dsh-plugin-vajraclaw
Verifieddsh-plugin-vajraclaw ยท v2.1.0 ยท Apache-2.0
Local tool-call failsafe for DSH: blocks a fixed list of high-risk shell patterns and credential-file reads before execution, with a per-session hash-linked JSONL audit log, and an optional external Gateway for centralized policy.
Install
dsh plugin add dsh-plugin-vajraclaw Confirm the layer applied with dsh --profile default --dump-config โ see the install guide.
Source
Tags
Creators
Readme
โก DROSโข VajraClaw for DSH & Multi-Agent Workstations
Local Tool-Call Failsafe & Runtime Governance Sidecar for Autonomous AI Agents
English | ็น้ซไธญๆ่ชชๆ | ๐ Official Website
Local tool-call failsafe for DSH: blocks high-risk shell patterns (e.g. destructive recursive deletions, fork bombs, disk overwriting) and credential-file reads before execution, with a persistent hash-linked JSONL audit log, and an optional external Gateway for centralized multi-agent policy.
๐ฏ Dual Architecture Overview:
- Embedded Mode (Default): Zero-dependency local TypeScript pattern-matching failsafe and JSONL audit chain running natively inside DSH with zero latency overhead.
- Gateway Mode (Optional): Connect to an external DROS Gateway container for multi-agent workstation synchronization (AGY, Codex, Claude Code, Cursor).
DSH Tool Call Event
โ
โผ
[dsh-plugin-vajraclaw]
โ
โโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโ
โผ โผ
[Embedded Mode] (Default) [Gateway Mode] (Optional)
โข Regex Pattern Failsafe โข Centralized Multi-Agent Policy
โข Sensitive File Protection โข Cross-Station Sync (AGY, Codex, Claude)
โข Persistent JSONL Audit โข Requires DROS Gateway Container
๐ ใCommunity Edition: Free Forever for Personal Multi-Agent Workstationsใ
- ๐ก๏ธ 100% Free for Personal Use (Non-Commercial Use): Embedded local failsafe is fully open-source (Apache-2.0).
- ๐ Audit Logging: Structured JSONL audit records linking execution history across session restarts.
- โก Optional Centralized Gateway: Provides cross-agent governance when opting into external Gateway deployment.
๐ Compliance Notice: Any deployment operated by corporate entities, salaried employees within the scope of employment, or used to generate commercial value strictly requires a commercial license.
๐๏ธ Philosophy: Guarding the Hyper-Open Plugin Ecosystem
The brilliance of DeepSeek Harness (DSH) lies in its radical openness: "Everything is a plugin." However, this hyper-openness inevitably expands the attack surface:
- Any rogue third-party plugin can attempt unauthorized tool execution, memory poisoning, or silent data exfiltration.
- DROS steps in as the universal anchor, orchestrating best-of-breed open-source security tools (Falco eBPF, Cilium CNI, Wazuh SIEM) to construct an impregnable Defense-in-Depth perimeter for all developers!
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. In-App Layer: DSH Security Plugins โ <โโ ๐ข Reception Security (Prompt Filtering)
โ (NeMo / Llama-Guard filters conversational toxicity) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ (Valid Prompt, prepares Tool Call)
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. Runtime Gateway: DROS VajraClaw (Core Anchor) โ <โโ ๐๏ธ Vault Gatekeeper (Execution Identity)
โ (W3C DID Signature + 364ns O(1) Tool Permission Bitmap) โ Enforcement-path latency <1 ฮผs under specified benchmark!
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ (Permitted Tool Call)
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. Infrastructure Layer: Open-Source SecOps (Cilium / Falco)โ <โโ ๐ Police Grid (Kernel & Network Fabric)
โ (Cilium blocks rogue egress; Falco eBPF catches escapes) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
๐งญ Governance Scope: What DROS Defends vs. What It Doesn't
To maintain complete architectural clarity and rigorous technical defense, DROS defines crisp defensive boundaries:
| Attack Vector / Threat | Traditional Semantic Guardrails | DROS VajraClaw Core | Defensive Outcome |
|---|---|---|---|
| Indirect Prompt Injection (PDF/Web hijacking tool execution) | โ Easily fooled by LLM confusion | โ Deterministic Block | Deterministic In-Band Fusing (<1ฮผs benchmarked bitmap match) |
| Rogue Tool Calling (Unauthorized DB write / Shell execution) | โ Flawed application logic | โ Cryptographic Block | 100% Interception within defined threat model & capability vector |
| Data Exfiltration (Plugin silently sending tokens to C2) | โ Invisible to LLMs | โ Network Isolated | 100% Dropped (internal: true sandbox topology) |
| Container Escape / Privilege Escalation | โ No host visibility | โ ๏ธ Handled via Falco | eBPF Kernel Detection (cap_drop: ALL capability isolation) |
| Business Logic Flaws / Model Hallucinations | โ Beyond security scope | โ Beyond security scope | Handled via Prompt engineering & Agent QA workflows |
๐ Zero-Trust Key Management & Root Recovery Principle
DROS operates on a strict Zero-Trust Cryptographic Model:
- No Backdoors Policy: The vendor holds NO master keys. Your Ed25519 private seed hex is generated locally. Always backup your seed hex into your password manager.
- Rebuilding Root of Trust: If you lose your private key, recovery is only possible if you maintain Root/SSH access to the host server to re-deploy the public verification key.
๐ Multi-Agent Workstation Architecture (DSH + AGY + Codex + Claude)
Although packaged as a DSH plugin for zero-friction setup, the underlying DROS Gateway runs in Docker (localhost:8080), enabling you to protect your entire multi-agent environment under a single 5-Agent Concurrent Governance Envelope:
graph TD
subgraph "Your Local Developer Workstation"
DSH[DeepSeek Harness<br/>dsh-plugin-vajraclaw] -->|HTTP / Intercept| GW[โก DROS Docker Gateway<br/>localhost:8080]
AGY[Google Antigravity AGY<br/>MCP / Python SDK] -->|MCP Gateway| GW
Codex[OpenAI Codex / Claude Code<br/>Tool Interception] -->|REST / C-ABI| GW
Cursor[Cursor / IDE Agents<br/>Local Hook] -->|API Proxy| GW
GW --> Micro[๐ก๏ธ DROS Micro-Kernel<br/>O 1 Bitmap Matrix & Ed25519 W3C DID]
Micro --> OS[Local OS / Filesystem / Terminal Execution]
end
๐ Dual Mode Comparison Matrix (Standalone Plugin vs. Docker Gateway)
| Capability Dimension | ๐ฆ Mode A: Standalone Plugin (Default) | โก Mode B: DROS Docker Gateway (Optional) |
|---|---|---|
| Runtime Environment | Pure In-Process TypeScript (Zero Dependency) | Local Docker Container (localhost:8080) |
| Supported Agents | DeepSeek Harness (DSH) Only | DSH + Google AGY + Codex + Claude + Cursor |
| Principal Identity | Process-Bound Agent ID | Native W3C did:key (Ed25519) Cryptographic Identity |
| Tool Execution Gate | Robust Regex Shell & File Pattern Failsafe | Deterministic AST Bitmap Policy Engine (<1ฮผs) |
| Audit Verification | Persistent Hash-Linked JSONL (Local Disk) | Ed25519 Cryptographically Signed Merkle Chain |
| RFC-010 Agent Passport | Standard Format Interpretation | Full Local Passport Issuance & Multi-Agent Attestation |
| Network Overhead | 0 ms (Direct In-Memory Hook) | <1 ms (Local Loopback HTTP / C-ABI) |
| License & Access | 100% Free Forever (Apache-2.0) | Free for Personal Hacker Use (Community) |
๐ก๏ธ Governance & Defense Capability Matrix
| Threat Vector / Capability | Traditional LLM Guardrails (NeMo/Lakera) | ๐ฆ DSH Standalone TS Plugin | ๐ก๏ธ DROS Hacker Docker Gateway | ๐ข Enterprise / Mesh Tier |
|---|---|---|---|---|
| Runtime Vehicle | Cloud API / External Model | In-Process JS (Zero Deps) | Local Docker Container (:8080) |
Enterprise Cluster / K8s / C-ABI |
| Protected Scope | Single Chat Session | DSH Local Process | Full Ecosystem (Claude+Codex+Cursor+DSH+AGY) | Multi-Node Fleet / Private Cloud |
| Execution Intent Governance | ๐ด Text-matching only | ๐ข Regex Pattern Failsafe | ๐ข 100% Deterministic AST Fusing (<1ยตs) | ๐ข AST Bitmaps + eBPF Kernel Hooks |
| Destructive Command Blocking | ๐ด Vulnerable to Injections | ๐ข Sensitive Path Block | ๐ข Deterministic Syscall Severing | ๐ข Hardware HSM + Kernel-level Lock |
| Credential & Secret Protection | ๐ด No Physical Guard | ๐ข Sensitive Path Block | ๐ข Dynamic Redaction + Sandbox Isolation | ๐ข Hardware HSM + ZKP-Lite Proofs |
| Agent Identity Binding | ๐ด No Identity | ๐ข Session-level ID | ๐ข Native W3C did:key (Ed25519) |
๐ข 3-Tier PKI DrosIdentityToken (DIT) |
| Non-Repudiable Audit Chain | ๐ด Plain Text Logs | ๐ข Local SHA-256 Hash Chain | ๐ข Ed25519 Signed Merkle Hash Chain | ๐ข EU AI Act Art. 12 Court-Grade Chain |
| RFC-010 Passports | ๐ด Unsupported | ๐ข Format Parser | ๐ข Local Minting & Cross-Agent Verification | ๐ข Cross-Organization Roaming Passports |
| Decision Latency | ๐ด 1,000 ~ 3,000 ms (Slow LLM) | ๐ข <1 ms (Direct In-Memory Hook) | ๐ข <1 ยตs (C-ABI) / <1 ms (REST Gateway) | ๐ข <500 ns (Zero-Copy Memory Lookup) |
| License | Pay-per-Token API | 100% Free (Apache-2.0) | Free License for Individuals | Startup $2,990 / Enterprise $29,990 |
๐ Quick Start (ๆ้ไธๆ)
Mode A: Standalone Plugin Mode (Default, Zero-Dependency, No Docker)
Directly install the plugin in DSH to immediately enable high-risk command blocking, credential file protection, and local audit logging:
dsh plugin --profile web add dsh-plugin-vajraclaw
(Runs 100% in-process with zero network overhead and zero external dependencies)
Mode B: Advanced Multi-Agent Workstation Mode (Optional Docker Gateway)
If you wish to govern multiple multi-agent runtimes (DSH + Google AGY + Codex + Claude Code + Cursor) under a single workstation with Native W3C did:key identity, RFC-010 passports, and microsecond AST policy matrix:
- Launch the Free DROS Docker Gateway:
docker run -d -p 8080:8080 --name dros-gateway dros/hacker-gateway:v1.0.0 - Configure DSH Plugin Gateway Endpoint (in DSH Settings or
cordis.patch.yml):dsh-plugin-vajraclaw: gatewayUrl: "http://localhost:8080" - Connect Other External Agents (AGY / Codex / Claude Code / Cursor):
export DROS_GATEWAY_URL="http://localhost:8080" export DROS_IDENTITY_SEED="0x1a2b3c4d..." # Your local Ed25519 seed hex
๐ ๐ Read the Advanced SecOps Guide (docs/ADVANCED_SECOPS_GUIDE.md) for internal: true network isolation, Falco eBPF, and Wazuh integration templates.
๐ How to Configure Security Policies (Vajra.md Guide)
DROS supports two straightforward formats: Intuitive Markdown (Vajra.md) and Structured YAML (demo_policy.yaml).
1. ๐ Intuitive Markdown Example (Vajra.md)
Declare allowed capabilities and hard security boundaries in plain Markdown:
# ๐ก๏ธ DROS Agent Security Policy (Vajra.md)
## 1. Allowed Capabilities
- Allow reading workspace files (`file_read`)
- Allow standard queries (`search_web`, `query_db`)
- Allow safe terminal commands (`git status`, `npm test`, `cargo check`)
## 2. Strict Fail-Closed Boundaries
- Block all recursive deletion or wiping commands (`rm -rf`, `rmdir /s`, `format`)
- Block access to credential paths (`.env`, `id_rsa`, `secrets.json`, `.aws/credentials`)
- Restrict transaction amounts exceeding $1,000 threshold (`amount <= 1000`)
[!IMPORTANT] ๐ Crucial Security Best Practice: Lock
Vajra.mdto Read-Only After Configuration! To prevent compromised or hallucinating AI Agents from attempting to rewrite their own security rules to escalate privileges, always set your policy file to read-only once configured:
- Linux / macOS:
chmod 444 Vajra.md- Windows (PowerShell):
Set-ItemProperty -Path Vajra.md -Name IsReadOnly -Value $true- Docker Container Mount: Mount with the read-only flag
-v $(pwd)/Vajra.md:/app/demo_policy.yaml:ro(Note: DROS kernel enforces 4-Layer Invariant Defense to intercept unauthorized policy modifications in-band; combining this with OS file-level locks achieves 100% airtight physical defense!)
2. ๐ค Let AI Generate Your Policy in 1 Second! (AI Prompt Template)
You don't need to write policies from scratch! Copy the following universal prompt to ChatGPT, Claude, or Cursor:
๐ Copy this Prompt to any LLM / AI Assistant:
You are a DROS deterministic security architecture expert. Based on my Agent requirements, generate a standard DROS "Vajra.md" security policy in Markdown. Agent Details: - Agent Role & Scenario: [e.g., Fullstack Developer / Customer Service / Financial Automation] - Allowed Tools & Operations: [e.g., Read/Write src/, Run tests, Query order database] - Strict Boundaries & Denials: [e.g., Block deletion of root/workspace, Block .env access, Payment limit $500] Follow the DROS "Default Fail-Closed" whitelist principle and structure the output into: 1. Role & Capability Scope 2. Allowed Capabilities (Whitelist) 3. Security Boundary Constraints (Thresholds & Pattern Failsafes)
3. ๐ Instant Hot Reloading
Simply mount your Vajra.md when launching the Docker gateway. Policy changes take effect in <1 microsecond without container restarts:
docker run -d -p 8080:8080 --name dros-gateway \
-v $(pwd)/Vajra.md:/app/demo_policy.yaml \
dros/hacker-gateway:v1.0.0
๐ Technical Foundations & Benchmark Sandboxes
The deterministic runtime governance, microsecond circuit-breaking, and cryptographic audit mechanisms implemented in this project are grounded in the following academic research and open-source benchmark environments:
Core Architecture & Six Fundamental Boundaries:
- DROS-6P: A Unified Deterministic Runtime Governance Architecture Closing the Six Fundamental Trust Boundaries of Enterprise AI Agents
- Zenodo DOI:
10.5281/zenodo.21833970| Archival Record: zenodo.org/records/21833970
Defense-in-Depth Substrate (4-Layer Model):
- DROS 4-Layer Defense-in-Depth Architecture for Autonomous AI Workloads
- Zenodo DOI:
10.5281/zenodo.21903475| Archival Record: zenodo.org/records/21903475
External C-ABI & Non-Repudiable Attribution (PGM):
- Runtime Attribution Framework: An External C-ABI and PKI-Based Zero-Trust Infrastructure for Non-Repudiable Execution Governance in Multi-Agent Systems
- Zenodo DOI:
10.5281/zenodo.21903687| Archival Record: zenodo.org/records/21903687
Open Technical Standard & Verification Benchmark:
- RFC-010 Standard: Compliant with Open Agent Passport & Evidence Specification (W3C DID
did:key& Ed25519 signature chain). - Benchmark Testbed: DROS-VEP Lite (Reproducible Security Sandbox)
- Empirical Report: 24-hour continuous multi-scenario soak test report (160,611 requests verified at 26.1ฮผs decision latency).
- RFC-010 Standard: Compliant with Open Agent Passport & Evidence Specification (W3C DID
๐๏ธ Official Organization & Contact Information
- Publishing Entity: Top-Celestial Company Ltd. (ๅบทๅฎธๅๆ้ๅ ฌๅธ)
- Official Website: https://dr-os.io
- Customer Support & Inquiries: [email protected]
- GitHub Organization: https://github.com/Top-Celestial-Company-Ltd
๐ Patent & Legal Notices
Patent Notice: DROS deterministic runtime execution governance and in-band interception technology is protected under U.S. Provisional Patent Application (U.S. PPA No. 64/111,973, Patent Pending). All commercial rights reserved by Top-Celestial Company Ltd.
๐น๐ผ ็น้ซไธญๆ่ชชๆ
้็จๅ AI Agent ็ขบๅฎๆง้่กๆๅฎๅ จๆฒป็่ๅพฎ็ง็ด็ๆทๅพฎๆ ธๅฟใๅ็้ฉ้ DeepSeek Harness (DSH) ๅคๆ๏ผๅๆๅฏไฝ็บ Docker ๆฌๅฐ Sidecar ๅฎ่ญท AGY (Google Antigravity)ใOpenAI CodexใClaude CodeใCursor ่ OpenClaw ็ญๅ้ก Agentใ
๐ฏ ๆ ธๅฟๆถๆงๅฎไฝ๏ผไธๅฅ่ฉฑๆ่งฃ่ช็ฅ๏ผ๏ผ
DSH ๆฏ DROS ็็คพ็พคๅ ฅๅฃ๏ผDROS ๆฏ่ทจ Agent ็ๅท่กๆฒป็ๅฑคใ
ๅๅพๅ
ฅๅฃ (GET IT HERE)
DSH ๅธ้ๅคๆ
โ
โ ๆธ ้ๅ็ผ (distribution)
โผ
DROS VajraClaw
โ
้จ็ฝฒๅฝขๆ
(DEPLOY IT HERE)
Docker / Sidecar
โ
โโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโ
โผ โผ โผ
DSH AGY Codex ... (Claude, Cursor, OpenClaw)
โ โ โ
โโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโ
โผ
DROS ๆฒป็้็ (Enforcement)
โ
โโโโโโโโโโโโโโโผโโโโโโโโโโโโโโ
โผ โผ โผ
MCP API CLI
๐ ใๅไบบ้็ผ่ ็คพ็พค็๏ผๅค Agent ๅทฅไฝ็ซๆฐธไน ๅ ่ฒปใ
- ๐ก๏ธ ๅไบบไฝฟ็จ๏ผ้ๅๆฅญ็จ้๏ผ 100% ๆฐธไน ๅ ่ฒป๏ผ็บๆฌๆฉๅค Agent ๅทฅไฝ็ซๅปบ็ซ็ตฑไธๅฎๅ จ้็๏ผๆฏๆดๆๅค 5 ๅไธฆ็ผ Agent๏ผใ
- ๐ชช ไธๅฑคๅฏ็ขผๅญธๆถๆงๆจกๅ (
RFC-010)๏ผ
- ไธป้ซ่บซๅ (Identity)๏ผๅ็ W3C DID ้้ฐ็ถๅฎ (
did:key:z6Mku...)ใ- ๅท่กๅญ่ญ (Evidence)๏ผๆฏๆฌก Tool ๅท่ก็ข็ Ed25519 ๆธไฝ็ฐฝ็ซ ใ
- ไธๅฏๅฆ่ช่ฟฝๆบฏ (Accountability)๏ผ้ฒ็ฏกๆนไนๆฌๆฉ JSON ๅฏฉ่จๅญ่ญ้ใ
- โก Universal Docker ็ถฒ้๏ผๅๆไฟ่ญท DSH ๅคๆใMCP ๆๅๅจ่ๅ้ก็ต็ซฏ CLI Agentใ
๐๏ธ ๆ ธๅฟๅฒๅญธ๏ผๅผ้ ้ๆบ่ณๅฎ้ฃ็๏ผๅฎ่ญทๆฅต่ด้ๆพ็ๆไปถ็ๆ
DeepSeek Harness (DSH) ็ๅๅคงไน่ๅจๆผๅ ถๆฅต่ด็้ๆพๆงโโใไธๅ็ๆไปถ (Everything is a plugin)ใใ็ถ่๏ผๆฅต่ด็้ๆพๅฟ ็ถไผด้จ่ๆปๆ้ข็็ก้ๆพๅคง๏ผ
- ็ฌฌไธๆนๆกๆๅคๆๅฏ่ฝไผๅ่ถๆฌ่ฎๆชใ็ฏกๆนๅ จๅ่จๆถ้ซ๏ผๆๆไธญๅฐๆธๆ็ผๅพๅค้จ C2 ไผบๆๅจใ
- DROS ๆฎๆผไบใ้ๆบ่ณๅฎ่็ถฒ็ฎก็้ ้ ญ็พ่ๆ ธๅฟๅฎ้จใ๏ผๆๆ Falco eBPFใCilium ็ถฒ่ทฏ้้ข่ Wazuh ๅฏฉ่จ๏ผ็บๅ จ็้็ผ่ ๆถๆง่ตทๅฎๆด็็ซ้ซ้ฒ็ฆฆ็ธฑๆทฑ๏ผ่ฎๆฏไฝ Agent ็ฉๅฎถ้ฝ่ฝๅฎๅฟไบซๅ้ๆบ็ๆ ็่ช็ฑ๏ผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. ๆ็จ็จๅผๅ
ง้จๅฑค (In-App Layer: DSH ๅ
ง้จๆไปถ) โ <โโ ๐ข ๅๅฐๅฎๆชข (Prompt Filter)
โ - NeMo / Llama-Guard: ่ฒ ่ฒฌๅฐ่ฉฑ่ชๆๅฏฉๆฅ่ไธ่ฏๅ
งๅฎน้ๆฟพ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ (้้่ชๆๅฏฉๆฅ๏ผAgent ็ผ่ตท Tool Call)
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. ้่กๆๆฒป็้้ (Runtime Gateway: DROS VajraClaw) โ <โโ ๐๏ธ ้ๅบซๅฎ่ก (Execution Identity)
โ - W3C DID ่บซๅๆ็ด + 364ns ๆฌ้้ป้ฃๆฅ่กจ โ ๆๅฎๅบๆบๆธฌ่ฉฆ้
็ฝฎไธๅท่ก่ทฏๅพๅปถ้ฒ <1 ฮผs๏ผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ (ๆพ่กๅๆณ็ Syscall / Egress ๆต้)
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. ๅบ็ค่จญๆฝ่ๆ ธๅฟๅฑค (Infra SecOps: OpenShip / Falco / Cilium)โ <โโ ๐ ็น่ญฆ้ฒ็ท (Kernel & Network Fabric)
โ - Cilium ๅฐ้ๆกๆๅค็ผ๏ผFalco eBPF ๆ ธๅฟๅฑคๆๆๅฎนๅจ้้ธ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
๐งญ ๆฒป็้็๏ผDROS ๅฎ่ญทไป้บผ vs. ไธๅฎ่ญทไป้บผ
็บไบ็ถญ่ญทๆฅต่ดๅด่ฌน็ๅทฅ็จ็็ท่้ฒ็ฆฆ็ฏ็๏ผDROS ๆ็ขบๅๅฎ้็๏ผ
| ๆปๆๆๆณ่ๅจ่ ๆ ๅข | ๅณ็ตฑ่ชๆ Guardrails | DROS VajraClaw ็ฉ็ๅพฎๆ ธๅฟ | ๆ็ต้ฒ็ฆฆๆๆ |
|---|---|---|---|
| ้ๆฅๆ็คบ่ฉๆณจๅ ฅ (็ถฒ้ /PDF ๅคพๅธถๆไปค่ฉ้จ Agent ๅชๅบซ) | โ LLM ่ชๆๆททๆทๆ่ขซ็น้ | โ ็ขบๅฎๆงๆๆช | ็ขบๅฎๆงๅธถๅ ง็ฉ็็ๆท (<1ฮผs ๅบๆบๆธฌ่ฉฆ้ป้ฃๆฅ่กจ) |
| ๅดๅ่ถๆฌ่ชฟ็จ (ๆชๆๆฌๅคๆๅทๅทๅผๅซ DB/ไปๆฌพ Tool) | โ ๆ็จๅฑค้่ผฏ่ๅผฑ | โ ๅฏ็ขผๅญธ้ปๆท | 100% ้ปๆท (ๅจๅฎ็พฉไนๅจ่ ๆจกๅ่ Capability ๅ้ๅ ง) |
| ็ง่ชๅค็ผๆดฉๅฏ (ๅคๆ็ง่ช้ฃ็ทๅค้จ C2 ๅณ่ผธๆฉๅฏ) | โ LLM ๅฎๅ จ็กๆ | โ ็ถฒ่ทฏๅพฎ้้ข | 100% ไธๅ
(internal: true ๆฒ็ๆๆฒ) |
| ๅฎนๅจ้้ธ่ๅฎฟไธปๆฉๆๆฌ | โ ็กไธปๆฉๆ ธๅฟ่ฆ่ง | โ ๏ธ ๅๅ Falco eBPF | ๆ ธๅฟๅฑคๆๆ (cap_drop: ALL ็นๆฌๅๅฅช้้ข) |
| ๆฅญๅ้่ผฏ้ฏ่ชค่ๆจกๅๅนป่ฆบ | โ ่ถ ๅบ่ณๅฎ็ฏ็ | โ ่ถ ๅบ่ณๅฎ็ฏ็ | ๅฑฌ LLM ็ๆๅ่ณช๏ผ็ฑ Prompt ๅทฅ็จ่ QA ๆต็จๅชๅ |
๐ ้ถไฟกไปป้้ฐ่ Root ๆๆด็ๆญป่ญฆ็คบ
DROS ๅดๆ ผ่ฒซๅพน ้ถไฟกไปปๅฏ็ขผๅญธๆถๆง๏ผ
- ๅๅป ็กๅพ้่ฒๆ (No Backdoors)๏ผๅๅป ็กไปปไฝ่ฌ็จ้้ฐใๆจ็ Ed25519 ็ง้ฐ็จฎๅญ (Seed Hex) ๅ ๅญๅจๆฌๅฐ่จๆถ้ซ๏ผ่ซๅๅฟ ่ช่กๅฆฅๅๅไปฝ่ณๅฏ็ขผๅบซ (1Password / Bitwarden)ใ
- ้ๅปบไฟกไปปๆ น (Rebuilding Root of Trust)๏ผ่ฅ้บๅคฑ็ง้ฐ๏ผๅฏๆๅจไฟๆไผบๆๅจๆ้ซ Root / SSH ็ฎก็ๅกๆฌ้ ็ๅๆไธ๏ผๆนๅฏๆๅๆฟๆ้ฉ่ญๅ ฌ้ฐไปฅ้ๅปบไฟกไปปๆ นใ
๐ ้็จๅค Agent ๆททๅๅทฅไฝ็ซๆๆฒ (DSH + AGY + Codex + Claude)
DROS ้ไปฅ DSH ๅคๆๅฝขๅผๆไพไธ้ตๅฎ่ฃ๏ผไฝๅบๅฑคๆฏ ๆจๆบๅ Docker ๅฎนๅจ (localhost:8080)๏ผๅฎๅฐ้็ผๆฉๅฏๅๆๅฎ่ญทๅคๅไธๅๅนณๅฐ็ๆดป่บ Agent๏ผๅ
ฑ็จ 5 ๅไธฆ็ผ้
้ก๏ผ๏ผ
- DSH ไฝฟ็จ่
โ ้้
dsh-plugin-vajraclawๆฅๅ ฅใ - Google Antigravity (AGY) โ ้้ MCP ็ถฒ้ๆ Python SDK ๆฅๅ ฅใ
- OpenAI Codex / Claude Code / Cursor โ ้้ๆฌๅฐ REST API / Hook ๆๆชๆฅๅ ฅใ
๐ก ๆๆฐๅฎๅน่ๆนๆก่ซไปฅ ๅฎๆน็ถฒ็ซ (dr-os.io) ๅ ฌๅธ็บๆบใ
| ๅฎๅ จๅ่ฝ / 6-Pillar ๆฉๅถ็ถญๅบฆ | ๐ข Hacker / ๅไบบ็คพ็พค็ (ๅ ่ฒป) | ๐ต Startup | ๐ฃ Enterprise | ๐ Sovereign |
|---|---|---|---|---|
| ็ฎๆจๅฎขๆถ | ๅไบบ้็ผ่ / ๆฌๆฉๅค Agent ็ฉๅฎถ | 10~50ไบบๆฐๅตๅ้ | ไธญๅคงๅไผๆฅญ / ไธๅธๅ ฌๅธ | ้่้ๆง / ๅ้ฒ |
| ๆฉๅจๆๆฌ (UUIDs) | 1 ็ต UUID | 3 ็ต UUIDs | 15 ็ต UUIDs | ็ก้ๅถ |
| Concurrent Agents ไธ้ | 5 ๅไธฆ็ผ Agent | 30 ๅ | 450 ๅ | ็ก้ๅถ (Swarm) |
| Pillar 1๏ผPrincipal ่บซไปฝ่ญๆ | โ
ๅ็ W3C did:key ๆ็ด |
โ 3-Tier PKI DIT | โ ่ทจๅ BEC ๆ่ญ็ผๆพ | โ ็กฌ้ซ Dongle ๅฐ่จ |
| Pillar 2๏ผAuthorization ๆฌ้ๅ้ | โ AST ้ป้ฃๅๆฏๅฐ | โ ้ถๅ ็ฉ Bitmaps | โ ๅ จ่ช่จ Capability ๅ้ | โ ๅๆ ไฝๅ ๅๅค็ถญ็ฉ้ฃ |
| Pillar 3๏ผTool Bound ๅทฅๅ ท้็ | โ C-ABI / HTTP ็ๆท (<1ฮผs) | โ 26.1ฮผs ๅธถๅ ง็ๆท | โ Sub-500ns Thread Panic | โ ๆถ็็กฌ้ซ็ด็ฉ็็ๆท |
| Pillar 4๏ผPolicy Gate ไธๅคง้้ฅ | โ ๅ ้ๆ ่ฆๅ | โ ๅๆ PII ้ฎ่ฝ | โ HITL ้็ฐฝ + ZKP-Lite | โ ่ป่ฆ็ด้้ฅ็ฉ้ฃ |
| Pillar 5๏ผAudit Log ็จฝๆ ธ่ฟฝๆบฏ | โ Ed25519 ็ฐฝ็ซ ๆฅ่ช | โ Ed25519 ๆธไฝ็ฐฝ็ซ | โ SHA-256 Merkle ้ๆน้ | โ ไธๅฏๅฆ่ชๆงๆณ้ข็ดๆ่ญ |
| Pillar 6๏ผExpiry/Revocation ็งๆค | โ ้้ๅ Gateway | ๐ก 15ๅ้ BEC ้ๆ | โ <1ฮผs RCU ๅๅญๆ้ๅๆ | โ ๅๆฃๅผ็ง็ด็ถฒๆ ผๆค้ท |
| RFC-010 ้ๆพ Agent ่ญท็ งๆ ผๅผ | โ ๆฌๅฐๅฎๆด็ฐฝ็ซ ็ผ่ก | โ ๅค่ง่ฒ DIT ็ฐฝ็ฝฒ | โ ไผๆฅญ GuardVM ้ไธญ้ฉ่ญ | โ ๅ้ฒ็ด 3-Tier ็ฐฝ็ซ ้ |
| ้ๆพๅฝๆงๅ ่ณผ็ขๆฅญๅ่ฆ Package | โ ไธ้ๆพๅ ่ณผ | ๐ก ้ๆพๅฝๆงๅ ่ณผ | โญ ้ๆพๅฝๆงๅ ่ณผ | โ ๅ ๅซๅฎๆดๆฌ้ |
| ้จ็ฝฒ่ผ้ซ | Local PC / ๅค Agent Docker ็ถฒ้ | VM / NAS Docker | K8s / GKE / Cluster | Air-Gapped / FPGA |
๐ 30 ็งๆฅต้ไธๆ
ๆญฅ้ฉ 1๏ผๅๅ DROS Docker ็ถฒ้
docker run -d -p 8080:8080 --name dros-gateway dros/hacker-gateway:v1.0.0
ๆญฅ้ฉ 2๏ผ้ฃๆฅๆจ็ Agent
- DSH ไฝฟ็จ่
๏ผๅฎ่ฃๅคๆๅณๅฏ่ชๅ้ฃ็ท๏ผ
dsh plugin --profile web add dsh-plugin-vajraclaw - AGY / Codex / Claude Code / Cursor / Python SDK ไฝฟ็จ่
๏ผ
ๅ
้้
็ฝฎๅ
ฉ่ก็ฐๅข่ฎๆธ๏ผๅณๅฏ็ซๅณๅฐๆฌๆฉ Agent ็ดๅ
ฅ DROS ๅพฎ็ง็ดๅท่กๆฒป็่ W3C DID ๅญ่ญ้็๏ผ
export DROS_GATEWAY_URL="http://localhost:8080" export DROS_IDENTITY_SEED="0x1a2b3c4d..." # ๆฌๆฉๅฐๅฑฌ Ed25519 ็ง้ฐ็จฎๅญ Hex
๐ ๐ ้ฑ่ฎ้ฒ้่ณๅฎ่ๅค Agent ๆๆฒๅ ๅบๆๅ (docs/ADVANCED_SECOPS_GUIDE.md)๏ผ็ฒๅ internal: true ็ถฒ่ทฏๅพฎ้้ข Compose ็ฏๆฌใFalco eBPF ๆ ธๅฟ้ฒ้้ธ่ Wazuh SIEM ๆดๅๆๅ๏ผใ
๐ ็ธ้ๆ่กๆ ธๅฟ่ซๆ่ๅฏฆๆธฌ้ฉ่ญ (Technical Foundations & Benchmarks)
ๆฌๅฐๆกไน็ขบๅฎๆงๅท่กๆฒป็ใๅพฎ็ง็ด็ๆท่ๅฏ็ขผๅญธๅญ่ญๆฉๅถ๏ผๅ่ไธฆๅปถไผธ่ชไปฅไธๆ ธๅฟๆ่ก่ซๆ่้ๆบๅฏฆๆธฌ็ฐๅข๏ผ
ๆ ธๅฟๆถๆง่ๅ ญๅคงไฟกไปป้็ (Core Architecture):
- DROS-6P: A Unified Deterministic Runtime Governance Architecture Closing the Six Fundamental Trust Boundaries of Enterprise AI Agents
- Zenodo DOI:
10.5281/zenodo.21833970| ่จ้ๅ ธ่: zenodo.org/records/21833970
ๅๅฑคๆทฑๅบฆ้ฒ็ฆฆๆถๆง (Defense-in-Depth Model):
- DROS 4-Layer Defense-in-Depth Architecture for Autonomous AI Workloads
- Zenodo DOI:
10.5281/zenodo.21903475| ่จ้ๅ ธ่: zenodo.org/records/21903475
ๅคๆ FFI ่ไธๅฏๅฆ่ชๅญ่ญๆจก็ต (Runtime Attribution Framework):
- Runtime Attribution Framework: An External C-ABI and PKI-Based Zero-Trust Infrastructure for Non-Repudiable Execution Governance in Multi-Agent Systems
- Zenodo DOI:
10.5281/zenodo.21903687| ่จ้ๅ ธ่: zenodo.org/records/21903687
้ๆบๆ่กๆจๆบ่ๅฏฆๆธฌๅบๆบๅ (Open Standard & Verification Sandbox):
- RFC-010 ่ฆ็ฏ: ้ตๅพช้ๆพ Agent ่บซๅ่ๅญ่ญ่ฆ็ฏ๏ผW3C DID
did:key่ Ed25519 ็ฐฝ็ซ ้๏ผใ - ๅฏฆๆธฌๅบๆบ็ฐๅข: DROS-VEP Lite (ๅฏๅพฉ็พๅฎๅ จ่ฉๆธฌๆฒ็)
- ๅฏฆๆธฌๅ ฑๅ: ๆถต่ 24 ๅฐๆ้ทๆๅคๅ ดๆฏๆธฌ่ฉฆๆธๆ๏ผ160,611 ๆฌก่ซๆฑ้ฉ่ญ๏ผๆฑบ็ญๅปถ้ฒ 26.1ฮผs๏ผใ
- RFC-010 ่ฆ็ฏ: ้ตๅพช้ๆพ Agent ่บซๅ่ๅญ่ญ่ฆ็ฏ๏ผW3C DID
๐๏ธ ๅฎๆน็ผ่ก็ต็น่่ฏ็นซ่ณ่จ (Official Contact)
- ็ผ่กไธป้ซ๏ผTop-Celestial Company Ltd. (ๅบทๅฎธๅๆ้ๅ ฌๅธ)
- ๅฎๆน็ถฒ็ซ๏ผhttps://dr-os.io
- ๅฎขๆถๆๅ่ๅๅ่ซฎ่ฉข๏ผ[email protected]
- GitHub ๅฎๆน็ต็น๏ผhttps://github.com/Top-Celestial-Company-Ltd
๐ ๅฐๅฉ่ๆณๅพ่ฒๆ
ๅฐๅฉ่ฒๆ๏ผ DROS ๅท่กๆฒป็่ๅฎๅ จๆ่กๅทฒ็ณ่ซ็พๅ่จๆๅฐๅฉไฟ่ญท๏ผU.S. Provisional Patent Application No. 64/111,973๏ผPatent Pending๏ผใ