dsh-vault
Encrypted credential vault for DeepSeek Harness with model tools and a Settings UI.
Install
$ dsh plugin --profile web add dsh-vaultPlugin Overview & Capabilities
AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.
Key Capabilities
- Encrypts vault entries at rest using Node crypto, scrypt-derived keys, and AES-256-GCM.
- Stores logins, SSH credentials, API keys, OAuth tokens, TOTP secrets, cards, attachments, cookie sessions, and custom fields.
- Provides model tools for CRUD, secret-free search, password generation, TOTP, backups, recovery codes, health checks, rotation reporting, and integrity checks.
- Supports imports and exports for several password-manager and browser formats, including Bitwarden, KeePass, 1Password, Chrome, Firefox, and macOS Keychain.
- Offers configurable read-only, ask-before-write, and automatic read-write access modes plus a Settings UI.
- Supports multiple named vaults, encrypted backups, soft deletion, restoration, and password history.
Useful For
- Keep personal development credentials such as SSH keys, API keys, and OAuth tokens available to DeepSeek Harness tools.
- Store and retrieve website login credentials and generate TOTP codes when explicitly requested.
- Import an existing password-manager export into a local Harness-managed vault.
- Audit stored credentials for weak, reused, expired, or missing-2FA entries.
- Capture and manage browser cookie sessions for supported automation workflows.
Who It Fits
- DeepSeek Harness users managing personal credentials locally.
- Developers who need model-accessible SSH, API, and OAuth credentials.
- Users migrating password data from supported password managers or browsers.
Documented Limitations
- Vault security depends on the strength of the master password.
- Forgetting the master password permanently loses access to vault data.
- Plaintext secrets are present in process memory after unlock and are returned to model context by explicit vault_get calls.
- The project states that it targets single-machine, personal deployments; team-shared vaults are out of scope.
- GitHub installation requires allowing the package build script and building sources during installation.
DSH Compatibility
Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.
Security Signals
Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.
package.json declares 0 runtime, 15 development, 9 peer, and 0 optional dependencies.
package.json declares DSH bundle metadata.
GitHub reports the repository license as MIT.
A root package.json was captured and can be inspected by the registry.
package.json declares a prepare lifecycle script that may run during relevant package installation workflows.
Public GitHub source metadata is available for this registry snapshot.
Source & Registry Notes
Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.
- Source repository
- Ox0400/dsh-vault
- Registry source
- GitHub · dsh-plugin topic
- Registry classification
- Plugin
- Source checked
- c2e578e · 2026-09-25
This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.
Repository Activity
- GitHub stars
- 11GitHub stars
- Forks
- 0
- Open issues
- 0
- Last commit
- 2026-09-24
- Last release
- 2026-09-18
Related DSH Plugins
Ranked by overlapping capabilities, use cases, plugin type, categories, and DSH profile.
Traceable, searchable, cross-session knowledge graph memory engine for DeepSeek Harness.
View plugin →Vision routing and pixel-level visual tool suite for DeepSeek Harness agents with built-in free fallbacks.
View plugin →Compatibility bridge and host ABI enabling unmodified Pi plugins to run natively on DeepSeek Harness.
View plugin →Second-model AI auto-review for DeepSeek Harness approval requests with fail-closed safety and session audit.
View plugin →