onlyqzq/dsh-riskproof
Risk-aware approval layer for high-risk AI Agent tool calls
项目介绍Project Overview
RiskProof 是 DSH 的溯源感知执行安全插件,挂载工具运行时,追踪工具输入来源与跨工具污点流,在副作用发生前允许、询问或拒绝。适用于网页内容、客户数据、外发动作串联等风险链路检测。它不替代沙箱、防火墙或完整 DLP。
RiskProof is a provenance-aware execution-security plugin for DSH. It hooks the tool runtime, maps tool arguments to their source results, propagates taint labels across calls, and allows, asks, or denies before side effects run. Use it to detect risky cross-tool flows such as web ingestion leading to private data access and external actions. It does not replace sandboxing, firewalls, or full semantic DLP.
请帮我了解并安装插件:【dsh-riskproof】【https://github.com/onlyqzq/dsh-riskproof】
把上面这条消息直接发给当前会话里的 DSH,让它帮你了解并安装。安装命令不一定准确,发给 DSH 更稳。Send this message to DSH in your current session. CLI install commands may not be accurate across systems — DSH will figure it out for you.
或使用命令行安装(适合开发者)Or use CLI install (for developers)
命令行安装CLI Install
dsh plugin --profile web add dsh-riskproof
把 onlyqzq/dsh-riskproof 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
RiskProof
Provenance-aware execution security for DeepSeek Harness.
Track where tool inputs came from. Detect risky cross-tool data flows. Stop sensitive side effects before execution.
What RiskProof answers
Most tool-permission plugins answer one question: is this tool allowed?
RiskProof answers a different one:
Where did the data in this tool call come from, what did it flow through, and where is it about to go?
A single tool call is usually safe. The composition is not.
web_fetch ← UNTRUSTED_WEB
│
database_query ← CUSTOMER_DATA
│
send_email ← external destination
│
RiskProof → DENY (evidence-backed, before the side effect)
Why RiskProof
| Permission rules | RiskProof |
|---|---|
| Is this tool allowed? | Where did this data come from? |
| Single call | Cross-tool flow |
| Tool name | Provenance + taint |
| Static rule | Stateful attack chain |
| Permission decision | Evidence-backed execution decision |
RiskProof is a layer over the DSH Tool Runtime, not another Agent Runtime. It never re-implements tool dispatch, approval, or lifecycle — it observes and decides.
Quick Start
# add the plugin to a DSH profile
dsh plugin --profile <profile> add dsh-riskproof
# confirm the bundled patch was composed
dsh --profile <profile> --dump-config
The package declares a DSH bundle, so plugin add composes its riskproof row automatically. No second install or manual row is required. The schema defaults are safe; RiskProof silently tracks context and only asks or blocks when a risky cross-tool flow appears.
To tune it, override the bundled row from the profile's later cordis.patch.yml layer:
- id: riskproof
config:
mode: enforce # enforce | observe
policy:
preset: balanced # permissive | balanced | strict
internalDomains: [acme.internal]
blockedDomains: [collector.evil.example]
# allowedExternalDomains: [api.approved.example]
classification:
overrides:
gmail_send: [EXTERNAL_ACTION]
company_db: [PRIVATE_ACCESS]
See docs/configuration.md for the full reference.
See it work
sequenceDiagram
participant A as Agent
participant T as DSH ToolRuntime
participant R as RiskProof
A->>T: web_fetch(url)
T->>R: tools/pre-execute
R-->>T: allow (EXTERNAL_INGESTION recorded)
T-->>A: untrusted content
A->>T: database_query(sql)
T->>R: tools/pre-execute
R-->>T: ask (operator approves private access)
T-->>A: CUST-8842 balance 125000
A->>T: send_email(to=external, body=CUST-8842…)
T->>R: tools/pre-execute
R-->>T: DENY — ingestion + private access + sensitive data + external action
T-->>A: Error: <reason>
The same flow is reproduced as a deterministic regression test in tests/security/attack-chain.test.ts.
Try it locally with no model or profile — a real DSH ToolRuntime pipeline with three mock tools:
npm run demo
See demo/README.md.
Features
Track data origin
Know where tool inputs came from. RiskProof maps arguments back to the tool results that produced them.
Follow sensitive data
Carry security labels — UNTRUSTED_WEB, CUSTOMER_DATA, PII, SECRET, … — across tool calls, additively.
Detect attack chains
Identify the EXTERNAL_INGESTION → PRIVATE_ACCESS → EXTERNAL_ACTION pattern that single-tool checks miss.
Stop before execution
Block or ask before the side effect runs, through the native tools/pre-execute gate.
Guard sensitive surfaces
Gate credential-file paths, high-confidence destructive commands, download-and-execute pipelines, blocked destinations, and credentials embedded in network-capable commands.
Adapt without rewriting rules
Start with the default balanced preset, roll out with permissive, or use strict; every configurable decision can still be overridden individually.
Explain every decision
Generate structured, privacy-preserving security evidence and actionable remediation for every decision. Keep proofs in memory or append them to an operator-controlled JSONL file.
How it works
RiskProof hooks the native DSH tool pipeline:
tools/pre-execute
│ capability classification
│ argument provenance mapping
│ taint analysis
│ toolchain state (EIT → PAT → NAT)
│ deterministic policy evaluation
▼
allow / ask / deny (monotonic with other plugins)
│
tools/result
│ update ContextTracker
│ update Toolchain state
▼ record execution evidence
- Classification is deterministic (tool name + description + schema), configurable, and never uses an LLM.
- Provenance uses exact and bounded substring matching over a per-session context index.
- Taint is additive; ordinary tool output can never remove a label.
- Decisions are deterministic, explainable, and testable.
See docs/architecture.md.
Security boundaries
RiskProof protects supported observable tool-call flows through DSH:
- DSH tool calls through the supported
tools/pre-execute/tools/resultpaths - supported observable provenance (exact / bounded substring matching)
- configured sensitive flows and cross-tool attack patterns
RiskProof does not replace:
- OS sandbox / process isolation
- network firewall / SSRF protection
- endpoint security / malware scanning
- credential vaults
- full semantic DLP
See docs/security-model.md for the complete threat model and known limitations.
Documentation
- Installation
- Architecture
- Security model
- Provenance & taint
- Toolchain model
- Configuration
- Development
- v0.2 security-plugin benchmark
- Awesome DSH Plugin review alignment
- Migrating from RiskProof (MCP)
Roadmap
v0.2 (current)
- DSH-native runtime (
tools/pre-execute,tools/result) - Provenance + taint tracking
- Cross-tool EIT → PAT → NAT detection
- Privacy-preserving proof with optional JSONL persistence
- Policy presets, sensitive-path gates, deterministic command-risk checks, and egress domain policy
- Remediation guidance and per-rule proof statistics
v0.3
- Tool identity continuity
- Task-aware policy
- Execution receipts
Later
- Output-side information-flow control
- Trusted declassification
Contributing
Issues, rule submissions, tool-capability mappings, and false-positive reports are welcome. See CONTRIBUTING.md.
Security reporting
Please report vulnerabilities privately. See SECURITY.md.
nexu-io/open-design
freestylefly/awesome-gpt-image-2
anywhere-labs/dsh-desktop
walkinglabs/learn-harness-engineering
awesome-dsh-plugin/awesome-dsh-plugin
MemTensor/MemOS