DeepSeek Harness (DSH) adopts a plugin architecture, allowing developers to extend agent capabilities by registering tools. When developing DSH plugins involving account registration, key management, or security configuration, generating high-entropy passwords directly in the workflow is a common requirement. The dsh-password plugin registers the password_generate tool and provides cryptographically secure random password generation for the DSH plugin environment.

This is a DSH plugin maintained by ZhijiangTang. It only depends on ESM modules, requires no build steps, and has zero external dependencies. Its core functionality is registering the password_generate tool, supporting two generation modes: strong random strings and Diceware phrases. All randomness is sourced from Node.js crypto.randomInt, ensuring cryptographic security.

Features

The plugin provides the following core capabilities:

  • Tool registration: Registers the password_generate tool in the DSH environment.
  • Strong password generation: Generates random strings containing uppercase and lowercase letters, digits, and symbols, and supports excluding easily confused characters (such as Il1O0).
  • Diceware generation: Generates readable English phrases based on a built-in word list.
  • Cryptographic security: Uses node:crypto.randomInt as the random source and does not rely on insecure Math.random.
  • Stateless and safe: Runs purely in memory, does not write to disk, does not write logs, and holds no persistent state.

Installation and Enablement

Before installation, make sure the DSH environment and the required peer dependencies (@deepseek-ai/cordis, @deepseek-ai/dsh-tools, @deepseek-ai/dsh-llm) are configured.

Install the plugin with the following commands:

# 本地安装
dsh plugin --profile <name> add file:./plugins/dsh-password

# 或发布后安装
dsh plugin --profile <name> add dsh-password

After installation, the plugin registers the password_generate tool in the DSH process.

Typical Usage

Tool Invocation

Call the password_generate tool and control the generation policy through parameters. The following example generates two 24-character strong passwords:

call password_generate with type random, length 24, count 2, avoidAmbiguous true

Parameters

Parameter Type Default Description
type string random Generation type; select random or diceware.
length number 20 Password length (8–128); applies only when type=random.
count number 1 Number of passwords to generate (1–10).
words number 5 Number of Diceware words (4–8); applies only when type=diceware.
separator string - Diceware word separator.
includeSymbols boolean true Whether to include symbols (applies only when type=random).
avoidAmbiguous boolean true Exclude ambiguous characters (Il1O0); applies only when type=random.

Return Value

The tool returns a standard JSON object containing the generation status, password list, type, character set, count, and entropy estimate.

{
  "ok": true,
  "passwords": [
    "aB3$xY9#mN2@pL5",
    "cD4!zW8*oQ1%pE6"
  ],
  "type": "random",
  "entropyBits": 153.8,
  "charset": "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789!@#$%^&*()_+-=[]{}|;:,.<>?",
  "count": 2,
  "error": ""
}

Generation Rules and Security Notes

  • Random mode: Uniformly samples from the character set (uppercase and lowercase letters + digits + symbols) based on node:crypto.randomInt. If avoidAmbiguous is enabled, Il1O0 are removed. After generation, each password is validated to ensure it contains at least one lowercase letter, one uppercase letter, and one digit (as well as symbols, depending on includeSymbols); if the requirement is not met, it is regenerated (up to 20 attempts; if exceeded, it falls back to a deterministic fallback that completes the required character classes).
  • Diceware mode: Uses a built-in list of 256 common short English words, randomly selects words of them, and joins them with separator. The entropy estimate formula is words × log2(256) bits.
  • Security mechanisms: The plugin holds no persistent state; all generated credentials exist only in memory and are not written to logs or the file system.

Applicable Scenarios and Notes

  • Applicable scenarios: Suitable for DSH plugin development scenarios that require automated generation of strong passwords, API keys, or Diceware phrases.
  • Note: The plugin runs with the permissions of the DSH process, and generation results appear in tool returns and UI summaries. Please store them properly after use and do not share them with others.
  • Source code review: Before installing unofficial plugins, it is recommended to review the source code and license (MIT).

Conclusion

dsh-password provides a lightweight, secure, and easy-to-use password generation solution for the DSH ecosystem. By integrating this plugin, developers can conveniently handle secure credential generation logic in agent workflows.