Bundle
dsh-password
DSH plugin: strong password / diceware passphrase generator (password_generate).
- Source
- ZhijiangTang
- stars
- 1 stars
- License
- MIT
- Updated
- Updated yesterday
Readme
# dsh-password
DSH 插件:强密码 / Diceware 口令生成工具,注册一个 `password_generate` 工具。
纯 ESM、零依赖、无构建步骤。所有随机性来自 `node:crypto.randomInt`(均匀采样,加密安全)。
## 安装
```sh
dsh plugin --profile <name> add file:./plugins/dsh-password
# 或发布后
dsh plugin --profile <name> add dsh-password
```
## 工具 `password_generate`
参数:
| 参数 | 类型 | 默认 | 说明 |
|---|---|---|---|
| `type` | string(enum `random`/`diceware`) | `random` | 生成类型 |
| `length` | number | `20` | 密码长度(8–128,仅 `random`) |
| `count` | number | `1` | 生成数量(1–10) |
| `words` | number | `5` | Diceware 单词数(4–8,仅 `diceware`) |
| `separator` | string | `-` | Diceware 单词连接符 |
| `includeSymbols` | boolean | `true` | 是否包含符号(仅 `random`) |
| `avoidAmbiguous` | boolean | `true` | 排除易混淆字符 `Il1O0`(仅 `random`) |
返回值(规范 JSON 对象):
```json
{
"ok": true,
"passwords": ["...", "..."],
"type": "random",
"entropyBits": 153.8,
"charset": "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789!@#$%^&*()_+-=[]{}|;:,.<>?",
"count": 2,
"error": ""
}
```
`error` 在成功时为空字符串,失败时携带原因。
## 生成规则
- **random**:`node:crypto.randomInt` 均匀采样字符集(大小写字母 + 数字 + 符号 `!@#$%^&*()_+-=[]{}|;:,.<>?`,`avoidAmbiguous` 时剔除 `Il1O0`)。生成后校验每个密码至少含 1 个小写 / 1 个大写 / 1 个数字(`includeSymbols` 时再保证 1 个符号),不满足则重生成(上限 20 次,超限退化为确定性补类兜底)。
- **diceware**:内置 256 个常见英文短词,`randomInt` 采样 `words` 个,用 `separator` 连接;熵估算为 `words × log2(256)` bits。
## 安全说明
- 随机源为 `node:crypto.randomInt`(crypto 强随机,均匀采样),不依赖 `Math.random`。
- 口令仅在内存中生成并返回,**不落盘、不写日志**;插件不持有任何持久状态。
- Diceware 词表为内置 256 词,每个单词贡献 `log2(256) = 8` bits 熵。
- 生成的密码/口令会出现在工具返回与界面摘要中,请在使用后自行妥善保管,勿与他人分享。
Install
dsh plugin --profile web add github:ZhijiangTang/dsh-password
Profile: web
With the hub plugin installed, ask your agent to install it by name — it resolves the same plan shown here.
dsh plugin --profile web add github:stvlynn/dsh.fish#path:packages/dsh-plugin-hub
install dsh-password from the hub
- This source has no pinned commit, so a later push upstream changes what installs. Prefer pinning a commit.