Preface¶
In DSH (DeepSeek Harness) sessions, the model often needs to access passwords, usernames, or TOTP codes. Instead of requiring the user to manually enter them in every conversation, the model can first search the local credential vault. The jindom/dsh-bitwarden plugin accomplishes this by integrating Bitwarden vault access and management tools into DSH sessions.
Features¶
This plugin provides the following capabilities for DSH:
- Settings card: Provides a graphical form in DSH plugin configuration for setting connection parameters.
- Management tools:
bitwarden_find: Retrieve the list of entries (without passwords).bitwarden_get: Get the password, username, TOTP, or custom fields of a specific entry.bitwarden_status: Check configuration status, connectivity, and unlock state.
- System prompt injection: Globally injects guidance telling the model to preferentially check the credential vault whenever it needs an account, password, or API key.
- Configuration form: Renders configuration items in the DSH settings interface and supports encrypted storage of the master password and API key.
Configuration¶
Configuration supports three methods, from highest to lowest priority: user settings (GUI) > plugin combined configuration > environment variables > default values.
1. DSH Settings Interface (Recommended)¶
Go to Settings → Plugins → Plugin Configuration → Bitwarden / Vaultwarden Vault, and use the card provided by the plugin for configuration. The master password and API key are write-only fields; after saving, their plaintext will not be returned.
| Field | Description |
|---|---|
serverUrl |
Server address, default is https://bitwarden.jindom.cc. |
email |
Login email address. It must match the account, because it is the salt for the KDF. |
masterPassword |
Master password (secret). Used to derive the master key; kept in memory only. |
apiKeyClientId |
Optional. The client_id from Bitwarden web → Account Settings → Security → API key. If filled in, it can bypass two-step verification. |
apiKeyClientSecret |
Optional. The corresponding client_secret (secret). |
cacheMinutes |
In-memory cache duration after unlock, default is 30 minutes. |
2. Environment Variables¶
The following environment variable names are supported (names without the DSH_ prefix are also supported):
DSH_BITWARDEN_SERVERDSH_BITWARDEN_EMAILDSH_BITWARDEN_MASTER_PASSWORDDSH_BITWARDEN_CLIENT_IDDSH_BITWARDEN_CLIENT_SECRET
3. Combined Configuration¶
In the profile’s cordis configuration, pass fields with the same names to the plugin as the base layer for settings.
Usage¶
The model-side tool calls use JSON format. The field parameter of bitwarden_get supports all (default), password, username, totp, notes, and fields.
Search Entries¶
bitwarden_find { "query": "github jindom" }
Returns a list of entries (id/name/username/website), without passwords.
Get Credentials¶
bitwarden_get { "id": "...", "field": "password" }
Get TOTP¶
bitwarden_get { "name": "GitHub 工作账号", "field": "totp" }
Returns the current 6/8-digit dynamic code.
Check Status¶
bitwarden_status { "refresh": true }
Discards the cache, logs in again to synchronize, and reports the status.
Security Notes¶
- Data storage: The master password, user keys, and decrypted entries are kept in memory only; they are not written to disk or logged. The plugin only persists the configuration entered by the user.
- Credential flow: Plaintext credentials returned by tools enter the session context. The prompt requires the model not to echo them or write them to files. For stricter control, use
field: "password"for narrow queries. - Certificate trust: The server certificate must be trusted according to the local Node CA policy. Self-signed certificates must be replaced with trusted certificates.
Assembly Method¶
This plugin is assembled as a profile bundle. Configure the insert entries for dsh.bundle.patch and cordis.patch.yml in package.json, and list the package name in the profile’s bundles.
Note: The same plugin can only have one assembly path. If it has already been assembled via a bundle, do not also run it using the injector’s
dev_inject_plugin; otherwiseclient-moduleswill refuse to start at startup due to a composition error. Usedev_reload_packagefor hot code updates.
Dependency Notes¶
- Argon2id KDF: The plugin supports Argon2id by default. If the server uses this algorithm and the optional dependency is not installed, the plugin will report an error. You can change the server-side KDF to PBKDF2-SHA256, or install
hash-wasm(npm install hash-wasm).
Project address:
* Ecosystem catalog: https://www.skillhub.cn/plugins/Jindom/dsh-bitwarden
* GitHub: https://github.com/Jindom/dsh-bitwarden