DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Token Vault — DeepSeek Harness 插件(DSH Plugin)
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录
← Plugins
T

@yyfather/dsh-token-vault

Token Vault

DeepSeek Harness 的安全凭据保管库:存储 GitHub/npm/API 令牌(机密信息不会离开主机),在环境中注入令牌后运行 gh/npm/npx/node/git,并从设置页面管理令牌。

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add github:YYfather/dsh-token-vault#f9fa1dfa397657d0c65ebe4be9efc0980177f039
README兼容性版本

兼容性与来源证明

Token Vault 以 @yyfather/dsh-token-vault 发布,当前版本为 1.0.3。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
web
发布来源
github
Registry 更新时间
2026/8/24

版本

1.0.3stable
2026/8/24

相关插件

正在加载相关插件…

最新版
1.0.3
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
未提供
文件数
未提供
Surface
web
许可证
MIT
发布源
github
GitHub
★ 0
周下载
0
最近提交
2026/8/23
查看源码 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题

相关插件

继续浏览 security-access 分类下经过校验的插件。

Doctor@linxin666/dsh-doctorDSH 配置档案的事务性救援模式,配备受监督的启动器、隔离的恢复容器、确定性修复、健康监控以及本地 Web 恢复控制台Pocketdsh-pocket把 DeepSeek Harness 装进你的口袋:一个包、一个设置页,手机扫码即同步访问电脑上的 DSH(局域网 + 公网,实时同屏)。DSCODE@toddzheng024/dscode-bundle完整的 DeepSeek 编码代理,支持持久化 shell、Ultra 协作和自动权限审查。Auto Reviewdsh-auto-review针对 DeepSeek Harness 审批请求的第二模型 AI 自动审查:只读审查子代理在审批应答链上决定允许或拒绝,并采用故障关闭回退机制和完整的会话日志审计。

README

@yyfather/dsh-token-vault

Secure credential vault for DeepSeek Harness · 凭证库插件

Store your GitHub / npm / API tokens in DSH's own credential store (ctx.credentials → ~/.credentials.yaml). Secrets never leave the host — no plaintext file, no model context, no browser round-trip. The agent uses tokens through vault_run which injects them into a child-process environment only; vault_show (the single disclosure path) requires an explicit confirm: true.

设置 → 凭证库 录入一次,之后所有 GitHub/npm 操作由 Host 侧代持。

Tools (agent-facing)

ToolPurpose
vault_listList stored token names only (never values)
vault_hasCheck one token's presence
vault_setStore/update a token (value never echoed)
vault_removeDelete a token
vault_importImport from gh auth token (source: gh) or ~/.npmrc (source: npm)
vault_runRun gh/npm/npx/node/git with the token injected via env (github/gh → GH_TOKEN, npm/node → NPM_TOKEN, env_name overrides); output contains no secrets
vault_showReveal one token (requires confirm: true, only on explicit user request)

Install

dsh plugin --profile desktop add @yyfather/dsh-token-vault

The package declares dsh.bundle.patch so it mounts automatically; restart DSH Desktop to activate. Then manage it from 设置 → 市场 → 已安装 (enable / update / uninstall), or paste tokens in 设置 → 凭证库.

Security design

  • Storage: DSH credential record space (dsh-token-vault/<name>, atomic modifyRecord) — no new plaintext files.
  • Usage: vault_run places the token in the child environment only; stdout/stderr/logs never contain it.
  • Disclosure: vault_show is the only leak path and demands confirm: true; usage rules advise rotating after use.
  • Prompt section token-vault-usage injected automatically: the agent must never print or persist tokens.

Structure

  • lib/index.js — host: ctx.tools.register for 7 vault tools; webServer routes /vault/status|set|remove|import; systemPrompt.section usage rules
  • lib/client.js — browser __ModuleLoader__ bundle: Settings → 凭证库 (add / import / delete, values never displayed)
  • cordis.patch.yml — bundle mount patch
  • package.json — market-format compliant (strict inject, full exports incl. ./client and ./cordis.patch.yml)

License

MIT © YYfather