dsh-audit-bundle
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@dsh-audit-bundleVerify the audit manifest for the current workspace."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
dsh-audit-bundle
Content-addressed audit indexes across independent DeepSeek Harness evidence producers.
This plugin is not an SBOM scanner, signer, audit logger, policy engine or archive. Existing tools already scan dependencies and individual 2Origin plugins already produce release, runtime, recovery, lineage and policy evidence. The missing layer is a small verifier that proves a particular subject/revision has enough pinned evidence from allowed, independent producers to cover declared controls.
Contract
An explicit manifest declares:
one subject ID and revision;
required controls with minimum eligible evidence, minimum distinct producers and allowed evidence types;
evidence files pinned by SHA-256;
JSON Pointers that bind every evidence file to the subject and revision;
value-hash assertions, so expected or observed values never enter the audit index.
Verification fails closed for missing, stale or invalid JSON evidence, subject/revision mismatch, failed assertions, disallowed types, insufficient evidence or insufficient independent producers. The output contains IDs, types, producers, paths into JSON, hashes, statuses, coverage and a deterministic SHA-256 pair-tree Merkle root. It never copies evidence bodies or assertion values.
Files must be workspace-relative regular files. Symlinks, path escape, oversized input and excessive structure are rejected. The plugin performs no network calls or child processes and writes only a content-addressed JSON index under the explicit artifactDir, followed by read-back verification.
Related MCP server: hivelaw
CLI
node bin/dsh-audit-bundle.mjs inspect --workspace examples/basic --manifest audit.manifest.json
node bin/dsh-audit-bundle.mjs verify --workspace examples/basic --manifest audit.manifest.json --artifactDir artifactsThe CLI emits one JSON object. A failed audit verdict exits 2; invalid usage exits 1.
DeepSeek Harness and MCP
The DSH bundle registers dsh_audit_bundle_inspect and dsh_audit_bundle_verify. The companion stdio MCP server registers audit_bundle_inspect and audit_bundle_verify through .mcp.json.
dsh plugin --profile audit-bundle add github:dongsheng123132/dsh-audit-bundle#<commit>
dsh --profile audit-bundle --dump-configVerification
npm ci
npm test
npm run check
npm run smoke:mcp
DSH_CHECKOUT=/path/to/built/deepseek-harness npm run smoke:dsh
python C:/Users/ZhuanZ/.codex/skills/.system/plugin-creator/scripts/validate_plugin.py .CI runs on Ubuntu and Windows. Node.js 22 or newer. MIT licensed.
This server cannot be installed
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityBmaintenanceMCP server for offline verification of signed artifacts — receipts, manifests, and audit bundles. MIT licensed, works without accounts or API calls. Tools: self_test, verify_receipt, verify_bundle, explain_artifact.41055Apache 2.0
- Alicense-qualityCmaintenanceMCP server for AI compliance auditing. Scores agent outputs for hallucination liability under the EU AI Act, issues verifiable compliance stamps, and tracks audit history by agent.MIT
- AlicenseAqualityBmaintenanceMCP server for verifying high-impact decisions with Trust OS.2MIT
- Alicense-qualityCmaintenanceEvidence-first delivery audit MCP server that evaluates task requirements against delivery evidence and returns a reproducible pass/needs_review/fail decision with a deterministic receipt.MIT
Related MCP Connectors
Remote MCP for C2PA intake verifier MCP, structured receipts, audit logs, and reviewer-ready evidenc
MCP Spec Compliance MCP — audits any MCP server.json against the official Model Context Protocol
Scans MCP servers for tool poisoning, prompt injection and supply chain risks.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/dongsheng123132/dsh-audit-bundle'
If you have feedback or need assistance with the MCP directory API, please join our Discord server