DSH Design Mode keeps provider credentials on the Host side and resolves them through the DSH credential provider only when a job starts.
OPENAI_API_KEY,FAL_KEY, or any other provider token.envfiles.dsh/design-modesession directories- private source images or exported workspace archives
- terminal logs that contain request headers or credentials
Please open a GitHub security advisory for the repository instead of filing a public issue. Include a minimal reproduction that uses placeholder credentials and synthetic assets.