DeepSeek Harness (DSH) adopts a plugin architecture, allowing developers to extend agent capabilities by registering tools. When developing DSH plugins involving account registration, key management, or security configuration, generating high-entropy passwords directly in the workflow is a common requirement. The dsh-password plugin registers the password_generate tool and provides cryptographically secure random password generation for the DSH plugin environment.
This is a DSH plugin maintained by ZhijiangTang. It only depends on ESM modules, requires no build steps, and has zero external dependencies. Its core functionality is registering the password_generate tool, supporting two generation modes: strong random strings and Diceware phrases. All randomness is sourced from Node.js crypto.randomInt, ensuring cryptographic security.
Features¶
The plugin provides the following core capabilities:
- Tool registration: Registers the
password_generatetool in the DSH environment. - Strong password generation: Generates random strings containing uppercase and lowercase letters, digits, and symbols, and supports excluding easily confused characters (such as
Il1O0). - Diceware generation: Generates readable English phrases based on a built-in word list.
- Cryptographic security: Uses
node:crypto.randomIntas the random source and does not rely on insecureMath.random. - Stateless and safe: Runs purely in memory, does not write to disk, does not write logs, and holds no persistent state.
Installation and Enablement¶
Before installation, make sure the DSH environment and the required peer dependencies (@deepseek-ai/cordis, @deepseek-ai/dsh-tools, @deepseek-ai/dsh-llm) are configured.
Install the plugin with the following commands:
# 本地安装
dsh plugin --profile <name> add file:./plugins/dsh-password
# 或发布后安装
dsh plugin --profile <name> add dsh-password
After installation, the plugin registers the password_generate tool in the DSH process.
Typical Usage¶
Tool Invocation¶
Call the password_generate tool and control the generation policy through parameters. The following example generates two 24-character strong passwords:
call password_generate with type random, length 24, count 2, avoidAmbiguous true
Parameters¶
| Parameter | Type | Default | Description |
|---|---|---|---|
type |
string | random |
Generation type; select random or diceware. |
length |
number | 20 |
Password length (8–128); applies only when type=random. |
count |
number | 1 |
Number of passwords to generate (1–10). |
words |
number | 5 |
Number of Diceware words (4–8); applies only when type=diceware. |
separator |
string | - |
Diceware word separator. |
includeSymbols |
boolean | true |
Whether to include symbols (applies only when type=random). |
avoidAmbiguous |
boolean | true |
Exclude ambiguous characters (Il1O0); applies only when type=random. |
Return Value¶
The tool returns a standard JSON object containing the generation status, password list, type, character set, count, and entropy estimate.
{
"ok": true,
"passwords": [
"aB3$xY9#mN2@pL5",
"cD4!zW8*oQ1%pE6"
],
"type": "random",
"entropyBits": 153.8,
"charset": "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789!@#$%^&*()_+-=[]{}|;:,.<>?",
"count": 2,
"error": ""
}
Generation Rules and Security Notes¶
- Random mode: Uniformly samples from the character set (uppercase and lowercase letters + digits + symbols) based on
node:crypto.randomInt. IfavoidAmbiguousis enabled,Il1O0are removed. After generation, each password is validated to ensure it contains at least one lowercase letter, one uppercase letter, and one digit (as well as symbols, depending onincludeSymbols); if the requirement is not met, it is regenerated (up to 20 attempts; if exceeded, it falls back to a deterministic fallback that completes the required character classes). - Diceware mode: Uses a built-in list of 256 common short English words, randomly selects
wordsof them, and joins them withseparator. The entropy estimate formula iswords × log2(256)bits. - Security mechanisms: The plugin holds no persistent state; all generated credentials exist only in memory and are not written to logs or the file system.
Applicable Scenarios and Notes¶
- Applicable scenarios: Suitable for DSH plugin development scenarios that require automated generation of strong passwords, API keys, or Diceware phrases.
- Note: The plugin runs with the permissions of the DSH process, and generation results appear in tool returns and UI summaries. Please store them properly after use and do not share them with others.
- Source code review: Before installing unofficial plugins, it is recommended to review the source code and license (MIT).
Conclusion¶
dsh-password provides a lightweight, secure, and easy-to-use password generation solution for the DSH ecosystem. By integrating this plugin, developers can conveniently handle secure credential generation logic in agent workflows.