dongsheng123132/dsh-windows-readiness-proof

dongsheng123132★ 1JavaScriptLast synced: 2026-08-14

Open on GitHub

Content-addressed readiness proof for sanitized DeepSeek Harness observations on managed Windows hosts

README excerpt

dsh-windows-readiness-proof dsh-windows-readiness-proof evaluates a SHA-256-pinned, sanitized observation of a managed Windows host against explicit DeepSeek Harness readiness requirements. It is an evidence verifier, not a collector or remediation tool. It never runs PowerShell, reads the registry, changes Group Policy, creates Defender exclusions, edits WDAC/AppLocker, installs software, restarts services, or probes the network. What it proves An explicit manifest fixes an opaque machine digest, snapshot revision, observation bytes, evaluation time, maximum evidence age, and requirements for: - Windows product type, architecture, build, and pending reboot; - Node, DSH, PowerShell edition/version, and language mode; - classified WDAC, AppLocker, Defender, execution policy, Credential Guard, and TLS 1.2 posture; - long paths, atomic rename, workspace/temp ACL class, and symlink policy; - non-interactive session, opaque identity class, writable profile, and recovery configuration; - free workspace/temp storage; - required connectivity identities represented only by endpoint SHA-256 plus status/TLS/proxy classes. Missing, stale, future, malformed, secret-shaped, identity-bearing, pat…

View full README on GitHub →
Agentsai-agentdeepseek-harnessdshdsh-pluginenterpriseevidencereadinesswindows

Category