nengong-ai/dsh-keychain-credentials ↗★ 0

dsh-keychain-credentials

macOS钥匙串凭据管理插件 适合macOS用户,将API密钥等凭据安全存入系统钥匙串,避免明文泄露。

包名
dsh-keychain-credentials
兼容性
待验证
Harness 依赖范围
>=0.1.2-rc.1 <0.2.0
Cordis 依赖范围
^4.0.2
版本
0.1.0
许可证
MIT
最近更新
2026年9月21日

安装

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:nengong-ai/dsh-keychain-credentials

Usage

Store a secret (account = credential reference name):

security add-generic-password -U -s dsh-credentials -a DEEPSEEK_API_KEY -w 'sk-…'

The LLM adapter resolves the reference per request — no restart needed after rotation.

Semantics kept from the seam contract:

  • Process environment shadows the keychain (per-run operator intent wins).
  • An empty stored value counts as absent.
  • set/unset reject while a read-only source (the environment) shadows the ref.
  • describe checks existence without reading the value — a status query never pulls plaintext into the agent process.
  • Errors from the security CLI are sanitized: exit code and stderr only, never the command line (which would carry the secret on a failed set).
  • Secrets are fed to security over stdin, never argv, so they never appear in ps.