dsh-token-vault
Secure credential vault for DeepSeek Harness: store GitHub/npm/API tokens (secrets never leave the host), run gh/npm/npx/node/git with the token injected in the environment, and manage tokens from a Settings page.
安装
dsh plugin --profile web add github:yyfather/dsh-token-vault
需要可复现安装时,可在仓库后追加 #commit 固定提交。
Secure credential vault for DeepSeek Harness: store GitHub/npm/API tokens (secrets never leave the host), run gh/npm/npx/node/git with the token injected in the environment, and manage tokens from a Settings page.
该插件未提供要点说明,请参考仓库 README。
- 安装并启动 DeepSeek Harness:
npx @deepseek-ai/dsh web - 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
- 用 dsh plugins list 确认已安装,必要时重启 Harness 生效
插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。
| 代码仓库 | github.com/yyfather/dsh-token-vault |
| 许可证 | MIT |
| 主要语言 | master |
| 下载量 | 2 |
| GitHub 星标 | 0 |
| 最近推送 | 2026-08-23 |
| 收录日期 | 2026-09-19 |
| 分类 | 安全与权限 |
事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。
以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。
# @yyfather/dsh-token-vault **Secure credential vault for DeepSeek Harness** · 凭证库插件 Store your GitHub / npm / API tokens in DSH's own credential store (`ctx.credentials` → `~/.credentials.yaml`). **Secrets never leave the host** — no plaintext file, no model context, no browser round-trip. The agent uses tokens through `vault_run` which injects them into a child-process environment only; `vault_show` (the single disclosure path) requires an explicit `confirm: true`. > 设置 → 凭证库 录入一次,之后所有 GitHub/npm 操作由 Host 侧代持。 ## Tools (agent-facing) | Tool | Purpose | | --- | --- | | `vault_list` | List stored token names only (never values) | | `vault_has` | Check one token's presence | | `vault_set` | Store/update a token (value never echoed) | | `vault_remove` | Delete a token | | `vault_import` | Import from `gh auth token` (source: gh) or `~/.npmrc` (source: npm) | | `vault_run` | Run `gh/npm/npx/node/git` with the token injected via env (github/gh → `GH_TOKEN`, npm/node → `NPM_TOKEN`, `env_name` overrides); output contains no secrets | | `vault_show` | Reveal one token (**requires `confirm: true`**, only on explicit user request) | ## Install ```sh dsh plugin --profile desktop add @yyfather/dsh-token-vault ``` The package declares `dsh.bundle.patch` so it mounts automatically; restart DSH Desktop to activate. Then manage it from **设置 → 市场 → 已安装** (enable / update / uninstall), or paste tokens in **设置 → 凭证库**. ## Security design - Storage: DSH credential record space (`dsh-token-vault/`, atomic `modifyRecord`) — no new plaintext files. - Usage: `vault_run` places the token in the child environment only; stdout/stderr/logs never contain it. - Disclosure: `vault_show` is the only leak path and demands `confirm: true`; usage rules advise rotating after use. - Prompt section `token-vault-usage` injected automatically: the agent must never print or persist tokens. ## Structure - `lib/index.js` — host: `ctx.tools.register` for 7 vault tools; `webServer` routes `/vault/status|set|remove|import`; `systemPrompt.section` usage rules - `lib/client.js` — browser `__ModuleLoader__` bundle: Settings → 凭证库 (add / import / delete, values never displayed) - `cordis.patch.yml` — bundle mount patch - `package.json` — market-format compliant (strict `inject`, full `exports` incl. `./client` and `./cordis.patch.yml`) ## License MIT © YYfather
数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。