Back to home@PerryLink

dsh-cert-mcp

No description

Stars
0
Language
JavaScript
Created
Sep 3, 2026
Updated
Sep 3, 2026

Introduction

dsh-cert-mcp

Read-only MCP server that exposes the dsh-plugin-certification registry: certification grades, snapshot dates and five-dimension evidence for DeepSeek Harness (DSH) plugins. Zero runtime dependencies, stdio transport.

Tools

ToolInputReturns
get_certificationowner, repoFull certification record (grade, snapshot, five dimensions, veto, notes) or "no record"
list_certifiedEvery entry in the public registry: repo / grade / snapshot
certification_specSpec v1 summary: five dimensions, grade scale, veto rule

The embedded snapshot lives in data/certified.json (synced from the certification repo) and the server refreshes it from the public registry at most once per five minutes. No writes, no secrets, no code execution.

Install

git clone https://github.com/PerryLink/dsh-cert-mcp
cd dsh-cert-mcp
node src/index.js        # stdio server

After the npm release you will be able to run it directly: npx @perrylink/dsh-cert-mcp.

Register in an MCP client

Claude Code:

claude mcp add dsh-cert -- node <path-to-repo>/src/index.js

Claude Desktop (claude_desktop_config.json):

{
  "mcpServers": {
    "dsh-cert": {
      "command": "node",
      "args": ["<path-to-repo>/src/index.js"]
    }
  }
}

DSH: add it through dsh-mcp-panel as a stdio server, or any MCP client that supports stdio.

Why this exists

The official DeepSeek Harness repository does not run a plugin registry and does not accept external PRs; discovery happens through the dsh-plugin GitHub topic and community lists, none of which certify anything. dsh-plugin-certification turns "can I install this plugin" into a reproducible five-dimension check (manifest, build hygiene, supply-chain Scorecard, release provenance, sandboxed install smoke test) with a public registry and README badges. This MCP server is the same data with an agent-facing interface: agents can look up a plugin's certification before recommending or installing it.

Registry

Data source: PerryLink/dsh-plugin-certificationdata/certified.json, spec v1.

Development

node test/smoke.mjs

License

Apache-2.0. A listing or grade is an evidence record, not a security guarantee: plugins run inside your DSH process with your permissions.