DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Credential Manager — DeepSeek Harness 插件(DSH Plugin)
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录
← Plugins
C

dsh-credential-manager

Credential Manager

DeepSeek Harness 的命名用户凭据:面向模型的凭据工具、通过 ctx.credentials 接口访问的机密信息、DSH_CM_* Shell 变量,以及“设置 → 凭据”页面

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add github:accpowered/dsh-credential-manager#82fe9c1f4f9d3b0600eadfb48de26da382c85d55
README兼容性版本

兼容性与来源证明

Credential Manager 以 dsh-credential-manager 发布,当前版本为 0.1.1。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
web
发布来源
github
Registry 更新时间
2026/9/19

版本

0.1.1stable
2026/9/19
0.1.0stable
2026/8/20

相关插件

正在加载相关插件…

最新版
0.1.1
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
未提供
文件数
未提供
Surface
web
许可证
MIT
发布源
github
GitHub
★ 1
周下载
0
最近提交
2026/9/19
查看源码 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题

相关插件

继续浏览 security-access 分类下经过校验的插件。

Doctor@linxin666/dsh-doctorDSH 配置档案的事务性救援模式,配备受监督的启动器、隔离的恢复容器、确定性修复、健康监控以及本地 Web 恢复控制台Mobiledsh-mobileDeepSeek Harness 移动端适配与安全访问插件,支持局域网、远程连接、Android App 和手机浏览器。DSCODE@toddzheng024/dscode-bundle完整的 DeepSeek 编码代理,支持持久化 shell、Ultra 协作和自动权限审查。Auto Reviewdsh-auto-review针对 DeepSeek Harness 审批请求的第二模型 AI 自动审查:只读审查子代理在审批应答链上决定允许或拒绝,并采用故障关闭回退机制和完整的会话日志审计。

README

dsh-credential-manager

English | 简体中文

Named user credentials for DeepSeek Harness: let the model use your API keys, tokens, and logins by reference — secret values never enter the conversation.

One credential is one flat record holding exactly one secret value. The model creates empty placeholder records with its credential_create tool; you enter the secret value in Settings → Credentials. Every configured secret is injected into each model shell execution as a DSH_CM_<ID> environment variable, resolved per execution, so the value reaches commands without ever being printed into the transcript.

What you get

PieceKindPurpose
credential-managerhost service pluginMetadata sidecar (storage domain), secret values behind the ctx.credentials seam, DSH_CM_* shell-env injection
tool-credential-managerhost tools pluginModel-facing tools credential_list / credential_create / credential_read / credential_update_note + a system-prompt policy section
Settings → Credentialsweb client plugin (dsh.client)The page where you enter/manage secret values; talks to the host over a self-mounted Typert Remote namespace

Install

From GitHub (builds on install via its prepare script; pnpm will ask you to allow the build once):

dsh plugin --profile web add github:accpowered/dsh-credential-manager

If pnpm prints an allowBuilds prompt, add the printed key under allowBuilds in the profile's pnpm-workspace.yaml and re-run the add — this is install-time code execution permission, so only allow sources you trust (pinning a commit, github:accpowered/dsh-credential-manager#<sha>, is recommended).

From a local checkout:

dsh plugin --profile web add ./dsh-credential-manager

Restart dsh web (or your profile) and hard-refresh the browser.

How it works with the harness

The bundle patch (cordis.patch.yml) inserts two host rows; the dsh.client declaration makes the web plane serve the settings page automatically:

- insert:
    - id: credential-manager
      name: dsh-credential-manager
    - id: tool-credential-manager
      name: dsh-credential-manager/tools

No harness source is modified:

  • The tools register into the host tool registry, so every agent preset sees them.
  • The settings page mounts its own Typert Remote contribution through the public ctx.remote.$mount seam — no api/remotes edit needed.
  • The host service is a TypertRemoteService; the gateway discovers its @Remote methods dynamically (SRC markers), so no code generation step is required to deploy.

Stock-upstream note: the upstream api/remotes forwarded-event allowlist does not include credential-manager/updated, so the settings page does not receive live push invalidations from other surfaces; it still converges through authoritative mutation replies and connection-reset refetches. If you run a harness that forwards the event, the page lights up live automatically.

Configuration

Both host rows work with zero configuration; every knob carries a schema default. To tune, restate the row in your profile's cordis.patch.yml (a patch replaces the row's whole config):

- id: credential-manager
  name: dsh-credential-manager
  config:
    maxNoteBytes: 8192        # UTF-8 byte cap for one user/LLM note field

- id: tool-credential-manager
  name: dsh-credential-manager/tools
  config:
    promptOrder: 116          # ordering weight of the system-prompt policy section

To mount only the service and the settings page (no model-facing tools), delete the tool-credential-manager row from the bundle patch.

Usage

  1. In a conversation, when the model needs a credential it calls credential_create with a name only (never a value) and asks you to fill it in.
  2. Open Settings → Credentials, find the placeholder, and enter the secret value (write-only; it is never read back into any page or transcript).
  3. The model uses the value through the listed DSH_CM_<ID> variable in bash/pwsh commands: curl -H "Authorization: Bearer $DSH_CM_MYAPI" ....
  4. credential_read exists as a deliberate last-resort escape hatch for non-shell use; the harness instructs the model to prefer the variable path.

Expired credentials keep working (the expiry day is informational) but are flagged in the page and in credential_list so the model can tell you to rotate them.

Uninstall

dsh plugin --profile web remove dsh-credential-manager

The service, tools, system-prompt section, settings page, and Remote namespace all detach with the plugin fiber. Persisted metadata rows (storages/credential_manager.json in the harness home) and stored secret values are left untouched.

Development

pnpm install
pnpm build       # tsc declarations + tsdown (node lib + browser client bundle)
pnpm test        # vitest: service CRUD / seam confinement / tool mapping

Layout: src/index.ts (host service, default export), src/tools.ts (tools plugin), src/types.ts + src/spec.ts (wire types + storage domain), src/client/ (settings page; remote.ts is the hand-maintained Typert Remote contribution — keep it in sync with the service's @Remote methods).

License

MIT