nengong-ai/dsh-keychain-credentials ↗★ 0
dsh-keychain-credentials
macOS钥匙串凭据管理插件 适合macOS用户,将API密钥等凭据安全存入系统钥匙串,避免明文泄露。
安装
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:nengong-ai/dsh-keychain-credentials说明文档
阅读完整 README ↗Usage
Store a secret (account = credential reference name):
security add-generic-password -U -s dsh-credentials -a DEEPSEEK_API_KEY -w 'sk-…'
The LLM adapter resolves the reference per request — no restart needed after rotation.
Semantics kept from the seam contract:
- Process environment shadows the keychain (per-run operator intent wins).
- An empty stored value counts as absent.
set/unsetreject while a read-only source (the environment) shadows the ref.describechecks existence without reading the value — a status query never pulls plaintext into the agent process.- Errors from the
securityCLI are sanitized: exit code and stderr only, never the command line (which would carry the secret on a failedset). - Secrets are fed to
securityover stdin, never argv, so they never appear inps.