dshbase

插件目录 / Developer / dsh-credentials-system

dsh-credentials-system

已验证 · 实测可装 khiqwq

✓ 持续维护 基于 4 个官方 DSH 包

查看 GitHub ↗ ← 返回插件目录

0Stars
0Forks
0未关闭 issue
JavaScript语言
2026-08-15最近推送
跨平台平台

功能简介

DSH系统绑定加密凭据提供者。

✅
我们的评价
可用 — 实测通过,早期项目

DSH系统绑定加密凭据提供者。 实测能干净安装、正常启动。早期项目,但功能可用。

「已验证」表示我们的自动化 CI 在干净 profile 里实际执行了 dsh plugin add 并启动成功——仅此而已。功能描述与版本兼容性均为作者声明。这不是安全审计,也不代表对第三方代码的背书。

README

dsh-credentials-system

DeepSeek Harness credential provider backed by the operating system's user-bound secret protection. Version 0.1 supports Windows x64/ARM64 through DPAPI CurrentUser.

Security properties

  • $DSH_HOME/.credentials.system.json contains only versioned DPAPI ciphertext and reference names.
  • A blob is bound to the current Windows user, this store id, and its exact credential reference.
  • There is no plaintext-file, environment-variable, machine-wide, or local-key fallback.
  • describe() returns only configured, source, and writable; there is no reveal API.
  • Wrong user, damaged ciphertext, unavailable native backend, and malformed storage fail loudly.
  • Explicit portable exports use scrypt plus AES-256-GCM; the passphrase and plaintext are never written beside the export.

This protects a copied credential file and prevents routine configuration views from disclosing values. It cannot protect secrets from malicious code already executing as the Harness process, memory inspection, a compromised Windows account, or a proxy that necessarily receives its own authentication credential.

DeepSeek Harness composition

Replace the built-in plaintext provider; never run it as an automatic fallback:

- id: credentials
  name: '@deepseek-ai/dsh-credentials-local'
  disabled: true

- insert:
    - id: credentials-system
      name: dsh-credentials-system

Consumers store only references, for example:

proxies:
  office:
    url: http://proxy.example:8080
    username: alice
    passwordRef: DSH_PROXY_OFFICE_PASSWORD

The Harness plugin configuration UI should submit a new value through the write-only credentials API. It must render an empty password field plus 锟斤拷configured/not configured锟斤拷, never a decrypted value or ciphertext.

Migrating the legacy plaintext file

provider.migrateLegacy({ refs?, archive? }) performs an explicit Host-side migration from $DSH_HOME/.credentials.yaml:

  1. strictly parse the bounded YAML mapping;
  2. list/select refs without returning values to a browser;
  3. DPAPI-encrypt each selected value;
  4. resolve and compare it in memory to verify the write;
  5. optionally rename the source to .credentials.yaml.migrated only when every entry migrated.

The renamed file is still plaintext. Delete it after verifying the new provider; it is retained rather than automatically destroyed so an interrupted migration cannot cause credential loss. Partial migration never renames or deletes the source.

Portable export

Portable export is an explicit backup/migration operation, not the runtime backend. The complete payload锟斤拷including reference names锟斤拷is encrypted using scrypt (N=131072, r=8, p=1) and AES-256-GCM. A wrong passphrase and a damaged file intentionally return the same error.

Important DSH distinction

@deepseek-ai/dsh-credentials-local stores plaintext in $DSH_HOME/.credentials.yaml. Owner-only file permissions and role("secret") redaction are useful boundaries, but they are not encryption. This provider must not silently fall back to it.

安装

🧩 让 Agent 自动装(推荐)

装一次目录插件,之后本站所有插件都能让 DeepSeek Harness 自动找、自动装:

dsh plugin add dshbase-catalog

然后对 agent 说「帮我装 dsh-credentials-system」,它会在目录里找到并自动安装。文档:dshbase-catalog · 已验证场景包。

该插件是 GitHub 源码(未发 npm)——直接从仓库装:

Web profile:

dsh plugin --profile web add github:khiqwq/dsh-credentials-system

Headless(CLI)profile:

dsh plugin --profile headless add github:khiqwq/dsh-credentials-system

实测报告

验证通过:从 GitHub 源码完成 L1 安装 + L2 加载 + L3 运行(dsh 0.1.0-rc.6)。

使用场景

扩展 agent 的编码能力面——给它一个新工具、工作流或集成,让它接手以前做不了的开发任务。

适合谁

想让 dsh 在真实代码库上像队友一样干活的开发者——能改、能跑、能验证,而不只是回答问题。

二次开发建议

工具/命令面就是缝:暴露更多 SDK 能力、加更聪明的上下文接线,或收紧改代码与验证之间的循环。

安全:尚未扫描——我们的每日静态扫描将很快覆盖它。

分享徽章

Developer 里更多

浏览全部 7797 个插件 →