Method limitation. This historical execution used a container with network access and published container paths and replay fixture text. The no-egress and redaction conditions were not met. See the security incident.
sha512-IyY6QjSNuQLojcV92qR44ILiXwu0n/yeaQDd0zzOC18iMRqybt1wIiI7FCcPmUDInlvLd4rEnM49AYsW/AF4NA==
| name | @roarpeng/graphflow |
|---|---|
| version | 2.2.0 |
| integrity | sha512-IyY6QjSNuQLojcV92qR44ILiXwu0n/yeaQDd0zzOC18iMRqybt1wIiI7FCcPmUDInlvLd4rEnM49AYsW/AF4NA== |
| repository | git+https://github.com/Roarpeng/GraphFlow.git |
| declared bundle patch | "./cordis.patch.yml" |
| declared engines.dsh | not declared — declarative and unenforced |
| DSH | 0.2.0-rc.2 |
|---|---|
| Node | v24.21.0 |
| OS / arch | linux 6.17.0-1022-azure x64 |
| verifier | dsh-verified 0.1.0 b737da1e4edd |
| generated | 2026-10-03T16:49:48.347Z |
| status | summary | evidence | |
|---|---|---|---|
L0 |
pass | declares dsh.bundle.patch and every declared patch path exists (1204 files, 24261577 bytes unpacked)
dsh.manifestVersion is not declared; the reader does not infer a default metrics{
"fileCount": 1204,
"unpackedBytes": 24261577,
"patchPaths": [
"./cordis.patch.yml"
],
"declaredEnginesDsh": null,
"shipsSource": true
} |
e-resolve, e-tarball, e-l0 |
L1 |
fail | installation blocked pending dependency build-script approval
pnpm refused to run build scripts for 4 package(s) and the install did not complete. This verifier never approves them: approval permits commands with the host user's permissions, which is the user's decision and a finding rather than a chore. The requested scripts are listed in the metrics. no dependency build script was approved by the verifier; approval permits commands with the host user permissions metrics{
"durationMs": 4847,
"exitCode": 1,
"declaredPeers": null,
"bundlesAfterInstall": [
"@deepseek-ai/dsh-base"
],
"pendingBuildScripts": [
"@roarpeng/graphflow@2.2.0",
"better-sqlite3@12.11.1",
"onnxruntime-node@1.30.0",
"protobufjs@7.6.6"
],
"buildScriptsApproved": 0,
"diagnosticsLog": "/work/dsh-home/profiles/verify/.plugin-manager/logs/operation-1SeoeV/pnpm.log"
} |
e-l1-install |
L2 |
skip | not run: the subject did not install
loading a plugin that is not present would measure nothing |
no evidence cited |
L3 |
skip | not run: the subject did not install
a session cannot be attributed to a subject that is not present |
no evidence cited |
L4 |
pass | 6 capability signal(s) present across 588 scanned file(s)
the package ships build output; code inside a bundle cannot be reliably attributed to the author or to an inlined dependency static analysis cannot see dynamically constructed code or prove intent metrics{
"scannedFiles": 588,
"scannedBytes": 3569614,
"skippedFiles": 0
} |
e-l4, e-patch |
L5 |
inconclusive | the subject did not install, so there was nothing to activate
no overhead claim is made when the differential could not be completed metrics{
"samples": 0
} |
no evidence cited |
L6 |
skip | not run: the subject did not install
removal was not attempted because nothing was installed |
no evidence cited |
| capability | confidence | attribution | first evidence |
|---|---|---|---|
hooks_system_prompt | medium | unknown | package/dsh/plugin.mjs:320 |
listens_on_port | medium | build-output | package/dist/surfaces/mcp/server.js:588 |
network_egress | low | build-output | package/dist/routing/provider-adapters/anthropic.js:21 |
reads_secret_env | medium | build-output | package/dist/routing/provider-adapters/anthropic.js:9 |
spawns_process | medium | unknown | package/scripts/safe-postinstall.cjs:5 |
writes_outside_workspace | low | unknown | package/dsh/plugin.mjs:478 |
Capability is not intent. A signature records what the code can reach for, not what it does.
No overhead measurement was published for this report.
| id | kind | artifact |
|---|---|---|
e-resolve |
command exit 0 409 ms | resolve @roarpeng/graphflow@2.2.0 -> @roarpeng/graphflow@2.2.0
{
"name": "@roarpeng/graphflow",
"version": "2.2.0",
"registry": "https://registry.npmjs.org",
"tarball": "https://registry.npmjs.org/@roarpeng/graphflow/-/graphflow-2.2.0.tgz",
"advertisedIntegrity": "sha512-IyY6QjSNuQLojcV92qR44ILiXwu0n/yeaQDd0zzOC18iMRqybt1wIiI7FCcPmUDInlvLd4rEnM49AYsW/AF4NA==",
"publishedAt": "2026-10-02T12:48:41.890Z"
}
|
e-tarball |
artifact exit 0 109 ms | fetch https://registry.npmjs.org/@roarpeng/graphflow/-/graphflow-2.2.0.tgz
{
"bytes": 3266668,
"resolvedIntegrity": "sha512-IyY6QjSNuQLojcV92qR44ILiXwu0n/yeaQDd0zzOC18iMRqybt1wIiI7FCcPmUDInlvLd4rEnM49AYsW/AF4NA==",
"advertisedIntegrity": "sha512-IyY6QjSNuQLojcV92qR44ILiXwu0n/yeaQDd0zzOC18iMRqybt1wIiI7FCcPmUDInlvLd4rEnM49AYsW/AF4NA==",
"integrityMatchesRegistry": true,
"sha256": "c9fa6e2a74a0e367a4dbd37e997f31666ad825c334226e45ab60dfd6820ab168"
}
|
e-l0 |
static | read published package.json and verify declared dsh.bundle.patch paths exist
{
"status": "pass",
"reasons": [],
"declared": {
"manifestVersion": null,
"bundlePatch": [
"./cordis.patch.yml"
],
"clientPlatform": "web",
"enginesDsh": null,
"enginesNode": ">=20"
},
"missingPatchPaths": [],
"fileCount": 1204,
"unpackedBytes": 24261577,
"shipsSource": true
}
|
e-patch |
static | read cordis.patch.yml
# GraphFlow — DeepSeek Harness (dsh) 插件层
#
# 用法:
# dsh plugin --profile web add @roarpeng/graphflow
# npx @deepseek-ai/dsh web
# 或已有 ~/.dsh 时: npx @roarpeng/graphflow install
#
# 能力:
# 1) MCP 10 工具挂到 ctx.tools(cwd = 会话/工作区 process.cwd())。
# 模型侧名称: mcp__graphflow__graphflow_context / _plan / _run /
# _report_outcome / _insight / _index / _skill_insights /
# _diagnose / _artifact / _skill_guide
# 2) ESM glue `@roarpeng/graphflow/dsh`:ctx.skills.register(graphflow)
# (dsh plugin add 即可用 skill,不必先 graphflow install);
# agent/disposed 时不默认把 pending episode 标成成功(等同 Claude Code
# SessionEnd 空 $2 保持 pending)。显式 GRAPHFLOW_HOOK_SUCCESS=true|false
# 才调用 graphflow outcome report。不监听 live session/flush。
# 3) 首轮 agent/pre-step 注入一句短 hint:先调 graphflow_context(rootDir=cwd)。
#
# 调用约定: 先 context(传 rootDir),复杂任务再 plan;改完代码后 index;
# 若走了 run,结束后必须 report_outcome。不要写死 GRAPHFLOW_WORKSPACE_ROOT。
#
# graphflow install(无 profile 包时)只写 MCP 行到 $DSH_HOME/cordis.patch.yml;
# 已 `dsh plugin add` / profile 有包时会清空 home overlay,由 bundle 独占 MCP+glue
# (避免 duplicate loader entry id / ERR_MODULE_NOT_FOUND)。
# 完整安装请优先: dsh plugin --profile web add @roarpeng/graphflow
- insert:
- id: mcp-graphflow
name: '@deepseek-ai/dsh-mcp-client'
config:
serverName: graphflow
transport: stdio
command: npx
args:
- '-y'
- '--package=@roarpeng/graphflow'
- graphflow-mcp
env:
GRAPHFLOW_MCP_STDIO: '1'
GRAPHFLOW_LOG_JSON: '1'
cwd: !!js process.cwd()
failOnStartupError: false
- id: graphflow-dsh
name: '@roarpeng/graphflow/dsh'
|
e-l4 |
static | scan 588 shipped source file(s) for capability signatures
{
"present": [
{
"id": "hooks_system_prompt",
"confidence": "medium",
"attribution": "unknown",
"firstEvidence": {
"file": "package/dsh/plugin.mjs",
"line": 320,
"snippet": "\"system-prompt\","
}
},
{
"id": "listens_on_port",
"confidence": "medium",
"attribution": "build-output",
"firstEvidence": {
"file": "package/dist/surfaces/mcp/server.js",
"line": 588,
"snippet": "httpServer.listen(requestedPort, host, resolve);"
}
},
{
"id": "network_egress",
"confidence": "low",
"attribution": "build-output",
"firstEvidence": {
"file": "package/dist/routing/provider-adapters/anthropic.js",
"line": 21,
"snippet": "const response = await fetch(`${baseUrl}/v1/messages`, {"
}
},
{
"id": "reads_secret_env",
"confidence": "medium",
"attribution": "build-output",
"firstEvidence": {
"file": "package/dist/routing/provider-adapters/anthropic.js",
"line": 9,
"snippet": "const apiKey = process.env.ANTHROPIC_API_KEY;"
}
},
{
"id": "spawns_process",
"confidence": "medium",
"attribution": "unknown",
"firstEvidence": {
"file": "package/scripts/safe-postinstall.cjs",
"line": 5,
"snippet": "const { spawnSync } = require(\"node:child_process\");"
}
},
{
"id": "writes_outside_workspace",
"confidence": "low",
"attribution": "unknown",
"firstEvidence": {
"file": "package/dsh/plugin.mjs",
"line": 478,
"snippet": "export function resolveCliForCapture(packageRoot = PACKAGE_ROOT, home = process.env.HOME || process.env.USERPROFILE) {"
}
}
],
"scannedFiles": 588,
"skippedFiles": 0,
"limits": [
"the package ships build output; code inside a bundle cannot be reliably attributed to the author or to an inlined dependency",
"static analysis cannot see dynamically construct
|
e-l1-install |
command exit 1 4847 ms | dsh plugin --profile verify add @roarpeng/graphflow@2.2.0
Downloading gpt-tokenizer@3.4.0: 0.00 B/17.68 MB
Downloading onnxruntime-web@1.31.0-dev.20260914-8d85527a0: 0.00 B/33.18 MB
Downloading onnxruntime-node@1.30.0: 0.00 B/113.50 MB
Downloading @img/sharp-libvips-linux-x64@1.3.4: 0.00 B/8.21 MB
[WARN] 1 deprecated subdependencies found: prebuild-install@7.1.3
Downloading onnxruntime-node@1.30.0: 93.02 MB/113.50 MB
Packages are hard linked from the content-addressable store to the virtual store.
Content-addressable store is at: /home/verifier/.local/share/pnpm/store/v11
Virtual store is at: node_modules/.pnpm
Packages: +186
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Progress: resolved 185, reused 0, downloaded 188, added 186, done
dependencies:
+ @roarpeng/graphflow 2.2.0
dsh: initialized profile verify at /work/dsh-home/profiles/verify
Error: ERR_PNPM_IGNORED_BUILDS
× adding a new package
╰─▶ Ignored build scripts: @roarpeng/graphflow@2.2.0, better-
sqlite3@12.11.1, onnxruntime-node@1.30.0, protobufjs@7.6.6
help: Run "pnpm approve-builds" to pick which dependencies should be allowed
to run scripts.
dsh: plugin command failed; diagnostics: /work/dsh-home/profiles/verify/.plugin-manager/logs/operation-1SeoeV/pnpm.log
|