dsh-build-hermeticity-proof
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@dsh-build-hermeticity-proofVerify the hermeticity of ./receipts/build.json"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
DSH Build Hermeticity Proof
An offline, deterministic evidence layer for DeepSeek Harness supply chains. It verifies whether an explicit, hash-only build access receipt stayed inside its declared file, environment, network, clock, randomness and output closure.
It does not execute a build, does not enforce a sandbox, authenticate the receipt, or prove that unrecorded accesses could not occur. It also does not prove reproducibility. A hermetic verdict means only that the supplied receipt is internally complete and policy-conformant.
Complementary boundary
dsh-reproducible-build-proofcompares independently operated rebuild receipts for byte-identical specified outputs.dsh-attestation-proofverifies DSSE/in-toto signatures, subjects and signer thresholds.This plugin checks one recorded build's declared external-influence closure: file reads/writes, environment reads, network, clock and randomness.
Observed undeclared access fails. A denied undeclared attempt is retained as containment evidence but does not breach the closure. Observed network access always fails under the v1 deny-only network policy. Declared inputs and outputs must all appear in the receipt; the source revision, invocation, clock value, random seed and allowed environment values are hash-bound.
Related MCP server: dsh-artifact-promotion-proof
Install
dsh plugin add github:dongsheng123132/dsh-build-hermeticity-proof#COMMITThe bundle exposes dsh_build_hermeticity_inspect and dsh_build_hermeticity_verify from one headless core. The independent MCP stdio server exposes build_hermeticity_inspect and build_hermeticity_verify. The CLI accepts inspect or verify plus an explicit JSON path.
See examples/hermetic.json. Reports contain only hashes, counts, booleans, classifications and verdicts. Secret-shaped material, raw logs and body/content fields are rejected. The DSH verify tool reads a workspace-relative non-symlink manifest, writes only to an explicit workspace-relative artifactDir, creates deterministic content-addressed output exclusively, and verifies it by read-back.
npm test
npm run check
npm run smoke:plugin
npm run smoke:mcp
python C:/Users/YOU/.codex/skills/.system/plugin-creator/scripts/validate_plugin.py .Node.js 22 or newer is required. The verifier has no runtime dependency, spawns no process and makes no network request.
This server cannot be deployed
Maintenance
Related MCP Connectors
Verifies Bernstein run receipts and hash chains; lists the shipped presets and adapters. Read-only.
Capture a web source, or seal a hash you hold, into a signed receipt anyone can verify offline.
Pre-flight MCP security. Blocks compromised deps + tool drift. HMAC-signed. Dredd judges.
Read-only verifier for 25 ProofRelay MCP tools and non-confidential evidence bundles.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceEnables verification of content-addressed settlement receipts for DSH Loader activation, injection closure, and tool schema settlement.MIT
- AlicenseNot gradedqualityCmaintenanceEnables offline, deterministic verification that one immutable artifact followed a declared build-to-production promotion chain, using only hash-based evidence and failing closed on incomplete or nonconformant gate records.MIT
- AlicenseNot gradedqualityCmaintenanceEnables offline verification that a supplied DSH workflow adhered to declared duty-separation constraints, producing a redacted, content-addressed JSON verdict.MIT
- AlicenseNot gradedqualityCmaintenanceOffers proof-only tools to inspect and verify remediation closure receipts, deterministically confirming asset coverage, fixed artifact deployment, rescanning, deadline compliance, and zero-residual closure without executing scans or touching live systems.MIT