Introduction¶
In the DeepSeek Harness (DSH) ecosystem, separation of duties (SoD) is one of the core goals of security auditing. NIST defines multiple SoD types (static, dynamic, object-based, etc.). Existing plugins such as dsh-guarded-hcl mainly target optimizer/evaluator/policy boundaries, while dsh-decision-effect-proof is responsible for reconciling decisions and effects.
The problem this plugin addresses is: Given a set of provided DSH workflow receipts, how can we prove offline and deterministically whether they comply with the declared duty-conflict policy?
Positioning¶
dsh-duty-separation-proof is an offline evidence-generation tool focused on post-hoc auditing. It does not provide real-time control; instead, it performs integrity checks and policy-compliance analysis on the provided receipt chain.
- Name:
dsh-duty-separation-proof - Maintainer:
dongsheng123132 - Category:
admin-security - License:
MIT
Core Features¶
- Offline Deterministic Evidence: Generates fixed results based on input data without relying on real-time system state.
- Workflow Order Validation: Strictly validates the exact order of request, approval, execution, and observation.
- Identity and Hash Binding: Validates identity and hash bindings for workflows, objects, and revisions.
- Receipt Chain Continuity: Checks whether the receipt chain is broken or anomalous.
- Subject Mutual-Exclusion Validation: Verifies that executing subjects and approving subjects belong to disjoint sets.
- Quorum Validation: Ensures the approval process reaches the configured quorum.
- Subject Diversity Validation: Verifies identity diversity and freshness of subjects and observers.
- Content-Addressed Output: Generates a redacted, content-addressed JSON verdict report.
Usage¶
The plugin provides command-line tools for inspection and verification. The DSH Bundle exposes the dsh_duty_separation_inspect and dsh_duty_separation_verify tools, and the Standalone MCP Server also provides equivalent proof-only inline tools.
# 运行测试
npm test
# 运行静态检查
npm run check
# 检查特定示例
node bin/dsh-duty-separation-proof.mjs inspect examples/settled.json
# 验证证据
node bin/dsh-duty-separation-proof.mjs verify examples/settled.json
Technical Details¶
- Manifest Boundary: All identities for workflows, objects, revisions, policies, subjects, observers, and receipts are
lowercase SHA-256values. The report contains only boundedproofIdhashes. - Canonical Sequence: The validated sequence must begin with
request, includeexecute, and end withobserve; it may contain multiple intermediateapprovestages. - Policy Inputs:
disjointDutySets(disjoint duty sets) and quorum thresholds are explicit policy inputs.
Notes¶
- Not an Authorization System: This plugin is not an authorization system. It does not grant roles, approve requests, execute changes, authenticate receipts, inspect real-time systems, or prove that the provided ledger is exhaustive.
- Report Attributes: The generated report intentionally marks
authenticatesReceipts,provesLedgerExhaustive, andprovesAbsenceOfUndeclaredActionsasfalse.