auditrail
Security auditing and session forensics bundle for DeepSeek Harness with SQLite persistence, redaction, and replay.
Install
$ dsh plugin --profile <name> add /path/to/dsh-plugin/auditrailPlugin Overview & Capabilities
AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.
Key Capabilities
- Records full tool invocation chains including actors, timestamps, commands, files accessed, network targets, status, and duration
- Evaluates built-in and configurable sensitive operation rules to flag risky actions like rm -rf, privilege escalation, or key access
- Applies secret masking, argument truncation, and privacy redaction before persisting records
- Stores audit trails in SQLite using WAL mode and SHA-256 hash chaining to detect tampering
- Provides model-facing tools for querying, exporting (JSON, Markdown, JSONL), inspecting policies, and generating plain-text replays
- Includes a standalone auditrail CLI for offline verification, stats, replay, and policy checks
Useful For
- Security compliance and forensic analysis of automated DeepSeek Harness tool execution
- Tamper-evident auditing of multi-step model workflows and file/network interactions
- Incident investigation and plain-text terminal replay of agent sessions without web UI dependencies
Who It Fits
- Security engineers and compliance officers auditing agent operations
- DeepSeek Harness developers needing full visibility into tool dispatch and sensitive command usage
- DevOps and SRE teams running production Harness environments
Documented Limitations
- Requires Node.js 22.13 or newer due to reliance on built-in node:sqlite
- CLI-level policy additions or modifications are process-scoped and runtime-only unless configured via dsh profile settings
DSH Compatibility
Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.
Security Signals
Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.
package.json declares 0 runtime, 4 development, 2 peer, and 0 optional dependencies.
package.json declares DSH bundle metadata.
GitHub reports the repository license as MIT.
A root package.json was captured and can be inspected by the registry.
Public GitHub source metadata is available for this registry snapshot.
Source & Registry Notes
Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.
- Source repository
- JohnXu22786/auditrail
- Registry source
- GitHub · dsh-plugin topic
- Registry classification
- Plugin Bundle
- Source checked
- 0d7d995 · 2026-09-30
This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.
Repository Activity
- GitHub stars
- 1GitHub stars
- Forks
- 0
- Open issues
- 0
- Last commit
- 2026-09-30
- Last release
- No release detected
Related DSH Plugins
Ranked by overlapping capabilities, use cases, plugin type, categories, and DSH profile.
Second-model AI auto-review for DeepSeek Harness approval requests with fail-closed safety and session audit.
View plugin →Native SQLite-backed local project taskboard plugin and UI for DeepSeek Harness with Agent claim and review flows.
View plugin →Persistent multi-model Agent teams and bounded DAG workflows with GUI controls for DeepSeek Harness.
View plugin →Preview, create, and edit spreadsheets, docs, slides, and canvases in DeepSeek Harness powered by Univer.
View plugin →