577,
  "patchPaths": [
    "./cordis.patch.yml"
  ],
  "declaredEnginesDsh": null,
  "shipsSource": true
}
e-resolve, e-tarball, e-l0
L1 fail installation blocked pending dependency build-script approval

pnpm refused to run build scripts for 4 package(s) and the install did not complete. This verifier never approves them: approval permits commands with the host user's permissions, which is the user's decision and a finding rather than a chore. The requested scripts are listed in the metrics.

no dependency build script was approved by the verifier; approval permits commands with the host user permissions

metrics
{
  "durationMs": 4847,
  "exitCode": 1,
  "declaredPeers": null,
  "bundlesAfterInstall": [
    "@deepseek-ai/dsh-base"
  ],
  "pendingBuildScripts": [
    "@roarpeng/graphflow@2.2.0",
    "better-sqlite3@12.11.1",
    "onnxruntime-node@1.30.0",
    "protobufjs@7.6.6"
  ],
  "buildScriptsApproved": 0,
  "diagnosticsLog": "/work/dsh-home/profiles/verify/.plugin-manager/logs/operation-1SeoeV/pnpm.log"
}
e-l1-install
L2 skip not run: the subject did not install

loading a plugin that is not present would measure nothing

no evidence cited
L3 skip not run: the subject did not install

a session cannot be attributed to a subject that is not present

no evidence cited
L4 pass 6 capability signal(s) present across 588 scanned file(s)

the package ships build output; code inside a bundle cannot be reliably attributed to the author or to an inlined dependency

static analysis cannot see dynamically constructed code or prove intent

metrics
{
  "scannedFiles": 588,
  "scannedBytes": 3569614,
  "skippedFiles": 0
}
e-l4, e-patch
L5 inconclusive the subject did not install, so there was nothing to activate

no overhead claim is made when the differential could not be completed

metrics
{
  "samples": 0
}
no evidence cited
L6 skip not run: the subject did not install

removal was not attempted because nothing was installed

no evidence cited

Capability (L4, static)

capabilityconfidenceattributionfirst evidence
hooks_system_promptmediumunknownpackage/dsh/plugin.mjs:320
listens_on_portmediumbuild-outputpackage/dist/surfaces/mcp/server.js:588
network_egresslowbuild-outputpackage/dist/routing/provider-adapters/anthropic.js:21
reads_secret_envmediumbuild-outputpackage/dist/routing/provider-adapters/anthropic.js:9
spawns_processmediumunknownpackage/scripts/safe-postinstall.cjs:5
writes_outside_workspacelowunknownpackage/dsh/plugin.mjs:478

Capability is not intent. A signature records what the code can reach for, not what it does.

Overhead (L5, dynamic)

No overhead measurement was published for this report.

Evidence

idkindartifact
e-resolve command exit 0 409 ms resolve @roarpeng/graphflow@2.2.0 -> @roarpeng/graphflow@2.2.0
{
  "name": "@roarpeng/graphflow",
  "version": "2.2.0",
  "registry": "https://registry.npmjs.org",
  "tarball": "https://registry.npmjs.org/@roarpeng/graphflow/-/graphflow-2.2.0.tgz",
  "advertisedIntegrity": "sha512-IyY6QjSNuQLojcV92qR44ILiXwu0n/yeaQDd0zzOC18iMRqybt1wIiI7FCcPmUDInlvLd4rEnM49AYsW/AF4NA==",
  "publishedAt": "2026-10-02T12:48:41.890Z"
}
e-tarball artifact exit 0 109 ms fetch https://registry.npmjs.org/@roarpeng/graphflow/-/graphflow-2.2.0.tgz
{
  "bytes": 3266668,
  "resolvedIntegrity": "sha512-IyY6QjSNuQLojcV92qR44ILiXwu0n/yeaQDd0zzOC18iMRqybt1wIiI7FCcPmUDInlvLd4rEnM49AYsW/AF4NA==",
  "advertisedIntegrity": "sha512-IyY6QjSNuQLojcV92qR44ILiXwu0n/yeaQDd0zzOC18iMRqybt1wIiI7FCcPmUDInlvLd4rEnM49AYsW/AF4NA==",
  "integrityMatchesRegistry": true,
  "sha256": "c9fa6e2a74a0e367a4dbd37e997f31666ad825c334226e45ab60dfd6820ab168"
}
e-l0 static read published package.json and verify declared dsh.bundle.patch paths exist
{
  "status": "pass",
  "reasons": [],
  "declared": {
    "manifestVersion": null,
    "bundlePatch": [
      "./cordis.patch.yml"
    ],
    "clientPlatform": "web",
    "enginesDsh": null,
    "enginesNode": ">=20"
  },
  "missingPatchPaths": [],
  "fileCount": 1204,
  "unpackedBytes": 24261577,
  "shipsSource": true
}
e-patch static read cordis.patch.yml
# GraphFlow — DeepSeek Harness (dsh) 插件层
#
# 用法:
#   dsh plugin --profile web add @roarpeng/graphflow
#   npx @deepseek-ai/dsh web
#   或已有 ~/.dsh 时: npx @roarpeng/graphflow install
#
# 能力:
#   1) MCP 10 工具挂到 ctx.tools(cwd = 会话/工作区 process.cwd())。
#      模型侧名称: mcp__graphflow__graphflow_context / _plan / _run /
#      _report_outcome / _insight / _index / _skill_insights /
#      _diagnose / _artifact / _skill_guide
#   2) ESM glue `@roarpeng/graphflow/dsh`:ctx.skills.register(graphflow)
#      (dsh plugin add 即可用 skill,不必先 graphflow install);
#      agent/disposed 时不默认把 pending episode 标成成功(等同 Claude Code
#      SessionEnd 空 $2 保持 pending)。显式 GRAPHFLOW_HOOK_SUCCESS=true|false
#      才调用 graphflow outcome report。不监听 live session/flush。
#   3) 首轮 agent/pre-step 注入一句短 hint:先调 graphflow_context(rootDir=cwd)。
#
# 调用约定: 先 context(传 rootDir),复杂任务再 plan;改完代码后 index;
#   若走了 run,结束后必须 report_outcome。不要写死 GRAPHFLOW_WORKSPACE_ROOT。
#
# graphflow install(无 profile 包时)只写 MCP 行到 $DSH_HOME/cordis.patch.yml;
# 已 `dsh plugin add` / profile 有包时会清空 home overlay,由 bundle 独占 MCP+glue
# (避免 duplicate loader entry id / ERR_MODULE_NOT_FOUND)。
# 完整安装请优先: dsh plugin --profile web add @roarpeng/graphflow

- insert:
    - id: mcp-graphflow
      name: '@deepseek-ai/dsh-mcp-client'
      config:
        serverName: graphflow
        transport: stdio
        command: npx
        args:
          - '-y'
          - '--package=@roarpeng/graphflow'
          - graphflow-mcp
        env:
          GRAPHFLOW_MCP_STDIO: '1'
          GRAPHFLOW_LOG_JSON: '1'
        cwd: !!js process.cwd()
        failOnStartupError: false
    - id: graphflow-dsh
      name: '@roarpeng/graphflow/dsh'
e-l4 static scan 588 shipped source file(s) for capability signatures
{
  "present": [
    {
      "id": "hooks_system_prompt",
      "confidence": "medium",
      "attribution": "unknown",
      "firstEvidence": {
        "file": "package/dsh/plugin.mjs",
        "line": 320,
        "snippet": "\"system-prompt\","
      }
    },
    {
      "id": "listens_on_port",
      "confidence": "medium",
      "attribution": "build-output",
      "firstEvidence": {
        "file": "package/dist/surfaces/mcp/server.js",
        "line": 588,
        "snippet": "httpServer.listen(requestedPort, host, resolve);"
      }
    },
    {
      "id": "network_egress",
      "confidence": "low",
      "attribution": "build-output",
      "firstEvidence": {
        "file": "package/dist/routing/provider-adapters/anthropic.js",
        "line": 21,
        "snippet": "const response = await fetch(`${baseUrl}/v1/messages`, {"
      }
    },
    {
      "id": "reads_secret_env",
      "confidence": "medium",
      "attribution": "build-output",
      "firstEvidence": {
        "file": "package/dist/routing/provider-adapters/anthropic.js",
        "line": 9,
        "snippet": "const apiKey = process.env.ANTHROPIC_API_KEY;"
      }
    },
    {
      "id": "spawns_process",
      "confidence": "medium",
      "attribution": "unknown",
      "firstEvidence": {
        "file": "package/scripts/safe-postinstall.cjs",
        "line": 5,
        "snippet": "const { spawnSync } = require(\"node:child_process\");"
      }
    },
    {
      "id": "writes_outside_workspace",
      "confidence": "low",
      "attribution": "unknown",
      "firstEvidence": {
        "file": "package/dsh/plugin.mjs",
        "line": 478,
        "snippet": "export function resolveCliForCapture(packageRoot = PACKAGE_ROOT, home = process.env.HOME || process.env.USERPROFILE) {"
      }
    }
  ],
  "scannedFiles": 588,
  "skippedFiles": 0,
  "limits": [
    "the package ships build output; code inside a bundle cannot be reliably attributed to the author or to an inlined dependency",
    "static analysis cannot see dynamically construct
e-l1-install command exit 1 4847 ms dsh plugin --profile verify add @roarpeng/graphflow@2.2.0
Downloading gpt-tokenizer@3.4.0: 0.00 B/17.68 MB
Downloading onnxruntime-web@1.31.0-dev.20260914-8d85527a0: 0.00 B/33.18 MB
Downloading onnxruntime-node@1.30.0: 0.00 B/113.50 MB
Downloading @img/sharp-libvips-linux-x64@1.3.4: 0.00 B/8.21 MB
[WARN] 1 deprecated subdependencies found: prebuild-install@7.1.3
Downloading onnxruntime-node@1.30.0: 93.02 MB/113.50 MB
Packages are hard linked from the content-addressable store to the virtual store.
  Content-addressable store is at: /home/verifier/.local/share/pnpm/store/v11
  Virtual store is at:             node_modules/.pnpm
Packages: +186
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Progress: resolved 185, reused 0, downloaded 188, added 186, done

dependencies:
+ @roarpeng/graphflow 2.2.0

dsh: initialized profile verify at /work/dsh-home/profiles/verify
Error: ERR_PNPM_IGNORED_BUILDS

  × adding a new package
  ╰─▶ Ignored build scripts: @roarpeng/graphflow@2.2.0, better-
      sqlite3@12.11.1, onnxruntime-node@1.30.0, protobufjs@7.6.6
  help: Run "pnpm approve-builds" to pick which dependencies should be allowed
        to run scripts.

dsh: plugin command failed; diagnostics: /work/dsh-home/profiles/verify/.plugin-manager/logs/operation-1SeoeV/pnpm.log

Limits

Disclaimers

raw report JSON · badge · dispute this report