Introduction

In the DeepSeek Harness (DSH) ecosystem, separation of duties (SoD) is one of the core goals of security auditing. NIST defines multiple SoD types (static, dynamic, object-based, etc.). Existing plugins such as dsh-guarded-hcl mainly target optimizer/evaluator/policy boundaries, while dsh-decision-effect-proof is responsible for reconciling decisions and effects.

The problem this plugin addresses is: Given a set of provided DSH workflow receipts, how can we prove offline and deterministically whether they comply with the declared duty-conflict policy?

Positioning

dsh-duty-separation-proof is an offline evidence-generation tool focused on post-hoc auditing. It does not provide real-time control; instead, it performs integrity checks and policy-compliance analysis on the provided receipt chain.

  • Name: dsh-duty-separation-proof
  • Maintainer: dongsheng123132
  • Category: admin-security
  • License: MIT

Core Features

  1. Offline Deterministic Evidence: Generates fixed results based on input data without relying on real-time system state.
  2. Workflow Order Validation: Strictly validates the exact order of request, approval, execution, and observation.
  3. Identity and Hash Binding: Validates identity and hash bindings for workflows, objects, and revisions.
  4. Receipt Chain Continuity: Checks whether the receipt chain is broken or anomalous.
  5. Subject Mutual-Exclusion Validation: Verifies that executing subjects and approving subjects belong to disjoint sets.
  6. Quorum Validation: Ensures the approval process reaches the configured quorum.
  7. Subject Diversity Validation: Verifies identity diversity and freshness of subjects and observers.
  8. Content-Addressed Output: Generates a redacted, content-addressed JSON verdict report.

Usage

The plugin provides command-line tools for inspection and verification. The DSH Bundle exposes the dsh_duty_separation_inspect and dsh_duty_separation_verify tools, and the Standalone MCP Server also provides equivalent proof-only inline tools.

# 运行测试
npm test
# 运行静态检查
npm run check
# 检查特定示例
node bin/dsh-duty-separation-proof.mjs inspect examples/settled.json
# 验证证据
node bin/dsh-duty-separation-proof.mjs verify examples/settled.json

Technical Details

  • Manifest Boundary: All identities for workflows, objects, revisions, policies, subjects, observers, and receipts are lowercase SHA-256 values. The report contains only bounded proofId hashes.
  • Canonical Sequence: The validated sequence must begin with request, include execute, and end with observe; it may contain multiple intermediate approve stages.
  • Policy Inputs: disjointDutySets (disjoint duty sets) and quorum thresholds are explicit policy inputs.

Notes

  • Not an Authorization System: This plugin is not an authorization system. It does not grant roles, approve requests, execute changes, authenticate receipts, inspect real-time systems, or prove that the provided ledger is exhaustive.
  • Report Attributes: The generated report intentionally marks authenticatesReceipts, provesLedgerExhaustive, and provesAbsenceOfUndeclaredActions as false.

References

NIST Separation of Duty glossary
NIST SP 800-192

GitHub repository | SkillHub catalog