Skip to main content
Glama
dongsheng123132

dsh-audit-bundle

dsh-audit-bundle

CI MIT license Node.js 22+ Awesome DSH Plugins

Content-addressed audit indexes across independent DeepSeek Harness evidence producers.

This plugin is not an SBOM scanner, signer, audit logger, policy engine or archive. Existing tools already scan dependencies and individual 2Origin plugins already produce release, runtime, recovery, lineage and policy evidence. The missing layer is a small verifier that proves a particular subject/revision has enough pinned evidence from allowed, independent producers to cover declared controls.

Contract

An explicit manifest declares:

  • one subject ID and revision;

  • required controls with minimum eligible evidence, minimum distinct producers and allowed evidence types;

  • evidence files pinned by SHA-256;

  • JSON Pointers that bind every evidence file to the subject and revision;

  • value-hash assertions, so expected or observed values never enter the audit index.

Verification fails closed for missing, stale or invalid JSON evidence, subject/revision mismatch, failed assertions, disallowed types, insufficient evidence or insufficient independent producers. The output contains IDs, types, producers, paths into JSON, hashes, statuses, coverage and a deterministic SHA-256 pair-tree Merkle root. It never copies evidence bodies or assertion values.

Files must be workspace-relative regular files. Symlinks, path escape, oversized input and excessive structure are rejected. The plugin performs no network calls or child processes and writes only a content-addressed JSON index under the explicit artifactDir, followed by read-back verification.

Related MCP server: hivelaw

CLI

node bin/dsh-audit-bundle.mjs inspect --workspace examples/basic --manifest audit.manifest.json
node bin/dsh-audit-bundle.mjs verify --workspace examples/basic --manifest audit.manifest.json --artifactDir artifacts

The CLI emits one JSON object. A failed audit verdict exits 2; invalid usage exits 1.

DeepSeek Harness and MCP

The DSH bundle registers dsh_audit_bundle_inspect and dsh_audit_bundle_verify. The companion stdio MCP server registers audit_bundle_inspect and audit_bundle_verify through .mcp.json.

dsh plugin --profile audit-bundle add github:dongsheng123132/dsh-audit-bundle#<commit>
dsh --profile audit-bundle --dump-config

Verification

npm ci
npm test
npm run check
npm run smoke:mcp
DSH_CHECKOUT=/path/to/built/deepseek-harness npm run smoke:dsh
python C:/Users/ZhuanZ/.codex/skills/.system/plugin-creator/scripts/validate_plugin.py .

CI runs on Ubuntu and Windows. Node.js 22 or newer. MIT licensed.

A
license - permissive license
-
quality - not tested
C
maintenance

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    A
    quality
    B
    maintenance
    MCP server for offline verification of signed artifacts — receipts, manifests, and audit bundles. MIT licensed, works without accounts or API calls. Tools: self_test, verify_receipt, verify_bundle, explain_artifact.
    4
    105
    5
    Apache 2.0
  • A
    license
    -
    quality
    C
    maintenance
    MCP server for AI compliance auditing. Scores agent outputs for hallucination liability under the EU AI Act, issues verifiable compliance stamps, and tracks audit history by agent.
    MIT
  • A
    license
    -
    quality
    C
    maintenance
    Evidence-first delivery audit MCP server that evaluates task requirements against delivery evidence and returns a reproducible pass/needs_review/fail decision with a deterministic receipt.
    MIT

View all related MCP servers

Related MCP Connectors

  • Remote MCP for C2PA intake verifier MCP, structured receipts, audit logs, and reviewer-ready evidenc

  • MCP Spec Compliance MCP — audits any MCP server.json against the official Model Context Protocol

  • Scans MCP servers for tool poisoning, prompt injection and supply chain risks.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/dongsheng123132/dsh-audit-bundle'

If you have feedback or need assistance with the MCP directory API, please join our Discord server