bailong-Hakuryu/dsh-security-assurance0

dsh-security-assurance

Evidence-backed application-security assurance for DeepSeek Harness

包名
dsh-security-assurance
版本
0.1.0-rc.9
许可证
MIT
最近更新
2026年8月31日

安装

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:bailong-Hakuryu/dsh-security-assurance

DSH Security Assurance

DSH Security Assurance is an independent DeepSeek Harness plugin for evidence-backed application-security assessment. It integrates through public Harness and Cordis seams and does not modify Harness Core.

v0.1 release candidate status

Version 0.1.0-rc.9 is the directly usable v0.1 candidate for Harness 0.1.2-alpha.1. It is intended for acceptance and release-gate verification. Stable 0.1.0 promotion is limited to version, signature, and release metadata after the exact candidate artifact passes every required gate; no unqualified behavior change may be folded into that promotion. The candidate proves:

  • dormant bundle installation metadata;
  • real Cordis registration at ctx.securityAssurance;
  • an opaque, runtime-verified Security Invocation boundary;
  • authorized Runtime Health, Repository Registry, Assessment start/query/wait, effective Security Catalog and digest-bound Start Preflight, Finding Summary and Detail, purpose-bound Evidence View, Bundle Manifest, and Assurance Submission operations;
  • an independently activatable dsh-security-assurance/tools Consumer with bounded security_repositories, security_catalog, security_assessment_start, read-only security_assessment_status and security_assessment_findings, and revision-bound security_assessment_resume and security_assessment_cancel, plus bounded security_assessment_export model tools. They derive the exact live Harness session outside model arguments, mint one operation-specific permission, and delegate all Assessment validation, pagination, redaction, recovery, cancellation, delivery, and state transitions to the root Service;
  • versioned Zod-validated public contracts;
  • a side-effect-free dsh-security-assurance/evaluation entry containing the first pure versioned Metrics Engine slice. It calculates Critical/High and severity-weighted Validated Recall, Validated Precision, Unsafe Satisfaction Rate, and Coverage Honesty Rate from strict independently adjudicated Evaluation evidence;
  • one SecurityResult success/failure envelope;
  • redacted authorization, validation, cancellation, deadline, and internal failures;
  • a plugin-private SQLite Registry with immutable revisions, idempotent Receipts, exact Revision CAS, fail-closed startup validation, and restart recovery;
  • explicit register, get, list, update, and non-destructive disable behavior;
  • a trusted dsh-security-assurance/host-repository-provider composition entry that registers Host configuration through the root Service and resolves only immutable path-free Repository bindings;
  • a package-owned dsh-security-assurance/workbench-remote Host Adapter plus generated strict dsh-security-assurance/typert and dsh-security-assurance/remote artifacts. Its headless Workbench slice exposes authority-projected Runtime Health, Repository and Assessment selection, effective getHealth, getCatalog, digest-bound startAssessment, exact getAssessment, integrity-verified getBundleManifest, path-free getRepository, revision-bound Finding queries, strict metadata-only getEvidenceView, separate expiring discloseEvidence, bounded waitForAssessmentRevision, and revision-bound, idempotent recordRiskDecision, resumeAssessment, and cancelAssessment without putting a Principal, permissions, or Security Invocation on the wire;
  • legacy Workbench browser source retained for future migration, but deliberately excluded from the 0.1.0-rc.9 package because Harness 0.1.2-alpha.1 no longer publishes the client-runtime preset it was built against. Direct Web users instead receive Harness's generic cards for the eight registered model tools. The legacy source previously provided one transient ctx.securityAssuranceWorkbench Controller. It opens authenticated Runtime Health, redacted Repository and Assessment selectors, builds the New Assessment Wizard only from Catalog choices, confirms immutable Start Preflight proposals, fetches immutable Snapshots, follows committed revisions through cancellable long-polling, fences stale responses and disclosure attempts, opens metadata only from an exact Finding Evidence Link, separately reauthorizes purpose-bound bounded content, validates every returned identity, byte, and expiry binding, and submits only exact Service-projected Risk Decision options with fresh idempotency before refetching committed truth, and renders verified SEALED Bundle metadata with registered Delivery Destination IDs. It erases its authority context and Assessment payload on close. The same entry contributes an additive bilingual launcher at sidebar.footer.action and a responsive Assessment surface at shell.overlay; the browser renders Service-projected state, Coverage, Verdict, available actions, bounded Evidence disclosure, and the governed Risk Decision form without accepting a browser-authored decision-maker. A BLOCKED Snapshot also carries bounded recovery metadata for the durable blocker, affected obligations, retained Evidence, required recovery condition, unreported execution budget, and possible Coverage Reconciliation; Resume and Cancel forms exist only when the corresponding Service action is projected;
  • exact Git revision, Change, and Workspace Snapshot Subject selectors;
  • bounded content-addressed Subject materialization below $DSH_HOME/security-assurance/subjects, with canonical manifests and no ordinary hard links to source content;
  • non-expanding symlink and submodule inventory; and
  • atomic ordering in which Subject Freeze succeeds before an Assessment ID and durable creation Receipt are committed;
  • a deterministic package-private Assessment path with durable CREATED → RUNNING → SEALED revisions;
  • a pure Policy Evaluator and independent seal-readiness check;
  • one versioned, built-in Pure Analyzer for the explicitly scoped security/node-package-lifecycle Policy, with a frozen Descriptor, development Qualification, bounded authority-free source slices, and no process, network, model, credential, or workspace access;
  • a side-effect-free dsh-security-assurance/analyzer Contract Entry and a local startup-composition Registry keyed by exact Analyzer ID and version;
  • frozen external Analyzer Descriptors, per-Assessment portfolios, bounded path-free Inputs, Attempt-scoped instances, and mandatory instance disposal;
  • fail-closed external Contribution admission: identity, Subject digest, Coverage obligation, and Evidence schema mismatches block the Assessment;
  • sealed advisory Evidence from unqualified external Pure Analyzers while mandatory Coverage remains a visible EVIDENCE_INELIGIBLE Gap and the Verdict remains INDETERMINATE;
  • Host-trusted, canonical-digest-bound external Analyzer Qualification Records covering exact Analyzer build, Policy, Mode, Coverage, Evidence schemas, execution backend, Provider, egress, platform, issuance, and expiry;
  • frozen per-Assessment Eligibility Decisions: qualified external Evidence and Findings remain visible, but a generic external clean claim stays Advisory; only the package-owned reference-validation contract can independently bind its exact Candidate Evidence to the frozen Subject and Policy;
  • versioned external Candidate Finding contracts with bounded weakness, Security Claim, Source Anchor, JSON Pointer, and contributed-Evidence links;
  • one exact deterministic Conformance Validation Contract that independently verifies immutable Subject and file digests, unique JSON security keys, the declared JSON Pointer, and the exact reference-control state against matching validation Evidence or Counter-Evidence;
  • separate Candidate Admission, Validation Contract Resolution, validation Evidence Eligibility, Validation Outcome, Technical Severity, Evidence Confidence, and Policy Significance records; and
  • immutable Candidate tri-state resolution under that Contract: eligible proof of VIOLATED produces VALIDATED and a blocking Finding, eligible Counter-Evidence proving SATISFIED produces REJECTED without a Finding, and contradictory or otherwise ineligible Evidence produces UNRESOLVED with an explicit Proof Gap and INDETERMINATE Verdict;
  • versioned listFindings projections that keep validated Findings, Rejected Candidates, and Unresolved Candidates visibly distinct while omitting Source Anchors, Security Claims, and Evidence payloads; Validation-state filtering occurs before bounded pagination, and HMAC-protected cursors bind the exact Assessment, Repository, sealed revision, page size, filter, and Security Principal;
  • revision-bound getFinding Detail Views that project canonical Subject- relative Source Anchors, exact tri-state Validation Outcome and Contract lineage, separate Severity/Confidence/Policy dimensions, Coverage and Risk status, and digest-bound Evidence Link metadata without returning Evidence values or read capabilities;
  • an opt-in frozen security/risk-decision-window-v1 stronger control that persists validated Findings and verified Evidence before opening an explicit pre-Seal BLOCKED window. Authorized recordRiskDecision commands bind the exact Assessment and Finding revisions, derive the decision maker only from the opaque Security Invocation, commit immutable idempotent Receipts, and prevent resumeAssessment from bypassing the window;
  • deterministic ordinary Risk Denial and non-Critical Risk Acceptance: denial preserves the blocking Policy Significance and FAILED Verdict, while an eligible time-bounded acceptance requires compensating controls, retains Technical Severity, changes only Policy Significance to NON_BLOCKING, and may produce SATISFIED only with complete mandatory Coverage. Risk Decision records are digest-bound into the final Seal, Bundle, and Submission;
  • separately enabled Critical break-glass under the frozen security/critical-break-glass-v1 stronger control. The first qualified human approval records only a durable PENDING_DUAL_AUTHORITY attestation; acceptance becomes effective only after a second independently authenticated Host Operator with a distinct principal submits the exact same rationale, controls, expiry, Assessment revision successor, and Finding identity. Both authorization attestations and the exact Subject/Policy scope survive restart and are bound into the final Seal;
  • authority- and revision-specific availableActions on every getAssessment Snapshot. Read-only callers and terminal Assessments receive no mutation actions; currently admissible Resume, Cancel, ordinary Risk Decision, Critical first-attestation, and distinct-principal second- attestation actions carry exact expected revisions and Finding identities. Risk options state their effect, authorization mode, control minimum, expiry ceiling, completed/required attestations, and whether the pending form must match exactly. The Workbench renders these Service projections directly; they are not browser-inferred authority or a model Risk Acceptance tool;
  • revision-bound getEvidenceView projections that require exact Assessment, consuming Finding revision, Evidence artifact, and digest identity. The metadata-only Profile needs Assessment read authority and always redacts content; the bounded-json Profile additionally requires the purpose-specific evidence:disclose:validation-review authority, VALIDATION_REVIEW purpose, an available frozen protection policy, an allowlisted Evidence schema, and a 32 KiB canonical JSON limit. Denied or unavailable content remains a structured redacted View without Store paths, keys, unrestricted sources, or reusable read capabilities;
  • blocking-Finding precedence proving a qualified validated Reference Candidate seals as FAILED with complete Coverage without allowing the Analyzer to set Finding, Severity, Significance, or Verdict directly;
  • staged, content-addressed publication of Analyzer Contribution, redacted Node package-manifest Evidence, and Evidence Eligibility Decision before sealing;
  • deterministic tri-state results for that scoped Policy: complete eligible Evidence with no forbidden install lifecycle script is SATISFIED, a validated forbidden preinstall/install/postinstall control is FAILED, and unsupported or malformed inputs remain INDETERMINATE;
  • blocking-Finding precedence over incomplete Coverage while every remaining Coverage Gap stays visible;
  • honest default-Policy reconciliation: because the general application- security obligation still has no complete qualified Analyzer portfolio, it remains INDETERMINATE, never a fabricated success;
  • atomic persistence of Verdict, Assessment Seal, Bundle Manifest, and self-contained Assurance Submission at one terminal revision;
  • content-addressed private Bundle publication with verification on every official read;
  • fail-closed restart and integrity behavior: interrupted RUNNING work becomes BLOCKED, sealed work is not rerun, and modified publication bytes are not served;
  • explicit revision-bound, idempotent resumeAssessment and cancelAssessment commands: resume admits a replacement execution without changing Subject or Policy, while cancellation persists intent before quiescence and commits CANCELED only afterward;
  • an optional dsh-security-assurance/control-plane-provider Cordis entry that registers exact Provider identity dsh/security-assurance, starts and waits for the same private Assessment Engine, and returns a Control Plane transport Submission by value; and
  • real dual-plugin Gate coverage proving SATISFIED → requirement satisfied, FAILED → REWORK_REQUIRED, INDETERMINATE → BLOCKED, and a missing Repository binding → fail-closed BLOCKED; and
  • real dual-plugin cancellation coverage proving explicit Mission cancellation records the external Assessment identity and leaves that same Assessment CANCELED without Verdict or Seal, including restart reconciliation when the Security commit precedes Control Plane Invocation termination; and
  • historical packed Harness 0.1.1-rc.2 profile proof for disabled, absent when-available, absent required, valid required integration, Adapter unload, and full profile restart; and
  • packed fail-closed Gate proof for a real Security FAILED → REWORK_REQUIRED, a real Security INDETERMINATE → BLOCKED, a digest-tampered Submission that is rejected before Evidence import, and a frozen Provider that disappears mid-Attempt without falling back to another registered version; and
  • historical packed Harness 0.1.1-rc.2 Reference Host driven through a real Chrome-family browser. The scenario proves Host-authenticated selection, keyboard/focus behavior, Runtime Health, digest-bound start, BLOCKED Risk Denial, sealed metadata-first Evidence and explicit bounded disclosure, bilingual responsive rendering, reload, offline/reconnect, denied authority, browser-state and remote-resource redaction, and Host lifecycle shutdown.

Production-qualified external Analyzers, process or agent Analyzers, general Node and application-security coverage, the complete protected Evidence Store, and the complete Workbench information architecture are deliberately not claimed as implemented yet. The Workbench Host Remote, authenticated redacted Assessment selection with stable cursor continuation, generated Client contract, transient browser Controller, Runtime Health, Repositories and digest-bound New Assessment flow, read-only Assessment Detail, multidimensional Finding triage, revision-bound Finding Detail navigation, bilingual metadata-first Evidence, explicit expiring bounded-content disclosure, a governed Risk Decision form with Critical Dual Authority completion, and a read-only SEALED Bundle/Export readiness view are i