bailong-Hakuryu/dsh-security-assurance ↗★ 0
dsh-security-assurance
Evidence-backed application-security assurance for DeepSeek Harness
安装
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:bailong-Hakuryu/dsh-security-assurance说明文档
阅读完整 README ↗DSH Security Assurance
DSH Security Assurance is an independent DeepSeek Harness plugin for evidence-backed application-security assessment. It integrates through public Harness and Cordis seams and does not modify Harness Core.
v0.1 release candidate status
Version 0.1.0-rc.9 is the directly usable v0.1 candidate for Harness
0.1.2-alpha.1. It is
intended for acceptance and release-gate verification. Stable 0.1.0
promotion is limited to version, signature, and release metadata after the
exact candidate artifact passes every required gate; no unqualified behavior
change may be folded into that promotion. The candidate proves:
- dormant bundle installation metadata;
- real Cordis registration at
ctx.securityAssurance; - an opaque, runtime-verified Security Invocation boundary;
- authorized Runtime Health, Repository Registry, Assessment start/query/wait, effective Security Catalog and digest-bound Start Preflight, Finding Summary and Detail, purpose-bound Evidence View, Bundle Manifest, and Assurance Submission operations;
- an independently activatable
dsh-security-assurance/toolsConsumer with boundedsecurity_repositories,security_catalog,security_assessment_start, read-onlysecurity_assessment_statusandsecurity_assessment_findings, and revision-boundsecurity_assessment_resumeandsecurity_assessment_cancel, plus boundedsecurity_assessment_exportmodel tools. They derive the exact live Harness session outside model arguments, mint one operation-specific permission, and delegate all Assessment validation, pagination, redaction, recovery, cancellation, delivery, and state transitions to the root Service; - versioned Zod-validated public contracts;
- a side-effect-free
dsh-security-assurance/evaluationentry containing the first pure versioned Metrics Engine slice. It calculates Critical/High and severity-weighted Validated Recall, Validated Precision, Unsafe Satisfaction Rate, and Coverage Honesty Rate from strict independently adjudicated Evaluation evidence; - one
SecurityResultsuccess/failure envelope; - redacted authorization, validation, cancellation, deadline, and internal failures;
- a plugin-private SQLite Registry with immutable revisions, idempotent Receipts, exact Revision CAS, fail-closed startup validation, and restart recovery;
- explicit register, get, list, update, and non-destructive disable behavior;
- a trusted
dsh-security-assurance/host-repository-providercomposition entry that registers Host configuration through the root Service and resolves only immutable path-free Repository bindings; - a package-owned
dsh-security-assurance/workbench-remoteHost Adapter plus generated strictdsh-security-assurance/typertanddsh-security-assurance/remoteartifacts. Its headless Workbench slice exposes authority-projected Runtime Health, Repository and Assessment selection, effectivegetHealth,getCatalog, digest-boundstartAssessment, exactgetAssessment, integrity-verifiedgetBundleManifest, path-freegetRepository, revision-bound Finding queries, strict metadata-onlygetEvidenceView, separate expiringdiscloseEvidence, boundedwaitForAssessmentRevision, and revision-bound, idempotentrecordRiskDecision,resumeAssessment, andcancelAssessmentwithout putting a Principal, permissions, or Security Invocation on the wire; - legacy Workbench browser source retained for future migration, but deliberately
excluded from the
0.1.0-rc.9package because Harness0.1.2-alpha.1no longer publishes the client-runtime preset it was built against. Direct Web users instead receive Harness's generic cards for the eight registered model tools. The legacy source previously provided one transientctx.securityAssuranceWorkbenchController. It opens authenticated Runtime Health, redacted Repository and Assessment selectors, builds the New Assessment Wizard only from Catalog choices, confirms immutable Start Preflight proposals, fetches immutable Snapshots, follows committed revisions through cancellable long-polling, fences stale responses and disclosure attempts, opens metadata only from an exact Finding Evidence Link, separately reauthorizes purpose-bound bounded content, validates every returned identity, byte, and expiry binding, and submits only exact Service-projected Risk Decision options with fresh idempotency before refetching committed truth, and renders verified SEALED Bundle metadata with registered Delivery Destination IDs. It erases its authority context and Assessment payload on close. The same entry contributes an additive bilingual launcher atsidebar.footer.actionand a responsive Assessment surface atshell.overlay; the browser renders Service-projected state, Coverage, Verdict, available actions, bounded Evidence disclosure, and the governed Risk Decision form without accepting a browser-authored decision-maker. ABLOCKEDSnapshot also carries bounded recovery metadata for the durable blocker, affected obligations, retained Evidence, required recovery condition, unreported execution budget, and possible Coverage Reconciliation; Resume and Cancel forms exist only when the corresponding Service action is projected; - exact Git revision, Change, and Workspace Snapshot Subject selectors;
- bounded content-addressed Subject materialization below
$DSH_HOME/security-assurance/subjects, with canonical manifests and no ordinary hard links to source content; - non-expanding symlink and submodule inventory; and
- atomic ordering in which Subject Freeze succeeds before an Assessment ID and durable creation Receipt are committed;
- a deterministic package-private Assessment path with durable
CREATED → RUNNING → SEALEDrevisions; - a pure Policy Evaluator and independent seal-readiness check;
- one versioned, built-in Pure Analyzer for the explicitly scoped
security/node-package-lifecyclePolicy, with a frozen Descriptor, development Qualification, bounded authority-free source slices, and no process, network, model, credential, or workspace access; - a side-effect-free
dsh-security-assurance/analyzerContract Entry and a local startup-composition Registry keyed by exact Analyzer ID and version; - frozen external Analyzer Descriptors, per-Assessment portfolios, bounded path-free Inputs, Attempt-scoped instances, and mandatory instance disposal;
- fail-closed external Contribution admission: identity, Subject digest, Coverage obligation, and Evidence schema mismatches block the Assessment;
- sealed advisory Evidence from unqualified external Pure Analyzers while
mandatory Coverage remains a visible
EVIDENCE_INELIGIBLEGap and the Verdict remainsINDETERMINATE; - Host-trusted, canonical-digest-bound external Analyzer Qualification Records covering exact Analyzer build, Policy, Mode, Coverage, Evidence schemas, execution backend, Provider, egress, platform, issuance, and expiry;
- frozen per-Assessment Eligibility Decisions: qualified external Evidence and Findings remain visible, but a generic external clean claim stays Advisory; only the package-owned reference-validation contract can independently bind its exact Candidate Evidence to the frozen Subject and Policy;
- versioned external Candidate Finding contracts with bounded weakness, Security Claim, Source Anchor, JSON Pointer, and contributed-Evidence links;
- one exact deterministic Conformance Validation Contract that independently verifies immutable Subject and file digests, unique JSON security keys, the declared JSON Pointer, and the exact reference-control state against matching validation Evidence or Counter-Evidence;
- separate Candidate Admission, Validation Contract Resolution, validation Evidence Eligibility, Validation Outcome, Technical Severity, Evidence Confidence, and Policy Significance records; and
- immutable Candidate tri-state resolution under that Contract: eligible proof
of
VIOLATEDproducesVALIDATEDand a blocking Finding, eligible Counter-Evidence provingSATISFIEDproducesREJECTEDwithout a Finding, and contradictory or otherwise ineligible Evidence producesUNRESOLVEDwith an explicit Proof Gap andINDETERMINATEVerdict; - versioned
listFindingsprojections that keep validated Findings, Rejected Candidates, and Unresolved Candidates visibly distinct while omitting Source Anchors, Security Claims, and Evidence payloads; Validation-state filtering occurs before bounded pagination, and HMAC-protected cursors bind the exact Assessment, Repository, sealed revision, page size, filter, and Security Principal; - revision-bound
getFindingDetail Views that project canonical Subject- relative Source Anchors, exact tri-state Validation Outcome and Contract lineage, separate Severity/Confidence/Policy dimensions, Coverage and Risk status, and digest-bound Evidence Link metadata without returning Evidence values or read capabilities; - an opt-in frozen
security/risk-decision-window-v1stronger control that persists validated Findings and verified Evidence before opening an explicit pre-SealBLOCKEDwindow. AuthorizedrecordRiskDecisioncommands bind the exact Assessment and Finding revisions, derive the decision maker only from the opaque Security Invocation, commit immutable idempotent Receipts, and preventresumeAssessmentfrom bypassing the window; - deterministic ordinary Risk Denial and non-Critical Risk Acceptance: denial
preserves the blocking Policy Significance and
FAILEDVerdict, while an eligible time-bounded acceptance requires compensating controls, retains Technical Severity, changes only Policy Significance toNON_BLOCKING, and may produceSATISFIEDonly with complete mandatory Coverage. Risk Decision records are digest-bound into the final Seal, Bundle, and Submission; - separately enabled Critical break-glass under the frozen
security/critical-break-glass-v1stronger control. The first qualified human approval records only a durablePENDING_DUAL_AUTHORITYattestation; acceptance becomes effective only after a second independently authenticated Host Operator with a distinct principal submits the exact same rationale, controls, expiry, Assessment revision successor, and Finding identity. Both authorization attestations and the exact Subject/Policy scope survive restart and are bound into the final Seal; - authority- and revision-specific
availableActionson everygetAssessmentSnapshot. Read-only callers and terminal Assessments receive no mutation actions; currently admissible Resume, Cancel, ordinary Risk Decision, Critical first-attestation, and distinct-principal second- attestation actions carry exact expected revisions and Finding identities. Risk options state their effect, authorization mode, control minimum, expiry ceiling, completed/required attestations, and whether the pending form must match exactly. The Workbench renders these Service projections directly; they are not browser-inferred authority or a model Risk Acceptance tool; - revision-bound
getEvidenceViewprojections that require exact Assessment, consuming Finding revision, Evidence artifact, and digest identity. The metadata-only Profile needs Assessment read authority and always redacts content; the bounded-json Profile additionally requires the purpose-specificevidence:disclose:validation-reviewauthority,VALIDATION_REVIEWpurpose, an available frozen protection policy, an allowlisted Evidence schema, and a 32 KiB canonical JSON limit. Denied or unavailable content remains a structured redacted View without Store paths, keys, unrestricted sources, or reusable read capabilities; - blocking-Finding precedence proving a qualified validated Reference Candidate
seals as
FAILEDwith complete Coverage without allowing the Analyzer to set Finding, Severity, Significance, or Verdict directly; - staged, content-addressed publication of Analyzer Contribution, redacted Node package-manifest Evidence, and Evidence Eligibility Decision before sealing;
- deterministic tri-state results for that scoped Policy: complete eligible
Evidence with no forbidden install lifecycle script is
SATISFIED, a validated forbiddenpreinstall/install/postinstallcontrol isFAILED, and unsupported or malformed inputs remainINDETERMINATE; - blocking-Finding precedence over incomplete Coverage while every remaining Coverage Gap stays visible;
- honest default-Policy reconciliation: because the general application-
security obligation still has no complete qualified Analyzer portfolio, it
remains
INDETERMINATE, never a fabricated success; - atomic persistence of Verdict, Assessment Seal, Bundle Manifest, and self-contained Assurance Submission at one terminal revision;
- content-addressed private Bundle publication with verification on every official read;
- fail-closed restart and integrity behavior: interrupted
RUNNINGwork becomesBLOCKED, sealed work is not rerun, and modified publication bytes are not served; - explicit revision-bound, idempotent
resumeAssessmentandcancelAssessmentcommands: resume admits a replacement execution without changing Subject or Policy, while cancellation persists intent before quiescence and commitsCANCELEDonly afterward; - an optional
dsh-security-assurance/control-plane-providerCordis entry that registers exact Provider identitydsh/security-assurance, starts and waits for the same private Assessment Engine, and returns a Control Plane transport Submission by value; and - real dual-plugin Gate coverage proving
SATISFIED → requirement satisfied,FAILED → REWORK_REQUIRED,INDETERMINATE → BLOCKED, and a missing Repository binding → fail-closedBLOCKED; and - real dual-plugin cancellation coverage proving explicit Mission cancellation
records the external Assessment identity and leaves that same Assessment
CANCELEDwithout Verdict or Seal, including restart reconciliation when the Security commit precedes Control Plane Invocation termination; and - historical packed Harness
0.1.1-rc.2profile proof fordisabled, absentwhen-available, absentrequired, valid required integration, Adapter unload, and full profile restart; and - packed fail-closed Gate proof for a real Security
FAILED → REWORK_REQUIRED, a real SecurityINDETERMINATE → BLOCKED, a digest-tampered Submission that is rejected before Evidence import, and a frozen Provider that disappears mid-Attempt without falling back to another registered version; and - historical packed Harness
0.1.1-rc.2Reference Host driven through a real Chrome-family browser. The scenario proves Host-authenticated selection, keyboard/focus behavior, Runtime Health, digest-bound start,BLOCKEDRisk Denial, sealed metadata-first Evidence and explicit bounded disclosure, bilingual responsive rendering, reload, offline/reconnect, denied authority, browser-state and remote-resource redaction, and Host lifecycle shutdown.
Production-qualified external Analyzers, process or agent Analyzers, general Node and application-security coverage, the complete protected Evidence Store, and the complete Workbench information architecture are deliberately not claimed as implemented yet. The Workbench Host Remote, authenticated redacted Assessment selection with stable cursor continuation, generated Client contract, transient browser Controller, Runtime Health, Repositories and digest-bound New Assessment flow, read-only Assessment Detail, multidimensional Finding triage, revision-bound Finding Detail navigation, bilingual metadata-first Evidence, explicit expiring bounded-content disclosure, a governed Risk Decision form with Critical Dual Authority completion, and a read-only SEALED Bundle/Export readiness view are i