dshbase

Plugin directory / Network / dsh-credentials-keychain

dsh-credentials-keychain

Verified · install-tested on dsh ShawnSiao

✓ Actively maintained

View on GitHub ↗ ← Back to plugin directory

1Stars
0Forks
0Open issues
unknownLanguage
2026-08-15Last push
Cross-platformPlatform

What it does

Planned OS-backed credential provider for DeepSeek Harness

✅
Our take
Works — verified, early-stage project

Planned OS-backed credential provider for DeepSeek Harness It installs cleanly and boots without issues in our testing. It's early-stage but functional.

“Verified” means our automated CI actually ran dsh plugin add in a clean profile and it booted — nothing more. Feature descriptions and version compatibility are the author’s claims. This is not a security audit and not an endorsement of third-party code.

README

dsh-credentials-keychain

English | 简体中文

An OS-backed credential provider bundle for DeepSeek Harness.

Status: design and implementation planning. This repository does not yet contain an installable plugin.

Goal

Replace the default file-backed credentials row with a provider that keeps writable secrets in an operating-system credential store while preserving the existing ctx.credentials API used by model and web providers.

The first release should require no new secret-management workflow inside DeepSeek Harness: existing settings surfaces continue to call describe(), set(), and unset(), and consumers continue to resolve CredentialRef values per operation.

Planned user experience

Installation will use the normal profile bundle command:

dsh plugin --profile web add github:ShawnSiao/dsh-credentials-keychain

The bundle will replace the base profile's credentials row. Existing model settings remain the primary UI; no model-facing tool will expose or enumerate secret values.

Scope

  • Preserve inherited environment variables as the highest-precedence, read-only source for CI and one-off launches.
  • Store writable values in Windows Credential Manager, macOS Keychain, or Linux Secret Service.
  • Report only configured state, source, and writability to UI consumers.
  • Publish credentials/updated only after a committed write or removal.
  • Fail loudly when the selected backend is unavailable or its security guarantees do not satisfy configured policy.

Security stance

An OS credential store improves at-rest handling, but it is not automatically a hard boundary against every process running as the same user. The implementation will publish a platform capability matrix and will not claim stronger isolation than each backend can prove.

High-assurance options such as user-presence requirements or application-bound access will be separate, explicit modes. Silent fallback to plaintext files is out of scope.

See the implementation plan for architecture, phases, acceptance criteria, and open security decisions.

Compatibility baseline

Planning is based on DeepSeek Harness master commit 47f943859b and package version 0.1.0-rc.5 as observed on 2026-08-13. DeepSeek Harness is in developer preview; implementation work must recheck public APIs before each release.

License

MIT

Install

🧩 Let your agent install it (recommended)

Install the catalog once, then DeepSeek Harness can find and install any plugin from this site automatically:

dsh plugin add dshbase-catalog

Then say "install dsh-credentials-keychain for me" — your agent finds it in the directory and installs it. Docs: dshbase-catalog · verified packs.

This plugin is GitHub source (not published to npm) — install it straight from the repo:

Web profile:

dsh plugin --profile web add github:ShawnSiao/dsh-credentials-keychain

Headless (CLI) profile:

dsh plugin --profile headless add github:ShawnSiao/dsh-credentials-keychain

Test report

Verified: L1 install + L2 load + L3 runtime from GitHub source on dsh 0.1.0-rc.6.

When to use it

Give the agent network access — requests, APIs, proxies, or protocols — so it can reach external systems.

Who it's for

Users whose tasks touch the network — calling APIs, fetching resources, or talking to remote services.

For developers — extending it

Adapters and request shaping are the seams — add protocols, auth handlers, retries, and endpoint abstractions.

Security: not yet scanned — our daily static scan will cover it shortly.

Share this badge

More in Network

Browse all 7797 plugins →