DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Password Shield — DeepSeek Harness 插件(DSH Plugin)
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录
← Plugins

dsh-password-shield

Password Shield

阻止悬浮在 DeepSeek Harness 聊天编辑器上的 iCloud Passwords 补全列表弹窗。

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add dsh-password-shield@0.4.0
README兼容性版本

兼容性与来源证明

Password Shield 以 dsh-password-shield 发布,当前版本为 0.4.0。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
web
发布来源
npm
Registry 更新时间
2026/9/20

版本

0.4.0stable
2026/9/10
0.3.0stable
2026/8/20
0.1.0stable
2026/8/17

相关插件

正在加载相关插件…

最新版
0.4.0
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
16 kB
文件数
12
Surface
web
许可证
MIT
发布源
npm
GitHub
★ 0
周下载
49
最近提交
2026/9/10
查看源码 ↗项目主页 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题

相关插件

继续浏览 ui-customization 分类下经过校验的插件。

Web App@deepseek-ai/dsh-web-appdsh 浏览器界面捆绑包:位于 dsh-base 之上的 Web 补丁层,加上运行时粘合插件(提供前端 dist、Web 界面提示符、bash 运行时变量和 URL 行)Experimental Agent Team Web Profile@deepseek-ai/dsh-experimental-agent-team-web-profile用于 Agent Teams Remote 和 UI 插件的实验性 Web 配置层Remote Web Ui@linxin666/dsh-remote-web-ui通过扫码配对访问 dsh Web GUI,共享一个官方界面:设置按钮旁的二维码可将手机和 PC 配对到同一个 Web GUI(手机采用竖屏触控适配层,PC 使用完整桌面界面),通过一次性令牌和 rClient Ui Git Graph@linxin666/dsh-client-ui-git-graph外部 dsh Web GUI 插件:空会话 Git 分支选择器和 Git 图,包含实际的主机端 Git 操作与防护,作为 dsh 配置文件包

README

dsh-password-shield

A narrowly scoped DSH web plugin that blocks the iCloud Passwords completion-list popup floating over the chat composer in old conversations.

The problem

The iCloud Passwords Chrome extension applies WebKit-style credential-field heuristics to every page. On some DSH conversation pages it misclassifies the chat composer and injects its empty completion list:

  • iCloud Passwords
  • Open Passwords App
  • Find and create passwords

No saved credential is required. The empty-state popup itself confirms that the extension offered autofill even though it found no credential for the DSH URL.

The popup is implemented as a <div popover> appended to <body>. Its open shadow root contains an iframe whose extension URL points to completion_list.html.

The fix

The plugin watches the DOM for exactly that structure. When it appears, it removes the completion-list iframe and forces its host invisible while keeping the host connected, allowing the extension to finish its own show/hide bookkeeping safely.

It intentionally does not:

  • change input[type=password] into another type;
  • modify API-key fields;
  • change autocomplete attributes;
  • read or store field values;
  • hide ordinary DSH popovers;
  • hide unrelated extension iframes.

Install

dsh plugin --profile web add dsh-password-shield@0.4.0 --save-exact --ignore-scripts
# Restart dsh web.

For a reviewed checkout during development only:

dsh plugin --profile web add github:ruby1304/dsh-password-shield#<full-commit-sha> --save-exact --ignore-scripts

Never use a mutable branch or link: checkout as production state.

Version 0.4.0 targets DSH 0.1.5-rc.1 exactly. Its browser bundle has no DSH-internal module request, relies only on the 0.1.5-rc.1 baseline loader, and does not request eager activation.

Privacy and security

  • The Host half is a no-op. It has no credential, filesystem, process or network access.
  • The browser half never reads input values and never changes password or API-key fields.
  • Matching is limited to the public iCloud Passwords extension ID and a completion_list.html iframe inside an open shadow root.
  • The plugin sends no telemetry and stores no state.

Uninstall with dsh plugin --profile web remove dsh-password-shield, restart DSH Web, and reload open pages. A completion-list iframe already removed from the current document is restored only by that page reload.

Tests

npm install
npm run check
npm run release:check

Tests cover pre-existing and dynamically inserted iCloud completion lists, ordinary DSH popovers, unrelated extension iframes, and the guarantee that password/text inputs remain untouched.

License

MIT