One of the core capabilities of DeepSeek Harness (DSH) is runtime dynamic loading of Cordis tools. The geekricardo/dsh-cordis-mcp plugin exposes this toolset to Claude Code through the MCP protocol. It acts as a proxy, allowing Claude Code to load, define, run, update, stop, and delete DSH dynamic plugins in real time, with capabilities equivalent to directly using cordis_* commands in a DSH session.
Core Features¶
The plugin provides the following capabilities:
- List manageable live DSH sessions.
- List all dynamic plugins and their status in the target session.
- Plugin/Package details: returns source code when a
packageIdis provided. - Inspect the provider directory (host + client).
- Execute read-only inspect queries (services/events/built-ins/slots/topics/tool directories).
- Define an immutable Package.
- Activate a Package (supports run/update) and returns an
awaiting-approvalstate. - Stop execution (cancels pending approvals and retains definitions).
- Permanently delete a plugin (including all Packages, authorizations, and version pointers).
Installation and Enablement¶
Use the official installation script:
curl -fsSL https://raw.githubusercontent.com/GeekRicardo/dsh-cordis-mcp/main/install.sh | bash
The script automatically completes the following steps:
1. Writes the dependency to ~/.dsh/profiles/web/package.json.
2. Appends dsh-cordis-mcp to dsh.profile.bundles.
3. Runs pnpm install.
4. Prompts you to restart the service.
After installation, restart the DSH service (for example, using pm2):
pm2 restart dsh-web
Connecting to Claude Code¶
Add the MCP service in Claude Code:
claude mcp add dsh --transport http http://127.0.0.1:8090/mcp
Authentication Configuration¶
The MCP endpoint enforces Bearer authentication and returns a 503 error if no Token is configured. The Token must be configured in the DSH settings page (dsh-cordis-mcp settings), and supports automatic generation, custom input, and regeneration.
Set the request header in the Claude Code configuration file (such as .mcp.json):
{
"mcpServers": {
"dsh": {
"type": "http",
"url": "http://127.0.0.1:8090/mcp",
"headers": { "Authorization": "Bearer <设置页里的 token>" }
}
}
}
Security and Notes¶
This plugin has permissions equivalent to Shell. Do not expose the port to non-local environments.
- Enforced Authentication: The endpoint enforces Bearer authentication; requests without a Token always return 401 or 503.
- Loopback Restriction: Only loopback access is accepted (
127.*/localhost/::1), and external access is denied. - No CORS: The endpoint never returns CORS headers, so web pages cannot directly read responses.
- Session Ownership: Dynamic plugins are owned by sessions and exist as process memory state; they are cleared when DSH restarts.
- Approval Flow: Packages containing a Client half must go through the DSH approval flow on first run and return
awaiting-approval. - Token Resolution Priority: Settings page configuration >
DSH_MCP_TOKENenvironment variable > automatically generated.