Overview
@aaronandwork/dsh-evidence-gate
README / EN
Package documentation
Registry summary
dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.
Read the full README on GitHubLIMITATIONS
Known limitations
- The policy is a **probabilistic constraint, not a hard guarantee** — nothing in the harness can intercept final prose. The gate + cross-check + visible ledger is the practical optimum at this layer. - The cross-check only sees what passed through the `tools/result` stream **while the plugin was loaded**; with an empty index, first-hand claims fall through cross-session lookup and the existence floor before failing closed. - Cross-check is corroboration, not truth: a real command run for an unrelated reason can still match, and a determined agent can cite a real path. It raises the cost of lying, it does not make lying impossible. - A tool execution that carries **no session identity** falls into a single shared bucket (the host log warns once when this happens). With multiple main sessions, that bucket is shared across them — if you ever see the warning, report which action produced it. - Deployments sharing one `DSH_HOME` (e.g. several profiles) share the store file (last write wins per 1.5s debounce).
