Introduction¶
Writing sensitive credentials such as API keys and passwords directly into prompts in DeepSeek Harness (DSH) creates a risk of leakage. dsh-accounts is a DSH plugin designed to solve credential management issues. It bridges credential storage with the AI execution environment, enabling the AI to use credentials for tasks without exposing the actual values to the model context.
Core Features¶
dsh-accounts provides the following core capabilities:
* Automatic browser login-form filling: Through the account_fill tool, account values are injected directly into the input fields of the built-in browser.
* Local CLI execution with environment-variable injection: Through the credential_run tool, API keys/tokens are injected into child processes as environment variables.
* Account listing query: Within a DSH conversation, the AI can call account_list to retrieve account metadata.
* Web management interface: A web management page is provided at the /dsh-accounts/ path for creating, reading, updating, and deleting accounts.
Installation and Enabling¶
Before installation, ensure that your DSH version is >= 0.1.1-rc.1.
Install it using the official plugin command:
dsh plugin --profile web add github:yangwuan55/dsh-accounts
After installation, restart the DSH web service for changes to take effect.
Typical Usage¶
The plugin provides three tools for the model to call:
-
account_fill
Used for automatic browser form filling. It requires the{ account, mapping: [{ selector, field }], submit? }parameter. Thefieldvalue can beusername,password,totp, or a custom key. This tool returns a redacted fill result and a flag indicating whether manual action is required. -
credential_run
Used for running a local CLI. It requires the{ account, command, args?, envKeys?, timeoutMs? }parameter. The tool injects the keys declared in the account’senvmapping into the child process as environment variables. The return value includes the exit code and redacted stdout/stderr. Ifenvis not declared orenvKeysis not specified, an error is returned. -
account_list
Used to query the account list. It takes no parameters and returns a list of metadata including account ID, Kind, Label, HasTotp, and Domains.
Security and Protocol¶
The plugin strictly follows the principle of security isolation:
* In-memory handling: Credential values flow only within the plugin process memory, and the model and the conversation never see the actual values.
* Protocol validation: The kind field in the payload is required and must be one of account, env, or secret.
* Domain allowlist: The domains field is used to restrict the auto-fill scope of account_fill, and it must be explicitly declared in the account record.
* Output redaction: The standard output and error output of credential_run are replaced with [REDACTED] before being returned.
Management Interface¶
The plugin provides a web management interface at http://127.0.0.1:3080/dsh-accounts/.
This page is used to manage accounts, supporting metadata viewing, account creation/editing, and account deletion. Password and Token inputs are masked by default, with one-click plain-text viewing available. The page enforces browser trust checks (Host Fence and same-Origin validation) to ensure that operations can only be initiated locally.
Conclusion¶
dsh-accounts addresses credential leakage risks in DSH by using a plugin-based approach, keeping actual values isolated from the model context. It can be quickly installed and enabled using the command.
GitHub: https://github.com/yangwuan55/dsh-accounts
Catalog: https://www.skillhub.cn/plugins/yangwuan55/dsh-accounts