
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
dsh-codebase-chat-mcp
Advanced tools
Standalone MCP server for dsh-codebase-chat — codebase intelligence tools for Cursor, Claude, Windsurf and any MCP client. Works without DeepSeek Harness.
Standalone MCP server for dsh-codebase-chat.
Works with Windsurf, Cursor, Claude, and any MCP-compatible IDE — without DeepSeek Harness.
This package exposes the same codebase intelligence tools as the DeepSeek Harness plugin, but as a standalone Model Context Protocol (MCP) server. It scans a local project, builds a sourced prompt, and either:
promptOnly: true; orDEEPSEEK_API_KEY or OPENAI_API_KEY is set.Deterministic tools (codebase_health, codebase_impact, codebase_deep_audit, codebase_check, codebase_doctor) need no model at all — same input, same output, fully offline.
In prompt mode your code never leaves your machine at all.
DEEPSEEK_API_KEY or OPENAI_API_KEY) — only needed if you want the server to call the LLM itself. Without a key, tools return the built prompt for the host model.npm install -g dsh-codebase-chat-mcp
# Or run without installing
npx dsh-codebase-chat-mcp
npx dsh-codebase-chat-mcp setup
The wizard detects installed MCP clients (Claude Desktop, Claude Code, Cursor, Windsurf, VS Code, Zed, Gemini CLI, Kiro, Cline, Roo Code), lets you pick which ones to configure, asks how you want answers (prompt-only host model or direct API key), and writes the dsh-codebase-chat server entry for you — preserving your existing mcpServers and backing up each config file (.bak). It always prints a manual entry at the end for any other MCP client. No API key needed for prompt-only mode.
git clone https://github.com/shinzarou-eng/dsh-codebase-chat.git
cd dsh-codebase-chat/mcp
pnpm install
Set one of:
$env:DEEPSEEK_API_KEY = "sk-..."
# or
$env:OPENAI_API_KEY = "sk-..."
Optional:
DEEPSEEK_BASE_URL or OPENAI_BASE_URL (default: https://api.deepseek.com/v1)CODEBASE_MODEL (default: deepseek-chat).codebase-chat.jsonA .codebase-chat.json at the indexed project root tunes every tool:
lang (default prompt language), maxTokens (context budget), ignoreDirs,
ignoreFiles, ignoreGlobs (indexing/analysis exclusions) and protectedPaths
(apply pipeline). Explicit tool arguments always win. See the main README for the
full schema.
Add to your MCP config:
{
"mcpServers": {
"dsh-codebase-chat": {
"command": "npx",
"args": ["dsh-codebase-chat-mcp"],
"env": {
"DEEPSEEK_API_KEY": "sk-...",
"CODEBASE_MODEL": "deepseek-chat"
}
}
}
}
On Windows with a local clone you can also use the absolute path:
{
"mcpServers": {
"dsh-codebase-chat": {
"command": "node",
"args": [
"C:\\Users\\YOU\\dsh-codebase-chat\\mcp\\index.mjs"
],
"env": {
"DEEPSEEK_API_KEY": "sk-..."
}
}
}
}
| Tool | Purpose |
|---|---|
codebase_chat | Q&A on a local project |
codebase_search | Search symbol or term |
codebase_explain | Explain a file or symbol |
codebase_refactor | Propose a refactor |
codebase_intelligence | Full CTO brief |
codebase_audit | Tech-debt & non-conformities |
codebase_report | Strategic board report |
codebase_ceo | One-page CEO brief |
codebase_tasks | Generate a TASKS.md plan |
codebase_player | UX / playthrough brief |
codebase_crea | Creative / marketing ideas from the code |
codebase_health | Deterministic static analysis — cycles, dead code, duplication, complexity, health score. No LLM needed |
codebase_impact | Deterministic blast-radius analysis — which files transitively depend on a target (file, required). No LLM needed |
codebase_deep_audit | Deterministic full audit — git churn & bus factor, churn × complexity risk, dependency integrity, per-function complexity, secrets, env coverage, README/config hygiene. ~30 analyses, all cited file:line. No LLM needed. Pass ui: true to also get a ui:// HTML dashboard resource (MCP-UI clients) |
codebase_check | Deterministic change verification — blast radius, complexity and findings on files changed vs base (default HEAD), diffed against .codebase-chat/baseline.json. No LLM needed |
codebase_doctor | Deterministic install diagnostic — node, index cache, LLM key presence, tree-sitter, baseline staleness, MCP client integrations. No LLM needed |
All tools accept:
projectPath (string, absolute or relative path, default: cwd)lang (string, fr or en, default: fr)focus / query (string, optional)embed (boolean, local semantic embeddings for better retrieval)promptOnly (boolean — return the built prompt for the host model instead of calling the LLM)diff (string, git ref e.g. main, HEAD~5 — scopes retrieval and codebase_health to files changed vs that ref, including uncommitted and untracked files)Every output is marked with:
[source: relative/path/file.ts:line][Confidence: X%][Severity: Critical/High/Medium/Low]By default the server uses stdio (MCP standard). SSE/HTTP transport can be added in a future version.
MIT — Built and maintained by shinzarou-eng.
FAQs
Standalone MCP server for dsh-codebase-chat — codebase intelligence tools for Cursor, Claude, Windsurf and any MCP client. Works without DeepSeek Harness.
We found that dsh-codebase-chat-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.