
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@pymodel/dsh-tavily
Advanced tools
Tavily web search + Tavily MCP for DSH: settings toggle to official DeepSeek, keyless search, MCP extract/crawl/map
Tavily for DeepSeek Harness: adds the Tavily Search API as a web search provider, plus a Tavily MCP bridge for extract / crawl / map tools.
npm (stable, official recommendation):
dsh plugin --profile web add @pymodel/dsh-tavily
dsh web
Or follow GitHub (latest commit on the repo):
dsh plugin --profile web add github:pymodel/dsh-research-plugins#path:packages/dsh-tavily
Settings → Plugins → Plugin settings → Tavily web search: turn the toggle on. The key is optional; leave it blank for keyless search. Test connection at the bottom-left checks that search works now (including keyless).
Pin a commit:
dsh plugin --profile web add github:pymodel/dsh-research-plugins#path:packages/dsh-tavily#<commit>
Remove:
dsh plugin --profile web remove dsh-tavily
dsh.bundle· prebuiltlib/· git install does not needallowBuilds
Authorization: Bearermax_results: 1); keyless if no key, account quota if a key is saved (1 credit)mcp__tavily__extract, mcp__tavily__crawl, mcp__tavily__map tools (requires a key, see below)| Toggle | Key | web_search |
|---|---|---|
| Off (default) | — | official DeepSeek |
| On | empty | Tavily keyless |
| On | set | Tavily account quota |
Provider id: tavily.
The bundled MCP row registers Tavily's extract / crawl / map tools under the tavily namespace. The hosted Tavily MCP server requires a key, so the row is enabled only when TAVILY_API_KEY is present in the launch environment:
export TAVILY_API_KEY=tvly-...
or in a project .env / $DSH_HOME/.env:
TAVILY_API_KEY=tvly-...
The key is interpolated into the endpoint URL at load time and never written to YAML. A key added to .env needs a dsh web restart.
| Ref | Meaning |
|---|---|
TAVILY_API_KEY | Optional (search). Present = account quota; absent = keyless |
TAVILY_SEARCH_ENABLED | Present = on; unset = off |
The search key and toggle are stored on the credentials plane ($DSH_HOME/.credentials.yaml). The MCP bridge reads TAVILY_API_KEY from the launch environment instead, because MCP rows resolve before credentials are materialized. Do not commit real keys.
@pymodel/dsh-tavily. Web search provider with settings toggle (off = official DeepSeek, on = Tavily) plus a Tavily MCP bridge (extract / crawl / map). English-only localisation.FAQs
Tavily web search + Tavily MCP for DSH: settings toggle to official DeepSeek, keyless search, MCP extract/crawl/map
The npm package @pymodel/dsh-tavily receives a total of 314 weekly downloads. As such, @pymodel/dsh-tavily popularity was classified as not popular.
We found that @pymodel/dsh-tavily demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.