DSH Plugins Marketplace

DSH Plugins

Plugins

/

dsh-credentials-system

k

dsh-credentials-system

Discovered

System-bound encrypted credential provider for DeepSeek Harness

dsh-credentials-system

DeepSeek Harness credential provider backed by the operating system's user-bound secret protection. Version 0.1 supports Windows x64/ARM64 through DPAPI CurrentUser.

Security properties

  • $DSH_HOME/.credentials.system.json contains only versioned DPAPI ciphertext and reference names.
  • A blob is bound to the current Windows user, this store id, and its exact credential reference.
  • There is no plaintext-file, environment-variable, machine-wide, or local-key fallback.
  • describe() returns only configured, source, and writable; there is no reveal API.
  • Wrong user, damaged ciphertext, unavailable native backend, and malformed storage fail loudly.
  • Explicit portable exports use scrypt plus AES-256-GCM; the passphrase and plaintext are never written beside the export.

This protects a copied credential file and prevents routine configuration views from disclosing values. It cannot protect secrets from malicious code already executing as the Harness process, memory inspection, a compromised Windows account, or a proxy that necessarily receives its own authentication credential.

DeepSeek Harness composition

Replace the built-in plaintext provider; never run it as an automatic fallback:

- id: credentials
  name: '@deepseek-ai/dsh-credentials-local'
  disabled: true

- insert:
    - id: credentials-system
      name: dsh-credentials-system

Consumers store only references, for example:

proxies:
  office:
    url: http://proxy.example:8080
    username: alice
    passwordRef: DSH_PROXY_OFFICE_PASSWORD

The Harness plugin configuration UI should submit a new value through the write-only credentials API. It must render an empty password field plus “configured/not configured”, never a decrypted value or ciphertext.

Migrating the legacy plaintext file

provider.migrateLegacy({ refs?, archive? }) performs an explicit Host-side migration from $DSH_HOME/.credentials.yaml:

  1. strictly parse the bounded YAML mapping;
  2. list/select refs without returning values to a browser;
  3. DPAPI-encrypt each selected value;
  4. resolve and compare it in memory to verify the write;
  5. optionally rename the source to .credentials.yaml.migrated only when every entry migrated.

The renamed file is still plaintext. Delete it after verifying the new provider; it is retained rather than automatically destroyed so an interrupted migration cannot cause credential loss. Partial migration never renames or deletes the source.

Portable export

Portable export is an explicit backup/migration operation, not the runtime backend. The complete payload—including reference names—is encrypted using scrypt (N=131072, r=8, p=1) and AES-256-GCM. A wrong passphrase and a damaged file intentionally return the same error.

Important DSH distinction

@deepseek-ai/dsh-credentials-local stores plaintext in $DSH_HOME/.credentials.yaml. Owner-only file permissions and role("secret") redaction are useful boundaries, but they are not encryption. This provider must not silently fall back to it.

Comments

Loading…

Similar plugins

dsh-credentials-vault

by tancheng33

HashiCorp Vault backend for the DeepSeek Harness credential seam: central secrets, AppRole machine auth, rotation without restart, and no long-lived provider key on the agent host

Security & AuditDevelopment & InfrastructureManifest valid

★ 0

MIT

TypeScript

Aug 16, 2026

dsh plugin --profile web add dsh-credentials-vault

by Ox0400

Encrypted credential vault for DeepSeek Harness — AES-256-GCM + TOTP, model tools + Settings UI

Security & AuditManifest valid

★ 11

↓ 1.2k/wk

MIT

TypeScript

Sep 30, 2026

dsh plugin --profile web add dsh-vault

by leonardoxr

Secure bounded coding tools for DeepSeek Harness

Manifest valid

★ 0

MIT

TypeScript

Aug 24, 2026

dsh plugin --profile web add dsh-coding-tools

by yoke233

OpenAI Codex OAuth login and usage card plugin for DeepSeek Harness

Security & AuditTools & CapabilitiesModels & ProvidersManifest valid

★ 12

MIT

JavaScript

Sep 28, 2026

dsh plugin --profile web add dsh-openai-codex-auth

by taichuy

DeepSeek Harness auth插件

Security & AuditManifest valid

★ 25

↓ 229/wk

Apache-2.0

TypeScript

Oct 2, 2026

dsh plugin --profile web add deepseek-harness-auth

by YYfather

Secure credential vault for DeepSeek Harness: tokens never leave the host — the agent runs gh/npm/npx/node/git with the token injected in the environment. Manage from 设置 → 凭证库 / 市场 → 已安装.

Manifest valid

★ 0

MIT

JavaScript

Aug 23, 2026

dsh plugin --profile web add @yyfather/dsh-token-vault