插件目录 / Network / dsh-credentials-keychain
dsh-credentials-keychain
已验证 · 实测可装 ShawnSiao
功能简介
dsh-credentials-keychain — DSH 插件(桥接)
可用 — 实测通过,早期项目
dsh-credentials-keychain — DSH 插件(桥接) 实测能干净安装、正常启动。早期项目,但功能可用。
「已验证」表示我们的自动化 CI 在干净 profile 里实际执行了 dsh plugin add 并启动成功——仅此而已。功能描述与版本兼容性均为作者声明。这不是安全审计,也不代表对第三方代码的背书。
README
dsh-credentials-keychain
English | 简体中文
An OS-backed credential provider bundle for DeepSeek Harness.
Status: design and implementation planning. This repository does not yet contain an installable plugin.
Goal
Replace the default file-backed credentials row with a provider that keeps writable secrets in an operating-system credential store while preserving the existing ctx.credentials API used by model and web providers.
The first release should require no new secret-management workflow inside DeepSeek Harness: existing settings surfaces continue to call describe(), set(), and unset(), and consumers continue to resolve CredentialRef values per operation.
Planned user experience
Installation will use the normal profile bundle command:
dsh plugin --profile web add github:ShawnSiao/dsh-credentials-keychain
The bundle will replace the base profile's credentials row. Existing model settings remain the primary UI; no model-facing tool will expose or enumerate secret values.
Scope
- Preserve inherited environment variables as the highest-precedence, read-only source for CI and one-off launches.
- Store writable values in Windows Credential Manager, macOS Keychain, or Linux Secret Service.
- Report only configured state, source, and writability to UI consumers.
- Publish
credentials/updatedonly after a committed write or removal. - Fail loudly when the selected backend is unavailable or its security guarantees do not satisfy configured policy.
Security stance
An OS credential store improves at-rest handling, but it is not automatically a hard boundary against every process running as the same user. The implementation will publish a platform capability matrix and will not claim stronger isolation than each backend can prove.
High-assurance options such as user-presence requirements or application-bound access will be separate, explicit modes. Silent fallback to plaintext files is out of scope.
See the implementation plan for architecture, phases, acceptance criteria, and open security decisions.
Compatibility baseline
Planning is based on DeepSeek Harness master commit 47f943859b and package version 0.1.0-rc.5 as observed on 2026-08-13. DeepSeek Harness is in developer preview; implementation work must recheck public APIs before each release.
License
安装
装一次目录插件,之后本站所有插件都能让 DeepSeek Harness 自动找、自动装:
dsh plugin add dshbase-catalog 然后对 agent 说「帮我装 dsh-credentials-keychain」,它会在目录里找到并自动安装。文档:dshbase-catalog · 已验证场景包。
该插件是 GitHub 源码(未发 npm)——直接从仓库装:
Web profile:
dsh plugin --profile web add github:ShawnSiao/dsh-credentials-keychain Headless(CLI)profile:
dsh plugin --profile headless add github:ShawnSiao/dsh-credentials-keychain 实测报告
验证通过:从 GitHub 源码完成 L1 安装 + L2 加载 + L3 运行(dsh 0.1.0-rc.6)。
使用场景
给 agent 网络能力——请求、API、代理或协议——让它能触达外部系统。
适合谁
任务涉及网络的人——调 API、抓资源或与远端服务通信。
二次开发建议
适配器和请求整形是缝——加协议、鉴权处理器、重试和端点抽象。