revive/dsh-git-credentials
DeepSeek Harness plugin: GitLab and GitHub API tokens stay out of the model context — encrypted at rest (AES-2
dsh-git-credentials is an out-of-tree DSH plugin that manages GitLab, GitHub, Gitee, Gitea, and Bitbucket API tokens so token values never enter the model context: the model's tools carry only a token reference name (e.g. GITLAB_TOKEN), and the value is decrypted from the plugin's own AES-256-GCM encrypted store at call time, appearing only in the outgoing HTTP Authorization header. Changing a site or rotating a token takes effect on the very next call — no restart required. A separate 32-byte random key file (0600, atomic writes) protects the store; losing the key file makes the data unrecoverable (decryption fails loud).
Install
dsh plugin --profile add ./dsh-git-credentials-0.2.2.tgzREADME EN primary (2026-09-01, repo revive/dsh-git-credentials): Option A (recommended) — download the release tarball dsh-git-credentials-0.2.2.tgz from the releases page (ships the built browser bundle, no build step) and install dsh plugin --profile add ./dsh-git-credentials-0.2.2.tgz; verify with dsh --profile --dump-config (look for the '# == dsh-git-credentials' layer), then restart the GUI. Option B — dsh plugin --profile add dsh-git-credentials per README after the package is linked. MIT.
Compatibility
DSH profile; GitLab/GitHub/Gitee/Gitea/Bitbucket API tokens; AES-256-GCM encrypted store.
Details
- Repo: revive/dsh-git-credentials
- Category: Coding & Development
- Stars: 2
- Version: release tarball dsh-git-credentials-0.2.2.tgz
- Last push: 2026-09-09
- First seen: 2026-08-14
Recent updates
Tokens never enter model context; AES-256-GCM store + separate key file; instant rotation; GitLab/GitHub/Gitee/Gitea/Bitbucket.
FAQ
- Can the model see my tokens?
- No — tools carry only a reference name; the value is decrypted at call time and appears only in the outgoing Authorization header.
- How are tokens stored?
- AES-256-GCM encrypted data file with a separate 32-byte random key file (0600, atomic writes).
- How do I install it?
- Download dsh-git-credentials-0.2.2.tgz from the releases page and dsh plugin --profile add ./dsh-git-credentials-0.2.2.tgz.
Alternatives
Zenquiem/dsh-security-suite · cdxiaodong/dsh-guardian · Jesse-njx/dsh-crosstalk