zhujiaqi/dsh-secret-paste ↗★ 2

dsh-secret-paste

自动识别输入中的密钥,存入凭证服务并以占位符发送给模型。 适合需避免密钥明文进入对话的用户,支持撤销与中等置信度确认。

包名
dsh-secret-paste
兼容性
待验证
Harness 依赖范围
^0.1.0-rc.7
Cordis 依赖范围
^4.0.1
版本
0.2.0
许可证
MIT
最近更新
2026年8月20日

安装

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:zhujiaqi/dsh-secret-paste

Usage

Auto-detect and hide

Paste text that contains a high-confidence secret (ghp_..., sk-proj-..., JWT, …). It is stored and replaced with [secret:PASTE_N] immediately, and a chip shows:

🔒 Hidden · · PASTE_N · Undo

  • Hover the chip to reveal the value in a tooltip — no layout shift.
  • Undo restores the plaintext while you are still drafting.
  • After you send, the chip stays visible but the undo button disappears; once the answer arrives, the chip is removed.

Medium confidence

confidence === 'medium' hits (e.g. a Bearer ) stay in the draft as-is and a "Suspected secret" chip asks you to confirm (Hide) or ignore (Ignore).

Manual marking

Formats the detector does not recognize (ark-..., some sk-...) are never guessed. Select the text and use the "Mark selection as secret" action, then "Hide & store".

Nested placeholders

A selection that already contains [secret:REF] can be wrapped again. The secret_resolve tool resolves such chains recursively down to plaintext (cycles or missing inner refs return found: false).