Plugin directory / Developer / dsh-credentials-system
dsh-credentials-system
Verified · install-tested on dsh khiqwq
What it does
System-bound encrypted credential provider for DeepSeek Harness
Works — verified, early-stage project
System-bound encrypted credential provider for DeepSeek Harness It installs cleanly and boots without issues in our testing. It's early-stage but functional.
“Verified” means our automated CI actually ran dsh plugin add in a clean profile and it booted — nothing more. Feature descriptions and version compatibility are the author’s claims. This is not a security audit and not an endorsement of third-party code.
README
dsh-credentials-system
DeepSeek Harness credential provider backed by the operating system's user-bound secret protection. Version 0.1 supports Windows x64/ARM64 through DPAPI CurrentUser.
Security properties
$DSH_HOME/.credentials.system.jsoncontains only versioned DPAPI ciphertext and reference names.- A blob is bound to the current Windows user, this store id, and its exact credential reference.
- There is no plaintext-file, environment-variable, machine-wide, or local-key fallback.
describe()returns onlyconfigured,source, andwritable; there is no reveal API.- Wrong user, damaged ciphertext, unavailable native backend, and malformed storage fail loudly.
- Explicit portable exports use
scryptplus AES-256-GCM; the passphrase and plaintext are never written beside the export.
This protects a copied credential file and prevents routine configuration views from disclosing values. It cannot protect secrets from malicious code already executing as the Harness process, memory inspection, a compromised Windows account, or a proxy that necessarily receives its own authentication credential.
DeepSeek Harness composition
Replace the built-in plaintext provider; never run it as an automatic fallback:
- id: credentials
name: '@deepseek-ai/dsh-credentials-local'
disabled: true
- insert:
- id: credentials-system
name: dsh-credentials-system
Consumers store only references, for example:
proxies:
office:
url: http://proxy.example:8080
username: alice
passwordRef: DSH_PROXY_OFFICE_PASSWORD
The Harness plugin configuration UI should submit a new value through the write-only credentials API. It must render an empty password field plus 锟斤拷configured/not configured锟斤拷, never a decrypted value or ciphertext.
Migrating the legacy plaintext file
provider.migrateLegacy({ refs?, archive? }) performs an explicit Host-side migration from $DSH_HOME/.credentials.yaml:
- strictly parse the bounded YAML mapping;
- list/select refs without returning values to a browser;
- DPAPI-encrypt each selected value;
- resolve and compare it in memory to verify the write;
- optionally rename the source to
.credentials.yaml.migratedonly when every entry migrated.
The renamed file is still plaintext. Delete it after verifying the new provider; it is retained rather than automatically destroyed so an interrupted migration cannot cause credential loss. Partial migration never renames or deletes the source.
Portable export
Portable export is an explicit backup/migration operation, not the runtime backend. The complete payload锟斤拷including reference names锟斤拷is encrypted using scrypt (N=131072, r=8, p=1) and AES-256-GCM. A wrong passphrase and a damaged file intentionally return the same error.
Important DSH distinction
@deepseek-ai/dsh-credentials-local stores plaintext in $DSH_HOME/.credentials.yaml. Owner-only file permissions and role("secret") redaction are useful boundaries, but they are not encryption. This provider must not silently fall back to it.
Install
Install the catalog once, then DeepSeek Harness can find and install any plugin from this site automatically:
dsh plugin add dshbase-catalog Then say "install dsh-credentials-system for me" — your agent finds it in the directory and installs it. Docs: dshbase-catalog · verified packs.
This plugin is GitHub source (not published to npm) — install it straight from the repo:
Web profile:
dsh plugin --profile web add github:khiqwq/dsh-credentials-system Headless (CLI) profile:
dsh plugin --profile headless add github:khiqwq/dsh-credentials-system Test report
Verified: L1 install + L2 load + L3 runtime from GitHub source on dsh 0.1.0-rc.6.
When to use it
Extend the agent's coding surface — give it a new tool, workflow, or integration so it handles a dev task it couldn't before.
Who it's for
Developers who want dsh to behave like a teammate on real codebases — editing, running, and verifying changes rather than just answering.
For developers — extending it
The tool/command surface is the seam: expose more of the SDK, add smarter context wiring, or tighten the loop between code changes and verification.