Plugin Data APIs
Machine-readable plugin data, split by concern — security certification, install certification, registry index and the trending boards. All static, cached and free to reuse with attribution. Built for AI agents and tooling.
# Fetch a plugin's security certification result curl https://www.dsh.so/artifact/@dsh-so/dsh-code-security.json # Install certification status (@author/plugin addressing) curl https://www.dsh.so/data/install/@dsh-so/dsh-plugin-finder.json # Full registry index curl https://www.dsh.so/plugins-index.json # Weekly npm download ranking curl https://www.dsh.so/data/npm-downloads.json # Star leaderboard (plugin / eco plugin / eco app boards) curl https://www.dsh.so/data/stars.json

01 APIs at a glance
Security Certification Data APIPer plugin
Static security review record for a single plugin: verdict badge, finding counts by severity, findings, and the scanned commit / release binding.
/artifact/@author/plugin.jsonDaily 01:10 BeijingAPI 02Install Certification Data APIPer plugin
Single-plugin install-verification query (L5 smoke preferred, L4 fallback): passed / failed / unknown / stale / untested with a verified flag and environment metadata.
/data/install/@author/plugin.jsonPer verification runAPI 03Plugin Index Data APIRegistry-wide
Lightweight registry summary: every collected plugin with verification level, security status, risk level and counts — no per-finding detail.
/plugins-index.jsonRebuilt on every deployAPI 04Plugin Record Data APIPer plugin
Canonical per-plugin fact sheet: verification per dsh version (L5-first), security summary, install, health and evidence pointers — one record for agent decision-making.
/plugin/@author/plugin.jsonRebuilt on every deployAPI 05Star Leaderboard Data APIRegistry-wide
GitHub star leaderboard split by the three artifact classes — dsh plugins / eco plugins / eco apps — top 100 by stars each. The upstream harness itself is absent; the ecoPlugin board admits install-verified entries only.
/data/stars.jsonRebuilt on deployAPI 06npm Downloads Data APIRegistry-wide
Weekly npm download ranking of DSH plugins (npm last-week window): the top-100 ranking behind the homepage board — rank, package, week downloads, cumulative total, stars.
/data/npm-downloads.jsonDaily snapshotAPI 07Star Trend Board Data APIRegistry-wide
GitHub star riser ranking over a 1-week window: the top-100 plugins by star gain, with baseline and current star counts.
/data/star-trend.jsonDaily snapshotAPI 08npm Popular Downloads Data APIRegistry-wide
All-time npm downloads popularity ranking: the top-100 plugins by cumulative downloads, with weekly downloads as context.
/data/npm-popular.jsonDaily snapshot02 Endpoint explorer
{
"id": "dsh-code-security-3",
"badge": { "state": "passed", "level": "passed", "detailUrl": "https://www.dsh.so/artifact/dsh-code-security-3/" },
"commitSha": "ec266465d104202e8fc07f7d8faeeb15760aef07",
"latestCommitSha": "ec266465d104202e8fc07f7d8faeeb15760aef07",
"pkgVersion": "0.2.2",
"pkgDsh": true,
"latestReleaseTag": null,
"counts": { "critical": 0, "warning": 0, "info": 0 },
"criticalByCategory": {},
"filesScanned": 15,
"scannedAt": "2026-09-21T20:04:36.213Z",
"scannerVersion": "dsh-static:73b7d4a8",
"rulesChecked": 31,
"findings": [],
"plugin": { "name": "dsh-code-security", "repository": "https://github.com/dsh-so/dsh-code-security" },
"license": { "spdx": "CC-BY-4.0", "attribution": "dsh.so" }
}{
"title": "SecurityScanRecord",
"type": "object",
"required": ["id", "badge", "counts", "scannedAt"],
"properties": {
"badge": { "badge.state": "passed | warn | fail | ..." },
"counts": { "critical": 0, "warning": 0, "info": 0 },
"findings": { "maxItems": 12, "items": "ruleId / severity / file / line" },
"commitSha": "scanned revision binding",
"scannedAt": "date-time"
}
}03 Agent integrations
MCP server · @dsh-so/mcp
Structured tools for Claude Code / ZCode / Cursor: registry search, plugin records, security scans, install status and the boards. Zero-install via npx, no API key — the server just reads these static endpoints.
{
"mcpServers": {
"dsh-so": {
"command": "npx",
"args": [
"-y",
"@dsh-so/mcp"
]
}
}
}Agent skill · dsh-plugin-data
A SKILL.md that teaches any agent when and how to query the data — verify the security verdict and install-verified status before recommending a plugin. Works without MCP: it points the agent straight at these static endpoints.
# install into the cross-agent skills directory (~/.agents/skills) mkdir -p ~/.agents/skills/dsh-plugin-data curl https://www.dsh.so/skills/dsh-plugin-data/SKILL.md \ -o ~/.agents/skills/dsh-plugin-data/SKILL.md
04 All endpoints
| URL | API | Description |
|---|---|---|
/data/security-scan.schema.json | Security | JSON Schema for the per-plugin scan-record format |
/artifact/@author/plugin.json | Security | Per-plugin JSON — scan badge + counts + findings + version binding |
/data/install/@author/plugin.json | Install | Single-plugin install-verification result (L5-preferring, L4 fallback) |
/plugins-index.json | Index | Registry summary — every plugin's status / risk level / counts |
/plugin/@author/plugin.json | Record | Canonical per-plugin fact sheet — verification, security, health, evidence |
/data/plugin-record.schema.json | Record | JSON Schema for the plugin record endpoint |
/data/install.schema.json | Install | JSON Schema for the install endpoint |
/data/stars.json | Star Leaderboard | GitHub star leaderboard — plugin / eco plugin / eco app boards, top 100 each |
/data/stars.schema.json | Star Leaderboard | JSON Schema for the star leaderboard feed |
/data/npm-downloads.json | npm Downloads | Top-100 weekly npm download ranking — the homepage board as a feed |
/data/npm-downloads.schema.json | npm Downloads | JSON Schema for the npm downloads feed |
/data/star-trend.json | Star Trend Board | Top-100 GitHub star gainers over a 1-week window |
/data/star-trend.schema.json | Star Trend Board | JSON Schema for the star trend feed |
/data/npm-popular.json | npm Downloads | Top-100 all-time npm downloads popularity ranking |
/data/npm-popular.schema.json | npm Downloads | JSON Schema for the npm popularity feed |
JSON endpoints allow cross-origin reads: Access-Control-Allow-Origin: *. No API key or registration is required.
05 Conventions
/artifact/@author/plugin.json (likewise /data/install/@author/plugin.json and /plugin/@author/plugin.json) — the @ author part is the plugin author's npm scope or GitHub username; the id inside every JSON stays the canonical slug. Bare-slug .json addresses are no longer issued.Cache-Control: public, max-age=3600 and cross-origin headers.utm_source marker, please keep it so we can track reuse traffic; each API page documents its update cadence.generatedAt / asOf / checkedAt).Security scan data and install-test states are aggregated from public GitHub repositories and append-only verification records by the dsh.so pipelines. Sample responses above are excerpts; field shapes follow the live endpoints. Check changelog for additions.