dsh-destinywind-tpm
Hardware-sealed and DPAPI/TPM-backed credential provider for DeepSeek Harness replacing plain-text storage.
Install
$ dsh plugin --profile web add link:<本仓库绝对路径>Plugin Overview & Capabilities
AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.
Key Capabilities
- Hardware and user-level credential encryption using Windows TPM CNG or DPAPI fallback
- Linux TPM 2.0 (tpm2-tools) and session keyring (libsecret) credential sealing
- AES-256-GCM envelope encryption with atomic staging flush to $DSH_HOME/.credentials.dpapi.json
- Automatic replacement of the default plain-text credentials provider via Cordis bundle patch
- Strict zero-plain-text enforcement: refuses to mount if no valid key protector is available
Useful For
- Securing DeepSeek API keys and LLM provider credentials against plain-text disk exposure
- Binding DSH credential stores to specific hardware and local user accounts to prevent unauthorized credential portability
- Hardening credential storage on enterprise and developer workstations
Who It Fits
- Security-conscious DeepSeek Harness users
- Developers needing hardware-backed secret management
- Workstation administrators requiring DPAPI or TPM credential isolation
Documented Limitations
- Encrypted store files cannot be decrypted on other machines or user accounts
- Requires re-entering credentials after migration from the default plain-text provider (no automatic migration)
- Process environment variables take precedence over the credential store and can mask stored keys
- Offline integration tests rely on hardcoded local paths and cannot run out-of-the-box in generic CI
DSH Compatibility
Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.
Security Signals
Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.
package.json declares 0 runtime, 0 development, 6 peer, and 0 optional dependencies.
package.json declares DSH bundle metadata.
GitHub reports the repository license as MIT.
A root package.json was captured and can be inspected by the registry.
Public GitHub source metadata is available for this registry snapshot.
Source & Registry Notes
Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.
- Source repository
- rickwindman/dsh-destinywind-tpm
- Registry source
- GitHub · dsh-plugin topic
- Registry classification
- Plugin Bundle
- Source checked
- d7a7a12 · 2026-09-27
This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.
Repository Activity
- GitHub stars
- 0GitHub stars
- Forks
- 0
- Open issues
- 0
- Last commit
- 2026-09-26
- Last release
- No release detected
Related DSH Plugins
Ranked by overlapping capabilities, use cases, plugin type, categories, and DSH profile.
Long-term spatiotemporal memory, zero-LLM whitebox reasoning, and knowledge flywheel integration for DeepSeek Harness via AEIS.
View plugin →Composable three-tier memory control plane for DeepSeek Harness with runtime context, searchable documents, and pluggable long-term memory.
View plugin →Multi-engine search provider for DeepSeek Harness with keyless fallback, time filtering, and UI configuration.
View plugin →Comprehensive long-term memory, self-evolution, skills, task management, and multi-agent dispatch bundle for DeepSeek Harness.
View plugin →