{"schemaVersion":2,"dataVersion":"20260822T105549Z-0a0b366f","generatedAt":"2026-08-22T10:55:49.138Z","source":{"id":"microherox-dsh-exa-mcp","slug":"microherox-dsh-exa-mcp","rank":723,"url":"https://github.com/MicroHEROX/dsh-exa-mcp","name":"MicroHEROX/dsh-exa-mcp","category":"browser","description":{"zh":"通过内置的 @deepseek-ai/dsh-mcp-client 桥接接入托管的 Exa 搜索 MCP 端点（mcp.exa.ai）：web_search_exa 与 web_fetch_exa 工具，免费额度匿名可用，设置 EXA_API_KEY 可解锁更高限额。","en":"Mounts the hosted Exa search MCP endpoint (https://mcp.exa.ai/mcp) through the in-box @deepseek-ai/dsh-mcp-client bridge: web_search_exa and web_fetch_exa tools, anonymous on the free tier or with your own EXA_API_KEY."},"stars":3,"starsCheckedAt":"2026-08-21","repository":{"owner":"MicroHEROX","repo":"dsh-exa-mcp","requestedRef":null,"subpath":""},"npm":"dsh-exa-mcp","downloads":227,"installMode":"npm","upstreamInstall":"dsh plugin --profile web add dsh-exa-mcp","tarball":null,"added":"2026-08-15","page":"https://awesome-dsh-plugin.com/p/MicroHEROX/dsh-exa-mcp/","screenshots":[],"discovery":{"provider":"awesome-dsh-plugin","channel":"plugins.json","indexUrl":"https://github.com/awesome-dsh-plugin/awesome-dsh-plugin","selection":"all curated entries"}},"report":{"sourceId":"microherox-dsh-exa-mcp","slug":"microherox-dsh-exa-mcp","policyVersion":"HT-DSH-0.2.2","scannedAt":"2026-08-22T08:27:58.225Z","scanStatus":"static-complete","verdict":"caution","score":95,"commit":"be2fe2afddc729ff9417f947d654838f513fb8ef","commitDate":"2026-08-21T17:54:16+08:00","artifactDigest":"sha256:508357b8815b2c02cb130d5029c35b945266702366eeb0697a43b5197c36ba0e","downloadUrl":"https://github.com/MicroHEROX/dsh-exa-mcp/archive/be2fe2afddc729ff9417f947d654838f513fb8ef.tar.gz","installMode":"npm","installCommand":"dsh plugin --profile web add dsh-exa-mcp","manifest":{"found":true,"path":"package.json","parseError":null,"packageName":"dsh-exa-mcp","packageVersion":"0.1.0","bundle":{"patch":"./cordis.patch.yml"},"client":null,"lifecycleScripts":{},"peerDependencies":[]},"identity":{"status":"found","installMode":"npm","upstreamNpm":"dsh-exa-mcp","manifestName":"dsh-exa-mcp","nameMatch":true,"npm":{"name":"dsh-exa-mcp","latestVersion":"0.1.0","publishedAt":"2026-08-15T05:06:33.321Z","createdAt":"2026-08-15T05:06:33.128Z","versionCount":1,"maintainers":1,"repository":"git+https://github.com/MicroHEROX/dsh-exa-mcp.git","hasInstallScripts":false,"deprecated":false},"repositoryMatch":"match","provenance":"none","tarballHost":null,"versionMatch":"match"},"permissions":{"bundlePatch":"cordis.patch.yml","inserts":[{"id":"mcp-exa","name":"@deepseek-ai/dsh-mcp-client","path":"cordis.patch.yml","disabled":false}],"overrides":[],"jsExpressions":1,"clientPlatform":null,"parseErrors":[]},"capabilities":["credentials","environment","host-bundle","mcp"],"outboundHosts":[{"host":"mcp.exa.ai","count":4}],"findings":[{"id":"HT-CONFIG-001","title":"Cordis 配置包含可执行 !!js 表达式","severity":"medium","confidence":"high","layer":"dsh-semantics","path":"cordis.patch.yml","pathClass":"cordis","line":42,"evidence":"!!js 'process.env.EXA_API_KEY ? { \"x-api-key\": process.env.EXA_API_KEY } : {}'","remediation":"!!js 是 DSH 的官方配置机制；只在表达式引入模块、访问进程或网络时需要额外解释。","note":"表达式访问模块、进程或网络，超出读取注入服务的常规用法","hash":"1ca2c09be37402bef246d2ee"}],"counts":{"critical":0,"high":0,"medium":1,"low":0},"rawCounts":{"critical":0,"high":0,"medium":1,"low":0},"vulnerabilities":[],"coverage":{"source":"complete","manifest":"complete","bundleConfig":"complete","dependencies":"lockfile-missing","vulnerabilities":"lockfile-missing","identity":"complete","artifact":"not-compared","llmReview":"not-needed","dynamicRuntime":"not-run","humanReview":"not-run"},"inventory":{"filesScanned":8,"bytesScanned":57880,"truncated":false,"lockfiles":[],"pathClasses":{"markdown":6,"cordis":1,"manifest":1}},"limitations":["此结果为源码静态检测，不等同于无漏洞证明。","尚未比对 npm 发布包与源码的一致性，也未执行隔离运行和人工复核。","危险能力可能是插件功能所需，需结合用途与证据人工判断。"],"limitationKeys":["static-analysis-only","no-artifact-runtime-human-review","capability-needs-context"]},"timeline":[{"scannedAt":"2026-08-22T08:27:58.225Z","commit":"be2fe2afddc729ff9417f947d654838f513fb8ef","policyVersion":"HT-DSH-0.2.2","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T11:29:48.431Z","commit":"be2fe2afddc729ff9417f947d654838f513fb8ef","policyVersion":"HT-DSH-0.2.1","verdict":"caution","status":"static-complete"},{"scannedAt":"2026-08-21T10:58:54.946Z","commit":"be2fe2afddc729ff9417f947d654838f513fb8ef","policyVersion":"HT-DSH-0.2.0","verdict":"caution","status":"static-complete"}],"events":[{"kind":"policy-change","from":"HT-DSH-0.2.1","to":"HT-DSH-0.2.2","commit":"be2fe2afddc729ff9417f947d654838f513fb8ef","policyVersion":"HT-DSH-0.2.2","at":"2026-08-22T08:27:58.225Z"},{"kind":"policy-change","from":"HT-DSH-0.2.0","to":"HT-DSH-0.2.1","commit":"be2fe2afddc729ff9417f947d654838f513fb8ef","policyVersion":"HT-DSH-0.2.1","at":"2026-08-21T11:29:48.431Z"},{"kind":"first-scan","from":null,"to":"caution","commit":"be2fe2afddc729ff9417f947d654838f513fb8ef","policyVersion":"HT-DSH-0.2.0","at":"2026-08-21T10:58:54.946Z"}]}