Skills Plugins MCP Prompt Model 导航 博客 资讯 我的中心
安全与权限 #credentials#deepseek-harness#dsh-plugin#security

dsh-token-vault

Secure credential vault for DeepSeek Harness: store GitHub/npm/API tokens (secrets never leave the host), run gh/npm/npx/node/git with the token injected in the environment, and manage tokens from a Settings page.

yyfather @yyfather ⬇ 2 ★ 0 master

安装

dsh plugin --profile web add github:yyfather/dsh-token-vault
下载安装清单

需要可复现安装时,可在仓库后追加 #commit 固定提交。

Secure credential vault for DeepSeek Harness: store GitHub/npm/API tokens (secrets never leave the host), run gh/npm/npx/node/git with the token injected in the environment, and manage tokens from a Settings page.

该插件未提供要点说明,请参考仓库 README。

credentialsdeepseek-harnessdsh-pluginsecurity
  1. 安装并启动 DeepSeek Harness:npx @deepseek-ai/dsh web
  2. 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
  3. 用 dsh plugins list 确认已安装,必要时重启 Harness 生效

插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。

代码仓库github.com/yyfather/dsh-token-vault
许可证MIT
主要语言master
下载量2
GitHub 星标0
最近推送2026-08-23
收录日期2026-09-19
分类安全与权限

事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。

以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。

# @yyfather/dsh-token-vault

**Secure credential vault for DeepSeek Harness** · 凭证库插件

Store your GitHub / npm / API tokens in DSH's own credential store (`ctx.credentials` → `~/.credentials.yaml`). **Secrets never leave the host** — no plaintext file, no model context, no browser round-trip. The agent uses tokens through `vault_run` which injects them into a child-process environment only; `vault_show` (the single disclosure path) requires an explicit `confirm: true`.

> 设置 → 凭证库 录入一次,之后所有 GitHub/npm 操作由 Host 侧代持。

## Tools (agent-facing)

| Tool | Purpose |
| --- | --- |
| `vault_list` | List stored token names only (never values) |
| `vault_has` | Check one token's presence |
| `vault_set` | Store/update a token (value never echoed) |
| `vault_remove` | Delete a token |
| `vault_import` | Import from `gh auth token` (source: gh) or `~/.npmrc` (source: npm) |
| `vault_run` | Run `gh/npm/npx/node/git` with the token injected via env (github/gh → `GH_TOKEN`, npm/node → `NPM_TOKEN`, `env_name` overrides); output contains no secrets |
| `vault_show` | Reveal one token (**requires `confirm: true`**, only on explicit user request) |

## Install

```sh
dsh plugin --profile desktop add @yyfather/dsh-token-vault
```

The package declares `dsh.bundle.patch` so it mounts automatically; restart DSH Desktop to activate. Then manage it from **设置 → 市场 → 已安装** (enable / update / uninstall), or paste tokens in **设置 → 凭证库**.

## Security design

- Storage: DSH credential record space (`dsh-token-vault/`, atomic `modifyRecord`) — no new plaintext files.
- Usage: `vault_run` places the token in the child environment only; stdout/stderr/logs never contain it.
- Disclosure: `vault_show` is the only leak path and demands `confirm: true`; usage rules advise rotating after use.
- Prompt section `token-vault-usage` injected automatically: the agent must never print or persist tokens.

## Structure

- `lib/index.js` — host: `ctx.tools.register` for 7 vault tools; `webServer` routes `/vault/status|set|remove|import`; `systemPrompt.section` usage rules
- `lib/client.js` — browser `__ModuleLoader__` bundle: Settings → 凭证库 (add / import / delete, values never displayed)
- `cordis.patch.yml` — bundle mount patch
- `package.json` — market-format compliant (strict `inject`, full `exports` incl. `./client` and `./cordis.patch.yml`)

## License

MIT © YYfather

数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

提交后我们会发送一封确认邮件,点击邮件里的链接才会开始收信。

完全免费,取消任意时间。我们不会发送垃圾邮件。