← DeepSeek Harness Plugins
DeepSeek Harness PluginManifest Valid

dsh-destinywind-tpm

Hardware-sealed and DPAPI/TPM-backed credential provider for DeepSeek Harness replacing plain-text storage.

Terminal & TUI
0GitHub Stars0ForksUpdated2026-09-26

Install

$ dsh plugin --profile web add link:<本仓库绝对路径>

Plugin Overview & Capabilities

AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.

source-grounded
dsh-destinywind-tpm is a DeepSeek Harness plugin bundle that provides a cross-platform hardware/user-level credential storage service. Replacing the default plain-text credential provider, it protects reference values and secrets using AES-256-GCM envelope encryption sealed via Windows TPM (CNG) / DPAPI or Linux TPM 2.0 / libsecret keyring before flushing to disk.

Key Capabilities

  • Hardware and user-level credential encryption using Windows TPM CNG or DPAPI fallback
  • Linux TPM 2.0 (tpm2-tools) and session keyring (libsecret) credential sealing
  • AES-256-GCM envelope encryption with atomic staging flush to $DSH_HOME/.credentials.dpapi.json
  • Automatic replacement of the default plain-text credentials provider via Cordis bundle patch
  • Strict zero-plain-text enforcement: refuses to mount if no valid key protector is available

Useful For

  • Securing DeepSeek API keys and LLM provider credentials against plain-text disk exposure
  • Binding DSH credential stores to specific hardware and local user accounts to prevent unauthorized credential portability
  • Hardening credential storage on enterprise and developer workstations

Who It Fits

  • Security-conscious DeepSeek Harness users
  • Developers needing hardware-backed secret management
  • Workstation administrators requiring DPAPI or TPM credential isolation

Documented Limitations

  • Encrypted store files cannot be decrypted on other machines or user accounts
  • Requires re-entering credentials after migration from the default plain-text provider (no automatic migration)
  • Process environment variables take precedence over the credential store and can mask stored keys
  • Offline integration tests rely on hardcoded local paths and cannot run out-of-the-box in generic CI

DSH Compatibility

Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.

Not tested yetNo runtime compatibility tests have been published yet.

Security Signals

Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.

Dependency Counts

package.json declares 0 runtime, 0 development, 6 peer, and 0 optional dependencies.

info
Dsh Bundle Declared

package.json declares DSH bundle metadata.

info
License Declared

GitHub reports the repository license as MIT.

info
Package Manifest Available

A root package.json was captured and can be inspected by the registry.

info
Source Available

Public GitHub source metadata is available for this registry snapshot.

info

Source & Registry Notes

Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.

Source repository
rickwindman/dsh-destinywind-tpm
Registry source
GitHub · dsh-plugin topic
Registry classification
Plugin Bundle
Source checked
d7a7a12 · 2026-09-27

This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.

Repository Activity

GitHub stars
0GitHub stars
Forks
0
Open issues
0
Last commit
2026-09-26
Last release
No release detected
For maintainers

Maintaining this plugin?

This listing is generated from public repository data. If you maintain this project, you can review the information and share this listing with your users if you find it useful.

Add to README
Listed on DSHPlugin.app