설치
npx -y @deepseek-ai/dsh plugin --profile web add github:khiqwq/dsh-credentials-system이 설치 명령은 GitHub 저장소 주소에서 생성된 확인되지 않은 시작점입니다.
README
유지 관리자가 작성한 문서 스냅샷입니다.
dsh-credentials-system
DeepSeek Harness credential provider backed by the operating system's user-bound secret protection. Version 0.1 supports Windows x64/ARM64 through DPAPI CurrentUser.
Security properties
$DSH_HOME/.credentials.system.jsoncontains only versioned DPAPI ciphertext and reference names.- A blob is bound to the current Windows user, this store id, and its exact credential reference.
- There is no plaintext-file, environment-variable, machine-wide, or local-key fallback.
describe()returns onlyconfigured,source, andwritable; there is no reveal API.- Wrong user, damaged ciphertext, unavailable native backend, and malformed storage fail loudly.
- Explicit portable exports use
scryptplus AES-256-GCM; the passphrase and plaintext are never written beside the export.
This protects a copied credential file and prevents routine configuration views from disclosing values. It cannot protect secrets from malicious code already executing as the Harness process, memory inspection, a compromised Windows account, or a proxy that necessarily receives its own authentication credential.
DeepSeek Harness composition
Replace the built-in plaintext provider; never run it as an automatic fallback:
- id: credentials
name: '@deepseek-ai/dsh-credentials-local'
disabled: true
- insert:
- id: credentials-system
name: dsh-credentials-system
Consumers store only references, for example:
proxies:
office:
url: http://proxy.example:8080
username: alice
passwordRef: DSH_PROXY_OFFICE_PASSWORD
The Harness plugin configuration UI should submit a new value through the write-only credentials API. It must render an empty password field plus “configured/not configured”, never a decrypted value or ciphertext.
Migrating the legacy plaintext file
provider.migrateLegacy({ refs?, archive? }) performs an explicit Host-side migration from $DSH_HOME/.credentials.yaml:
- strictly parse the bounded YAML mapping;
- list/select refs without returning values to a browser;
- DPAPI-encrypt each selected value;
- resolve and compare it in memory to verify the write;
- optionally rename the source to
.credentials.yaml.migratedonly when every entry migrated.
The renamed file is still plaintext. Delete it after verifying the new provider; it is retained rather than automatically destroyed so an interrupted migration cannot cause credential loss. Partial migration never renames or deletes the source.
Portable export
Portable export is an explicit backup/migration operation, not the runtime backend. The complete payload—including reference names—is encrypted using scrypt (N=131072, r=8, p=1) and AES-256-GCM. A wrong passphrase and a damaged file intentionally return the same error.
Important DSH distinction
@deepseek-ai/dsh-credentials-local stores plaintext in $DSH_HOME/.credentials.yaml. Owner-only file permissions and role("secret") redaction are useful boundaries, but they are not encryption. This provider must not silently fall back to it.
프로젝트 파일 및 신호
표시된 항목은 디렉터리 스냅샷에서 감지된 공개 저장소 신호입니다.
저장소 정보
- 언어
- JavaScript
- 라이선스
- MIT
- 마지막 업데이트
- 2026. 8. 14. 오전 7:02
신중하게 설치하기
소스 코드, 권한, 수명 주기 스크립트, 의존성 및 네트워크 접근을 검토하고 신뢰하지 않는 플러그인은 격리 환경에서 테스트하세요.