DSH HUB
HomePlugin StorePlugin PacksCommunityRankingsResourcesPublish Guide
Plugin source
Back to catalog

onlyqzq /

onlyqzq/dsh-riskproof

Verified

Risk-aware approval layer for high-risk AI Agent tool calls

★ 1 Stars0 Forks0 IssuesN/A Community rating0 Confirmed installs
View on GitHub
READMESource: main@a084a1a3

RiskProof

Provenance-aware execution security for DeepSeek Harness.

Track where tool inputs came from. Detect risky cross-tool data flows. Stop sensitive side effects before execution.

English · 简体中文


What RiskProof answers

Most tool-permission plugins answer one question: is this tool allowed?

RiskProof answers a different one:

Where did the data in this tool call come from, what did it flow through, and where is it about to go?

A single tool call is usually safe. The composition is not.

web_fetch          ← UNTRUSTED_WEB
   │
database_query     ← CUSTOMER_DATA
   │
send_email         ← external destination
   │
RiskProof → DENY   (evidence-backed, before the side effect)

Why RiskProof

Permission rules RiskProof
Is this tool allowed? Where did this data come from?
Single call Cross-tool flow
Tool name Provenance + taint
Static rule Stateful attack chain
Permission decision Evidence-backed execution decision

RiskProof is a layer over the DSH Tool Runtime, not another Agent Runtime. It never re-implements tool dispatch, approval, or lifecycle — it observes and decides.

Quick Start

# add the plugin to a DSH profile
dsh plugin --profile <profile> add dsh-riskproof

# confirm the bundled patch was composed
dsh --profile <profile> --dump-config

The package declares a DSH bundle, so plugin add composes its riskproof row automatically. No second install or manual row is required. The schema defaults are safe; RiskProof silently tracks context and only asks or blocks when a risky cross-tool flow appears.

To tune it, override the bundled row from the profile's later cordis.patch.yml layer:

- id: riskproof
  config:
    mode: enforce            # enforce | observe
    policy:
      preset: balanced         # permissive | balanced | strict
      internalDomains: [acme.internal]
      blockedDomains: [collector.evil.example]
      # allowedExternalDomains: [api.approved.example]
    classification:
      overrides:
        gmail_send: [EXTERNAL_ACTION]
        company_db: [PRIVATE_ACCESS]

See docs/configuration.md for the full reference.

See it work

sequenceDiagram
    participant A as Agent
    participant T as DSH ToolRuntime
    participant R as RiskProof

    A->>T: web_fetch(url)
    T->>R: tools/pre-execute
    R-->>T: allow (EXTERNAL_INGESTION recorded)
    T-->>A: untrusted content

    A->>T: database_query(sql)
    T->>R: tools/pre-execute
    R-->>T: ask (operator approves private access)
    T-->>A: CUST-8842 balance 125000

    A->>T: send_email(to=external, body=CUST-8842…)
    T->>R: tools/pre-execute
    R-->>T: DENY — ingestion + private access + sensitive data + external action
    T-->>A: Error: <reason>

The same flow is reproduced as a deterministic regression test in tests/security/attack-chain.test.ts.

Try it locally with no model or profile — a real DSH ToolRuntime pipeline with three mock tools:

npm run demo

See demo/README.md.

Features

Track data origin

Know where tool inputs came from. RiskProof maps arguments back to the tool results that produced them.

Follow sensitive data

Carry security labels — UNTRUSTED_WEB, CUSTOMER_DATA, PII, SECRET, … — across tool calls, additively.

Detect attack chains

Identify the EXTERNAL_INGESTION → PRIVATE_ACCESS → EXTERNAL_ACTION pattern that single-tool checks miss.

Stop before execution

Block or ask before the side effect runs, through the native tools/pre-execute gate.

Guard sensitive surfaces

Gate credential-file paths, high-confidence destructive commands, download-and-execute pipelines, blocked destinations, and credentials embedded in network-capable commands.

Adapt without rewriting rules

Start with the default balanced preset, roll out with permissive, or use strict; every configurable decision can still be overridden individually.

Explain every decision

Generate structured, privacy-preserving security evidence and actionable remediation for every decision. Keep proofs in memory or append them to an operator-controlled JSONL file.

How it works

RiskProof hooks the native DSH tool pipeline:

tools/pre-execute
    │  capability classification
    │  argument provenance mapping
    │  taint analysis
    │  toolchain state (EIT → PAT → NAT)
    │  deterministic policy evaluation
    ▼
allow / ask / deny   (monotonic with other plugins)
    │
tools/result
    │  update ContextTracker
    │  update Toolchain state
    ▼  record execution evidence
  • Classification is deterministic (tool name + description + schema), configurable, and never uses an LLM.
  • Provenance uses exact and bounded substring matching over a per-session context index.
  • Taint is additive; ordinary tool output can never remove a label.
  • Decisions are deterministic, explainable, and testable.

See docs/architecture.md.

Security boundaries

RiskProof protects supported observable tool-call flows through DSH:

  • DSH tool calls through the supported tools/pre-execute / tools/result paths
  • supported observable provenance (exact / bounded substring matching)
  • configured sensitive flows and cross-tool attack patterns

RiskProof does not replace:

  • OS sandbox / process isolation
  • network firewall / SSRF protection
  • endpoint security / malware scanning
  • credential vaults
  • full semantic DLP

See docs/security-model.md for the complete threat model and known limitations.

Documentation

  • Installation
  • Architecture
  • Security model
  • Provenance & taint
  • Toolchain model
  • Configuration
  • Development
  • v0.2 security-plugin benchmark
  • Awesome DSH Plugin review alignment
  • Migrating from RiskProof (MCP)

Roadmap

v0.2 (current)

  • DSH-native runtime (tools/pre-execute, tools/result)
  • Provenance + taint tracking
  • Cross-tool EIT → PAT → NAT detection
  • Privacy-preserving proof with optional JSONL persistence
  • Policy presets, sensitive-path gates, deterministic command-risk checks, and egress domain policy
  • Remediation guidance and per-rule proof statistics

v0.3

  • Tool identity continuity
  • Task-aware policy
  • Execution receipts

Later

  • Output-side information-flow control
  • Trusted declassification

Contributing

Issues, rule submissions, tool-capability mappings, and false-positive reports are welcome. See CONTRIBUTING.md.

Security reporting

Please report vulnerabilities privately. See SECURITY.md.

License

Apache-2.0

—/ 5

No ratings yet

Verified DSH bundle

Commit a084a1a3711c

Community comments

No comments yet. Be the first to write one.

DSH HUB

A community index for DSH plugins. Not an official GitHub or DeepSeek AI product.

CommunityResourcesAPIAbout