MagicCrazyMan/dsh-password-prompt
DeepSeek Harness plugin: masked password panel in the Web GUI (password_prompt tool) — bundle + dual-face plug
Lets an agent ask the user for a password through a masked HTML password panel in the Web GUI — or for an account + password with an extra account field — no interactive terminal required. When the agent calls the password_prompt tool, the browser pops the panel and waits; the user types (masked, with a show/hide toggle). The password is written to a private 0600 file and only its path is returned to the agent; the account is returned in the clear. The agent can then feed the password to e.g. ssh through an askpass script. Uses only public shipped seams: ctx.userQuestions.ask() (same service behind the built-in ask_user_question) and a composer entry at priority -1 that claims questions whose id is the reserved literal password.
Install
pnpm dsh plugin --profile web add github:MagicCrazyMan/dsh-password-promptpnpm dsh plugin --profile web add github:MagicCrazyMan/dsh-password-prompt (or dsh plugin … when dsh is on PATH). The first add fails by design: pnpm refuses a git dependency's prepare script until it is explicitly allowed — the error prints the exact allowBuilds key (bound to the commit SHA) to add to ~/.dsh/profiles/web/pnpm-workspace.yaml, then re-run the add. Every update fetches a new SHA, so a later reinstall prints a new key. Declares dsh.bundle + dsh.client — the patch layer activates the plugin automatically, no manual cordis.patch.yml edits.
Compatibility
DSH Web GUI (bundle + dual-face plugin); uses only public seams — ctx.userQuestions.ask() and the browser conversation.composer chain. No DSH core changes. Security: NOT security-audited — author explicitly warns against production/financial passwords.
Details
- Repo: MagicCrazyMan/dsh-password-prompt
- Category: Agent Capabilities
- Stars: 2
- Version: GitHub source (no npm package)
- Last push: 2026-08-17
- First seen: 2026-08-14
Recent updates
masked HTML password panel; optional account field; 0600 secret file; show/hide toggle; works with ssh askpass flows; no DSH core changes.
FAQ
- How does the agent request a password?
- It calls the password_prompt tool; the Web GUI pops a masked panel and waits. The user types, and only the path to a 0600 secret file is returned to the agent.
- Is this plugin security-audited?
- No — the author explicitly states it has NOT undergone strict security testing or an independent audit, and recommends against using it with production, financial, or highly sensitive passwords.
- Does it need DSH core changes?
- No — it only uses public seams: ctx.userQuestions.ask() and the browser composer chain.
Alternatives
slywalker2006/dsh-passwords · perrylink-dsh-permgate · ang-XWBWZ/dsh-approval-ai