nengong-ai/dsh-keychain-credentials ↗★ 0

dsh-keychain-credentials

macOS Keychain credentials provider for DeepSeek Harness (dsh) — refs and records both stored in the login keychain, never in a plaintext file 适合macOS用户,将API密钥等凭据安全存入系统钥匙串,避免明文泄露。

パッケージ
dsh-keychain-credentials
互換性
未検証
Harness ピア範囲
>=0.1.2-rc.1 <0.2.0
Cordis ピア範囲
^4.0.2
バージョン
0.1.0
ライセンス
MIT
最終更新
2026/09/21

インストール

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:nengong-ai/dsh-keychain-credentials

ドキュメント

README 全文を読む ↗

Usage

Store a secret (account = credential reference name):

security add-generic-password -U -s dsh-credentials -a DEEPSEEK_API_KEY -w 'sk-…'

The LLM adapter resolves the reference per request — no restart needed after rotation.

Semantics kept from the seam contract:

  • Process environment shadows the keychain (per-run operator intent wins).
  • An empty stored value counts as absent.
  • set/unset reject while a read-only source (the environment) shadows the ref.
  • describe checks existence without reading the value — a status query never pulls plaintext into the agent process.
  • Errors from the security CLI are sanitized: exit code and stderr only, never the command line (which would carry the secret on a failed set).
  • Secrets are fed to security over stdin, never argv, so they never appear in ps.