Skip to content
dsh.fish
Bundle

@dsh-io/identity-sentinel

Performance-art dsh plugin: the machine inspects its owner; non-Chinese verdicts terminate all workflows. Installing = informed consent.

Source
dsh-io
License
MIT
Updated
Updated 14 days ago

Readme

# Identity Sentinel · 身份哨兵

> **⚠ CONSENT / 知情同意:** Installing this plugin means you have read this README and agree:
> the plugin inspects your machine's local signals (locale, language, timezone, keyboard layout,
> region format — all purely local, **zero network requests**). If the composite verdict is
> "not Chinese" (mainland / Hong Kong / Macau / Taiwan), the plugin **terminates all workflows**.
> If the verdict is Chinese, it does nothing. 安装本插件即视为已知情并同意上述行为。

**THIS IS A PERFORMANCE ART PIECE.** This is not security tooling and not policy. It is a mirror
held up to the idea that a machine can — or should — judge the nationality of its operator.

## How it works

1. On startup the plugin collects **four local signals** — never sent anywhere:
   - `locale` — system language / locale (`LC_ALL`, `LC_CTYPE`, `LANG`, Intl locale)
   - `timezone` — e.g. `Asia/Shanghai`, `Asia/Hong_Kong`, `Asia/Taipei`, `Asia/Macau`
   - `keyboard` — keyboard layout (`XKBLAYOUT` on Linux, `defaults` on macOS, registry on Windows)
   - `region` — region part of the Intl locale (`CN`, `HK`, `MO`, `TW`)
2. Signals are aggregated into an identity profile with a confidence score.
3. A weighted rule engine renders a verdict:
   - `non-cn` signals `>= threshold` (default **2**) and `forceTerminate` on → **terminate**
   - otherwise → **pass** (nothing happens)
4. On `terminate`: an art banner, the manifesto, and a termination declaration are printed;
   the process exits with code 1. On `pass`: a banner is printed and a single introspection tool
   (`system_identity`) is registered — nothing else changes.

Ambiguous or undetectable signals never count toward the threshold. Each failing collector
degrades gracefully and is logged.

## Install

```bash
# via the dsh plugin manager
dsh plugin add <path-to-this-package>

# or with a patch overlay on the web profile
npx @deepseek-ai/dsh --profile web --patch <abs-path>/cordis.patch.yml
```

**pnpm users** need the upstream peer fix (the official `latest` train still declares the
unpublished `@deepseek-ai/dsh-type-meta` — see
[deepseek-harness discussion #2862](https://github.com/deepseek-ai/deepseek-harness/discussions/2862)):

```yaml
# pnpm-workspace.yaml
overrides:
  "@deepseek-ai/dsh-type-meta": "npm:@deepseek-ai/dsh-invariants@0.0.1-rc.1"
```

## Tool

`system_identity` — asks the machine for its current verdict about its owner:
identity (`cn` / `non-cn` / `unknown`), action, confidence, and the full signal list.

## Embed

The core is a **zero-dependency pure-function library** — import it from any project:

```ts
import {
  collectSystemLocale, collectTimezone, collectKeyboard, collectRegion,
  aggregateIdentity, decide, renderArt,
} from '@dsh-io/identity-sentinel'
```

## Configuration

| Option | Type | Default | Meaning |
|---|---|---|---|
| `threshold` | number | 2 | Non-CN signals required to terminate |
| `artMode` | boolean | true | Print the art banners |
| `forceTerminate` | boolean | true | Actually exit (code 1) on a non-CN verdict; `false` = banners only |

## License

MIT © 2026 dsh-io

Install

dsh plugin --profile web add github:dsh-io/identity-sentinel

Profile: web

  • This package builds from source on install. pnpm will ask you to allow its build script — that is permission to run the package’s code on your machine, outside the agent sandbox. Only allow sources you trust.
  • This source has no pinned commit, so a later push upstream changes what installs. Prefer pinning a commit.
Source