
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
dsh-netcafe-writer
Advanced tools
Long-form drafts with the structure already decided. Blog posts, press releases, product and job descriptions, FAQs, email templates, READMEs, changelogs, meeting minutes, weekly reports, cover letters, academic polish, name ideas.
npm 上的包名是
dsh-netcafe-writer—— npm 判定dsh-writer与csv-writer过于相似而拒收。 仓库名不变,dsh plugin add github:...的装法照旧。
Blog posts, press releases, product and job descriptions, FAQs, email templates, READMEs, changelogs, meeting minutes, weekly reports, cover letters, academic polish, name ideas.
Each of these ships the format constraints — the section order, the length targets, the conventions of the genre — so you are not re-specifying "write a changelog" from scratch every time. The model does the writing; the tool supplies the shape.
Every set ships what_can_you_do — describe a task in any language, get the exact tool plus a ready-to-run call.
dsh plugin --profile <your-profile> add github:mario03690/dsh-writer
Thin config layer only (one @deepseek-ai/dsh-mcp-client row, shipped as cordis.patch.yml) — no tool code runs on your machine. Built against the MCP client config shape of the dsh v0.1 developer preview; verified against the live endpoint on 2026-08-22.
Every tool in this pack calls a model — none of it is free-quota deterministic work. $0.015–$0.03 per call depending on length. Every response reports its exact USD cost; failed calls are not charged. If you want the zero-model, always-reproducible tools instead, see dsh-validate or dsh-devkit.
No signup for the free anonymous quota. Documents are processed in memory and not retained. The config URL carries ?s=dsh-writer — a channel tag identifying the install path, not you.
Disclosure: built and run by the team behind ainetcafe.com — our own service, free tier plus paid usage. Full bundle (everything at once): dsh-netcafe. MIT.
| Signal | This plugin |
|---|---|
| Runtime | dsh v0.1 developer preview (Cordis v4). Touches only the MCP client config shape — the narrowest surface available. Verified against a live endpoint on 2026-08-22. |
| What runs locally | Nothing. Ships one cordis.patch.yml row; there is no tool code, no build step and no lifecycle script in this package. |
| Filesystem access | None. |
| Shell / process access | None. |
| Network access | Outbound HTTPS to ainetcafe.com only, from the MCP client that dsh already ships. |
| Credentials | None required for the free tier. An optional AllRouter key, if you supply one, is sent by dsh as a request header and is never stored by us. |
| Data retention | Documents and prompts are processed in memory and not retained. |
| Dependencies | One peer dependency: @deepseek-ai/dsh-mcp-client (ships with dsh). |
| License | MIT (see LICENSE). |
| Publisher | The team that runs ainetcafe.com. Issues get a same-day reply. |
A directory listing is not a security review. Read
cordis.patch.yml— it is short enough to read in full in under a minute.
FAQs
Long-form drafts with the structure already decided. Blog posts, press releases, product and job descriptions, FAQs, email templates, READMEs, changelogs, meeting minutes, weekly reports, cover letters, academic polish, name ideas.
The npm package dsh-netcafe-writer receives a total of 37 weekly downloads. As such, dsh-netcafe-writer popularity was classified as not popular.
We found that dsh-netcafe-writer demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.