534119219/chicheng-quickinput
DSH 便捷输入保险箱插件:输入栏「用量」与「发送」之间一键展开,自动收录会话中的密钥/网址/服务器/手机号等;点击填入或 Ctrl+点击直接发送;私密内容密码保护 + WebDAV 备份。
Project Overview项目介绍
This is a native plugin built exclusively for DeepSeek Harness that adds a quick input secure vault feature to the DSH web interface. It inserts a small gray circular button between the "usage" and "send" buttons in the input bar, which opens the vault panel when clicked. You can install it directly from GitHub via the DSH CLI using the command dsh plugin --profile web add 534119219/chicheng-quickinput, or you can install it from a local source directory for development. When modifying the plugin source code, you do not need to reinstall it, just refresh the browser page or restart the DSH web server for changes to take effect.
The plugin is designed for DSH users who frequently enter sensitive or commonly used information. On first run, you will be prompted to set a master password and a security word, which you can use to reset your password if you forget it. After setup, you can add and organize your commonly used entries like API keys, server addresses, phone numbers, and URLs with custom categories, tags, and privacy settings. When you need an entry, just click to insert it into the input bar, or hold Ctrl/Command and click to send it directly to the model.
All sensitive data is encrypted client-side using WebCrypto with PBKDF2-SHA256 150,000 rounds and AES-256-GCM. Non-private entries are stored in plaintext for quick access, while private entries and WebDAV credentials are encrypted. Private data only exists in browser memory when unlocked, and is cleared immediately when the vault is locked. The plugin currently only recognizes 11-digit Chinese mainland phone numbers starting with 1[3-9], and does not support foreign numbers or landlines. If you lose both your master password and security word, your data cannot be recovered due to the encryption design. It supports backup and restore via WebDAV, and is released under the MIT open source license.
这是一款专门为 DeepSeek Harness 开发的原生插件,用于在DSH Web界面的输入栏添加快捷输入保险箱功能。它会在「用量」和「发送」按钮之间插入一个灰色圆形快捷按钮,点击即可展开保险箱面板,方便用户快速填入预存的常用信息,还支持自动识别会话中的敏感信息并提示用户收录。该插件可通过DSH CLI命令直接从GitHub安装,也支持本地源码开发安装,修改源码后无需重新安装即可生效。
这个插件面向需要频繁输入敏感常用信息的DSH用户,典型使用流程是:首次使用时设置主密码和安全词,之后添加分类标签管理自己的密钥、服务器地址、手机号、网址等信息。需要输入时点击按钮展开面板,点击对应条目即可填入输入框,按住Ctrl或Cmd点击可直接发送。当会话中检测到敏感信息,按钮会出现红点提示,用户点击后即可快速收录这些信息到保险箱。
该插件采用端侧加密方案,非私密记录明文存储,私密记录和WebDAV配置通过浏览器端WebCrypto加密,仅解锁后内存留存明文,锁定即清空,数据存放在DSH的本地目录中。支持WebDAV备份恢复,忘记密码可通过安全词重置,若主密码和安全词都丢失则数据无法恢复。插件仅支持识别中国大陆手机号,不支持识别外国号码和座机,开源协议为MIT。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:chicheng-quickinput(534119219/chicheng-quickinput)
仓库:https://github.com/534119219/chicheng-quickinput
本站详情页:https://www.yhbd.top/plugins/534119219-chicheng-quickinput/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证未声明 · ⭐ 5 · 最近提交 2026-08-26 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- No license declared - all rights reserved by default; ask the author before commercial use or redistribution未声明开源许可证 —— 默认「保留所有权利」,商用或再分发前先问作者
- Only 5 stars - very few users, little community feedback星标只有 5,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add 534119219/chicheng-quickinput
把 534119219/chicheng-quickinput 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
chicheng-vault — DSH 便捷输入保险箱
在 DeepSeek Harness Web 界面的输入栏「用量」与「发送」按钮之间添加一个灰色圆形快捷按钮(与发送按钮同尺寸同圆角),点击展开「保险箱」面板:
- 收录密钥、服务器、地址、手机号、网址等常用信息,点击单条记录直接填入输入框,
Ctrl(或⌘)+ 点击直接发送; - 自动识别:会话中出现敏感信息时(密钥/JWT/PEM、URL、SSH 服务器、中国大陆手机号、IP、中文地址),按钮上出现红点脉冲提示(不自动弹出面板),点击按钮后可在面板顶部逐条收录;手机号仅识别中国手机号(11 位、
1[3-9]开头,可带+86/86前缀),不识别外国号码与座机; - 打开面板免密码:面板直接展示所有非私密记录;点击私密记录(或编辑私密记录 / 使用加密的 WebDAV 配置)时才验证主密码;验证一次持续有效,无操作超过设定时长(默认 10 分钟,可配置,0 = 关闭)后私密内容自动重新锁定,也可在面板头部手动锁定;
- 首次使用设置主密码与安全词;忘记密码可用安全词重置;
- 每条记录支持名称、分类、标签、是否私密,并记录创建时间;支持编辑/删除、全局模糊搜索(名称/标签/分类);
- WebDAV 备份/恢复(经宿主端代理转发,规避 CORS)。
数据安全(v2)
- 保险箱 store 分为两层:非私密记录为明文(仅含常用信息,方便免密查看),私密记录内容与 WebDAV 配置在浏览器内以 WebCrypto(PBKDF2-SHA256 15 万轮 + AES-256-GCM) 加密;
- 随机保险箱密钥 K 分别被主密码派生密钥与安全词派生密钥包裹后持久化;密文由宿主端存于
$DSH_HOME/vault/store.json,私密明文只存在于解锁后的浏览器内存,锁定即清空; - 自动识别只保存内容哈希用于去重,不落明文;
- 忘记主密码时,只有安全词能解出 K 并重置密码;若两者皆失,数据不可恢复(加密设计使然)。
功能对照
| 需求 | 实现 |
|---|---|
| 用量与发送之间灰色按钮 | conversation.input.right slot 取 props,按钮本体通过 DOM 锚点插入输入栏「用量」与「发送」之间;34×34 圆钮,灰底 |
| 点击展开 + 过渡动画 | 浮动面板(fixed 定位,fade + slide 动画,Esc/外部点击关闭) |
| 打开面板免密码 | 面板直接加载 store,非私密记录可见;仅私密内容触发密码验证 |
| 验证一次持续有效 | 解锁后 K 保留在内存;无操作超过 autoLockMinutes 自动重新锁定(pointerdown/keydown 刷新活跃时间,15 秒轮询) |
| 私密记录二次验证 | 点击/编辑私密记录 → 密码弹窗 → 全局解锁(不再逐条验证) |
| 安全词重置密码 | 设置内「忘记密码」→ 安全词验证 → 设置新密码(可换安全词) |
| 自动记录会话中的密钥/服务器/地址/手机号/网址 | 宿主端监听 session/event,模式识别后按钮红点提示;手机号仅识别中国大陆手机号并归一化为 11 位 |
| 每条记录名称/分类/标签/私密 | 新增/编辑表单完整支持;私密记录加密存储 |
| 记录创建时间 | 每条记录保存 createdAt,列表展示 |
| WebDAV 备份 | 设置分区内配置地址/账号/密码(配置加密存储)→ 立即备份/从备份恢复 |
| 左侧分类栏 | 密钥/服务器/地址/手机号/网址/其他 + 动态新增分类 |
| 点击填入、Ctrl+点击发送 | inputActions.setDraft / setDraft + submit |
| 全局搜索,搜索时分类不选中 | 名称/标签/分类模糊匹配,搜索中侧栏无选中态 |
| 每条记录编辑/删除按钮 | 行内图标按钮 + 删除确认 |
| 右上角「新增」按钮 | 面板头部右侧,打开新增表单 |
| 设置界面分区 + 圆角卡片 | 自动识别 / 自动锁定 / WebDAV / 修改密码 四个圆角边框分区,顶部对齐、可关闭 |
| 旧版本数据迁移 | 检测到 v1 store 时展示迁移页,输入原密码升级为 v2(私密内容改加密、非私密改明文);兼容历史 KDF 参数(PBKDF2 迭代数/哈希),vault 密文缺失时按空库迁移;忘记密码可用安全词重置并完成迁移 |
安装(以 web profile 为例)
从 GitHub 安装:
dsh plugin --profile web add 534119219/chicheng-quickinput
本地开发安装(编辑源码即时生效):
cd /d/Harness/chicheng-vault
dsh plugin --profile web add file:D:/Harness/chicheng-vault
# 若 pnpm 生成了快照副本,执行 relink 指向源码目录:
powershell -File D:/Harness/relink-plugins.ps1 -Name chicheng-vault
修改插件源码后无需重新安装,但宿主端改动需要手动重启 dsh web,客户端改动刷新页面即可(
Ctrl+F5硬刷新)。
测试
node test/matcher.test.mjs # 模式识别纯函数
node test/host.smoke.mjs # 宿主端 API + 监听 + WebDAV 代理(临时 DSH_HOME)
node test/crypto.test.mjs # 加密方案全链路(v2:setup/unlock/lock/reset/change/迁移)
node test/client.load.mjs # 客户端 bundle 结构
数据位置
$DSH_HOME/vault/store.json— v2 store(密钥包装 + 私密记录密文 + WebDAV 配置密文 + 非私密明文 + 开关)$DSH_HOME/vault/suggestions.json— 待收录建议与去重哈希- 备份文件由 WebDAV 目标地址决定(默认
chicheng-vault-backup.json)
License
MIT
lssyd20070106/dsh-ui-preset-enhance
Jolly-J/dsh-deepseek-billing
jLeon-account/dsh-client-usage
jiangli07/dsh-deepseek-quota-bar
boNeXY226/dsh-cost-chip
MeteorNOX/DeepSeek-Balance-Whale-Widget