
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
dsh-validate
Advanced tools
Offline identifier checks and Chinese money/tax arithmetic. Checksum-verified identifiers (mainland ID, USCC, bank card, plate, VIN, ISBN, IMEI, IBAN, EAN/UPC) plus amount-in-words, IIT, VAT, mortgage schedules and 调休-aware workday counts.
Checksum-verified identifiers (mainland ID, USCC, bank card, plate, VIN, ISBN, IMEI, IBAN, EAN/UPC) plus amount-in-words, IIT, VAT, mortgage schedules and 调休-aware workday counts.
Every tool here is a published algorithm — ISO 7064 MOD 11-2, Luhn, MOD-97, GB 11643 — computed in code, so the same input gives the same answer today and in five years. Nothing calls a model and nothing calls a third-party lookup service, so nothing here can break because someone else changed an API.
What is deliberately not here: phone-number carrier lookup, full administrative-division tables, courier detection. Those need external databases that change, or differ by locality. No reliable data, no tool — a "roughly right" answer would destroy the point of this pack.
Every set ships what_can_you_do — describe a task in any language, get the exact tool plus a ready-to-run call.
dsh plugin --profile <your-profile> add github:mario03690/dsh-validate
Thin config layer only (one @deepseek-ai/dsh-mcp-client row, shipped as cordis.patch.yml) — no tool code runs on your machine. Built against the MCP client config shape of the dsh v0.1 developer preview; verified against the live endpoint on 2026-08-22.
Deterministic, no model calls: $0.001 per call, inside the free anonymous quota. Failed calls are not charged.
No signup for the free anonymous quota. Documents are processed in memory and not retained. The config URL carries ?s=dsh-validate — a channel tag identifying the install path, not you.
Disclosure: built and run by the team behind ainetcafe.com — our own service, free tier plus paid usage. Full bundle (everything at once): dsh-netcafe. MIT.
| Signal | This plugin |
|---|---|
| Runtime | dsh v0.1 developer preview (Cordis v4). Touches only the MCP client config shape — the narrowest surface available. Verified against a live endpoint on 2026-08-22. |
| What runs locally | Nothing. Ships one cordis.patch.yml row; there is no tool code, no build step and no lifecycle script in this package. |
| Filesystem access | None. |
| Shell / process access | None. |
| Network access | Outbound HTTPS to ainetcafe.com only, from the MCP client that dsh already ships. |
| Credentials | None required for the free tier. An optional AllRouter key, if you supply one, is sent by dsh as a request header and is never stored by us. |
| Data retention | Documents and prompts are processed in memory and not retained. |
| Dependencies | One peer dependency: @deepseek-ai/dsh-mcp-client (ships with dsh). |
| License | MIT (see LICENSE). |
| Publisher | The team that runs ainetcafe.com. Issues get a same-day reply. |
A directory listing is not a security review. Read
cordis.patch.yml— it is short enough to read in full in under a minute.
FAQs
Offline identifier checks and Chinese money/tax arithmetic. Checksum-verified identifiers (mainland ID, USCC, bank card, plate, VIN, ISBN, IMEI, IBAN, EAN/UPC) plus amount-in-words, IIT, VAT, mortgage schedules and 调休-aware workday counts.
The npm package dsh-validate receives a total of 18 weekly downloads. As such, dsh-validate popularity was classified as not popular.
We found that dsh-validate demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.