One of the core capabilities of DeepSeek Harness (DSH) is runtime dynamic loading of Cordis tools. The geekricardo/dsh-cordis-mcp plugin exposes this toolset to Claude Code through the MCP protocol. It acts as a proxy, allowing Claude Code to load, define, run, update, stop, and delete DSH dynamic plugins in real time, with capabilities equivalent to directly using cordis_* commands in a DSH session.

Core Features

The plugin provides the following capabilities:

  1. List manageable live DSH sessions.
  2. List all dynamic plugins and their status in the target session.
  3. Plugin/Package details: returns source code when a packageId is provided.
  4. Inspect the provider directory (host + client).
  5. Execute read-only inspect queries (services/events/built-ins/slots/topics/tool directories).
  6. Define an immutable Package.
  7. Activate a Package (supports run/update) and returns an awaiting-approval state.
  8. Stop execution (cancels pending approvals and retains definitions).
  9. Permanently delete a plugin (including all Packages, authorizations, and version pointers).

Installation and Enablement

Use the official installation script:

curl -fsSL https://raw.githubusercontent.com/GeekRicardo/dsh-cordis-mcp/main/install.sh | bash

The script automatically completes the following steps:
1. Writes the dependency to ~/.dsh/profiles/web/package.json.
2. Appends dsh-cordis-mcp to dsh.profile.bundles.
3. Runs pnpm install.
4. Prompts you to restart the service.

After installation, restart the DSH service (for example, using pm2):

pm2 restart dsh-web

Connecting to Claude Code

Add the MCP service in Claude Code:

claude mcp add dsh --transport http http://127.0.0.1:8090/mcp

Authentication Configuration

The MCP endpoint enforces Bearer authentication and returns a 503 error if no Token is configured. The Token must be configured in the DSH settings page (dsh-cordis-mcp settings), and supports automatic generation, custom input, and regeneration.

Set the request header in the Claude Code configuration file (such as .mcp.json):

{
  "mcpServers": {
    "dsh": {
      "type": "http",
      "url": "http://127.0.0.1:8090/mcp",
      "headers": { "Authorization": "Bearer <设置页里的 token>" }
    }
  }
}

Security and Notes

This plugin has permissions equivalent to Shell. Do not expose the port to non-local environments.

  • Enforced Authentication: The endpoint enforces Bearer authentication; requests without a Token always return 401 or 503.
  • Loopback Restriction: Only loopback access is accepted (127.* / localhost / ::1), and external access is denied.
  • No CORS: The endpoint never returns CORS headers, so web pages cannot directly read responses.
  • Session Ownership: Dynamic plugins are owned by sessions and exist as process memory state; they are cleared when DSH restarts.
  • Approval Flow: Packages containing a Client half must go through the DSH approval flow on first run and return awaiting-approval.
  • Token Resolution Priority: Settings page configuration > DSH_MCP_TOKEN environment variable > automatically generated.