Dsh Riskproof
onlyqzq/dsh-riskproof · skills
Risk-aware approval layer for high-risk AI Agent tool calls.
★ 7GitHub stars
0Forks
2026-09-07Last updated
TypeScriptLanguage
Apache-2.0License
Key features
- Know where tool inputs came from.
- Carry security labels — UNTRUSTED_WEB, CUSTOMER_DATA, PII, SECRET, … — across tool calls, additively.
- Identify the EXTERNAL_INGESTION → PRIVATE_ACCESS → EXTERNAL_ACTION pattern that single-tool checks miss.
- Block or ask before the side effect runs, through the native tools/pre-execute gate.
- RiskProof maps arguments back to the tool results that produced them.
Install command
dsh plugin --profile web add github:onlyqzq/dsh-riskproof