534119219/chicheng-quickinput

DSH 便捷输入保险箱插件:输入栏「用量」与「发送」之间一键展开,自动收录会话中的密钥/网址/服务器/手机号等;点击填入或 Ctrl+点击直接发送;私密内容密码保护 + WebDAV 备份。

Project Overview项目介绍

This is a native plugin built exclusively for DeepSeek Harness that adds a quick input secure vault feature to the DSH web interface. It inserts a small gray circular button between the "usage" and "send" buttons in the input bar, which opens the vault panel when clicked. You can install it directly from GitHub via the DSH CLI using the command dsh plugin --profile web add 534119219/chicheng-quickinput, or you can install it from a local source directory for development. When modifying the plugin source code, you do not need to reinstall it, just refresh the browser page or restart the DSH web server for changes to take effect.

The plugin is designed for DSH users who frequently enter sensitive or commonly used information. On first run, you will be prompted to set a master password and a security word, which you can use to reset your password if you forget it. After setup, you can add and organize your commonly used entries like API keys, server addresses, phone numbers, and URLs with custom categories, tags, and privacy settings. When you need an entry, just click to insert it into the input bar, or hold Ctrl/Command and click to send it directly to the model.

All sensitive data is encrypted client-side using WebCrypto with PBKDF2-SHA256 150,000 rounds and AES-256-GCM. Non-private entries are stored in plaintext for quick access, while private entries and WebDAV credentials are encrypted. Private data only exists in browser memory when unlocked, and is cleared immediately when the vault is locked. The plugin currently only recognizes 11-digit Chinese mainland phone numbers starting with 1[3-9], and does not support foreign numbers or landlines. If you lose both your master password and security word, your data cannot be recovered due to the encryption design. It supports backup and restore via WebDAV, and is released under the MIT open source license.

这是一款专门为 DeepSeek Harness 开发的原生插件,用于在DSH Web界面的输入栏添加快捷输入保险箱功能。它会在「用量」和「发送」按钮之间插入一个灰色圆形快捷按钮,点击即可展开保险箱面板,方便用户快速填入预存的常用信息,还支持自动识别会话中的敏感信息并提示用户收录。该插件可通过DSH CLI命令直接从GitHub安装,也支持本地源码开发安装,修改源码后无需重新安装即可生效。

这个插件面向需要频繁输入敏感常用信息的DSH用户,典型使用流程是:首次使用时设置主密码和安全词,之后添加分类标签管理自己的密钥、服务器地址、手机号、网址等信息。需要输入时点击按钮展开面板,点击对应条目即可填入输入框,按住Ctrl或Cmd点击可直接发送。当会话中检测到敏感信息,按钮会出现红点提示,用户点击后即可快速收录这些信息到保险箱。

该插件采用端侧加密方案,非私密记录明文存储,私密记录和WebDAV配置通过浏览器端WebCrypto加密,仅解锁后内存留存明文,锁定即清空,数据存放在DSH的本地目录中。支持WebDAV备份恢复,忘记密码可通过安全词重置,若主密码和安全词都丢失则数据无法恢复。插件仅支持识别中国大陆手机号,不支持识别外国号码和座机,开源协议为MIT。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 2 warnings2 项注意
  • No license declared - all rights reserved by default; ask the author before commercial use or redistribution未声明开源许可证 —— 默认「保留所有权利」,商用或再分发前先问作者
  • Only 5 stars - very few users, little community feedback星标只有 5,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add 534119219/chicheng-quickinput

把 534119219/chicheng-quickinput 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

chicheng-vault — DSH 便捷输入保险箱

在 DeepSeek Harness Web 界面的输入栏「用量」与「发送」按钮之间添加一个灰色圆形快捷按钮(与发送按钮同尺寸同圆角),点击展开「保险箱」面板:

  • 收录密钥、服务器、地址、手机号、网址等常用信息,点击单条记录直接填入输入框,Ctrl(或 ⌘)+ 点击直接发送;
  • 自动识别:会话中出现敏感信息时(密钥/JWT/PEM、URL、SSH 服务器、中国大陆手机号、IP、中文地址),按钮上出现红点脉冲提示(不自动弹出面板),点击按钮后可在面板顶部逐条收录;手机号仅识别中国手机号(11 位、1[3-9] 开头,可带 +86/86 前缀),不识别外国号码与座机;
  • 打开面板免密码:面板直接展示所有非私密记录;点击私密记录(或编辑私密记录 / 使用加密的 WebDAV 配置)时才验证主密码;验证一次持续有效,无操作超过设定时长(默认 10 分钟,可配置,0 = 关闭)后私密内容自动重新锁定,也可在面板头部手动锁定;
  • 首次使用设置主密码与安全词;忘记密码可用安全词重置;
  • 每条记录支持名称、分类、标签、是否私密,并记录创建时间;支持编辑/删除、全局模糊搜索(名称/标签/分类);
  • WebDAV 备份/恢复(经宿主端代理转发,规避 CORS)。

数据安全(v2)

  • 保险箱 store 分为两层:非私密记录为明文(仅含常用信息,方便免密查看),私密记录内容与 WebDAV 配置在浏览器内以 WebCrypto(PBKDF2-SHA256 15 万轮 + AES-256-GCM) 加密;
  • 随机保险箱密钥 K 分别被主密码派生密钥与安全词派生密钥包裹后持久化;密文由宿主端存于 $DSH_HOME/vault/store.json,私密明文只存在于解锁后的浏览器内存,锁定即清空;
  • 自动识别只保存内容哈希用于去重,不落明文;
  • 忘记主密码时,只有安全词能解出 K 并重置密码;若两者皆失,数据不可恢复(加密设计使然)。

功能对照

需求 实现
用量与发送之间灰色按钮 conversation.input.right slot 取 props,按钮本体通过 DOM 锚点插入输入栏「用量」与「发送」之间;34×34 圆钮,灰底
点击展开 + 过渡动画 浮动面板(fixed 定位,fade + slide 动画,Esc/外部点击关闭)
打开面板免密码 面板直接加载 store,非私密记录可见;仅私密内容触发密码验证
验证一次持续有效 解锁后 K 保留在内存;无操作超过 autoLockMinutes 自动重新锁定(pointerdown/keydown 刷新活跃时间,15 秒轮询)
私密记录二次验证 点击/编辑私密记录 → 密码弹窗 → 全局解锁(不再逐条验证)
安全词重置密码 设置内「忘记密码」→ 安全词验证 → 设置新密码(可换安全词)
自动记录会话中的密钥/服务器/地址/手机号/网址 宿主端监听 session/event,模式识别后按钮红点提示;手机号仅识别中国大陆手机号并归一化为 11 位
每条记录名称/分类/标签/私密 新增/编辑表单完整支持;私密记录加密存储
记录创建时间 每条记录保存 createdAt,列表展示
WebDAV 备份 设置分区内配置地址/账号/密码(配置加密存储)→ 立即备份/从备份恢复
左侧分类栏 密钥/服务器/地址/手机号/网址/其他 + 动态新增分类
点击填入、Ctrl+点击发送 inputActions.setDraft / setDraft + submit
全局搜索,搜索时分类不选中 名称/标签/分类模糊匹配,搜索中侧栏无选中态
每条记录编辑/删除按钮 行内图标按钮 + 删除确认
右上角「新增」按钮 面板头部右侧,打开新增表单
设置界面分区 + 圆角卡片 自动识别 / 自动锁定 / WebDAV / 修改密码 四个圆角边框分区,顶部对齐、可关闭
旧版本数据迁移 检测到 v1 store 时展示迁移页,输入原密码升级为 v2(私密内容改加密、非私密改明文);兼容历史 KDF 参数(PBKDF2 迭代数/哈希),vault 密文缺失时按空库迁移;忘记密码可用安全词重置并完成迁移

安装(以 web profile 为例)

从 GitHub 安装:

dsh plugin --profile web add 534119219/chicheng-quickinput

本地开发安装(编辑源码即时生效):

cd /d/Harness/chicheng-vault
dsh plugin --profile web add file:D:/Harness/chicheng-vault
# 若 pnpm 生成了快照副本,执行 relink 指向源码目录:
powershell -File D:/Harness/relink-plugins.ps1 -Name chicheng-vault

修改插件源码后无需重新安装,但宿主端改动需要手动重启 dsh web,客户端改动刷新页面即可(Ctrl+F5 硬刷新)。

测试

node test/matcher.test.mjs     # 模式识别纯函数
node test/host.smoke.mjs       # 宿主端 API + 监听 + WebDAV 代理(临时 DSH_HOME)
node test/crypto.test.mjs      # 加密方案全链路(v2:setup/unlock/lock/reset/change/迁移)
node test/client.load.mjs      # 客户端 bundle 结构

数据位置

  • $DSH_HOME/vault/store.json — v2 store(密钥包装 + 私密记录密文 + WebDAV 配置密文 + 非私密明文 + 开关)
  • $DSH_HOME/vault/suggestions.json — 待收录建议与去重哈希
  • 备份文件由 WebDAV 目标地址决定(默认 chicheng-vault-backup.json)

License

MIT

← 上一个 Prev dsh-guide-dog 下一个 Next deep-structural-analysis-skill →