Plugin Data APIs

Machine-readable plugin data, split by concern — security certification, install certification, registry index and the trending boards. All static, cached and free to reuse with attribution. Built for AI agents and tooling.

8 APIs15 EndpointsCC BY 4.0No API KeyCORS enabled1h CDN cacheMCP + Skill
Quick start
# Fetch a plugin's security certification result
curl https://www.dsh.so/artifact/@dsh-so/dsh-code-security.json

# Install certification status (@author/plugin addressing)
curl https://www.dsh.so/data/install/@dsh-so/dsh-plugin-finder.json

# Full registry index
curl https://www.dsh.so/plugins-index.json

# Weekly npm download ranking
curl https://www.dsh.so/data/npm-downloads.json

# Star leaderboard (plugin / eco plugin / eco app boards)
curl https://www.dsh.so/data/stars.json
WeChat QR: data API discussions and update notices
Data APIs · WeChatScan to connect — Q&A and update noticesPlease note "dsh.so" in your request

01 APIs at a glance

API 01

Security Certification Data APIPer plugin

Static security review record for a single plugin: verdict badge, finding counts by severity, findings, and the scanned commit / release binding.

/artifact/@author/plugin.jsonDaily 01:10 Beijing
API 02

Install Certification Data APIPer plugin

Single-plugin install-verification query (L5 smoke preferred, L4 fallback): passed / failed / unknown / stale / untested with a verified flag and environment metadata.

/data/install/@author/plugin.jsonPer verification run
API 03

Plugin Index Data APIRegistry-wide

Lightweight registry summary: every collected plugin with verification level, security status, risk level and counts — no per-finding detail.

/plugins-index.jsonRebuilt on every deploy
API 04

Plugin Record Data APIPer plugin

Canonical per-plugin fact sheet: verification per dsh version (L5-first), security summary, install, health and evidence pointers — one record for agent decision-making.

/plugin/@author/plugin.jsonRebuilt on every deploy
API 05

Star Leaderboard Data APIRegistry-wide

GitHub star leaderboard split by the three artifact classes — dsh plugins / eco plugins / eco apps — top 100 by stars each. The upstream harness itself is absent; the ecoPlugin board admits install-verified entries only.

/data/stars.jsonRebuilt on deploy
API 06

npm Downloads Data APIRegistry-wide

Weekly npm download ranking of DSH plugins (npm last-week window): the top-100 ranking behind the homepage board — rank, package, week downloads, cumulative total, stars.

/data/npm-downloads.jsonDaily snapshot
API 07

Star Trend Board Data APIRegistry-wide

GitHub star riser ranking over a 1-week window: the top-100 plugins by star gain, with baseline and current star counts.

/data/star-trend.jsonDaily snapshot
API 08

npm Popular Downloads Data APIRegistry-wide

All-time npm downloads popularity ranking: the top-100 plugins by cumulative downloads, with weekly downloads as context.

/data/npm-popular.jsonDaily snapshot

02 Endpoint explorer

{
  "id": "dsh-code-security-3",
  "badge": { "state": "passed", "level": "passed", "detailUrl": "https://www.dsh.so/artifact/dsh-code-security-3/" },
  "commitSha": "ec266465d104202e8fc07f7d8faeeb15760aef07",
  "latestCommitSha": "ec266465d104202e8fc07f7d8faeeb15760aef07",
  "pkgVersion": "0.2.2",
  "pkgDsh": true,
  "latestReleaseTag": null,
  "counts": { "critical": 0, "warning": 0, "info": 0 },
  "criticalByCategory": {},
  "filesScanned": 15,
  "scannedAt": "2026-09-21T20:04:36.213Z",
  "scannerVersion": "dsh-static:73b7d4a8",
  "rulesChecked": 31,
  "findings": [],
  "plugin": { "name": "dsh-code-security", "repository": "https://github.com/dsh-so/dsh-code-security" },
  "license": { "spdx": "CC-BY-4.0", "attribution": "dsh.so" }
}

03 Agent integrations

MCP

MCP server · @dsh-so/mcp

Structured tools for Claude Code / ZCode / Cursor: registry search, plugin records, security scans, install status and the boards. Zero-install via npx, no API key — the server just reads these static endpoints.

search_pluginsget_plugin_recordget_security_scanget_install_statusget_npm_downloadsget_star_trenddata_freshness
mcp config
{
  "mcpServers": {
    "dsh-so": {
      "command": "npx",
      "args": [
        "-y",
        "@dsh-so/mcp"
      ]
    }
  }
}
SKILL

Agent skill · dsh-plugin-data

A SKILL.md that teaches any agent when and how to query the data — verify the security verdict and install-verified status before recommending a plugin. Works without MCP: it points the agent straight at these static endpoints.

endpoint tablefield semanticsdecision rulesCC BY 4.0
install skill
# install into the cross-agent skills directory (~/.agents/skills)
mkdir -p ~/.agents/skills/dsh-plugin-data
curl https://www.dsh.so/skills/dsh-plugin-data/SKILL.md \
  -o ~/.agents/skills/dsh-plugin-data/SKILL.md

04 All endpoints

URLAPIDescription
/data/security-scan.schema.jsonSecurityJSON Schema for the per-plugin scan-record format
/artifact/@author/plugin.jsonSecurityPer-plugin JSON — scan badge + counts + findings + version binding
/data/install/@author/plugin.jsonInstallSingle-plugin install-verification result (L5-preferring, L4 fallback)
/plugins-index.jsonIndexRegistry summary — every plugin's status / risk level / counts
/plugin/@author/plugin.jsonRecordCanonical per-plugin fact sheet — verification, security, health, evidence
/data/plugin-record.schema.jsonRecordJSON Schema for the plugin record endpoint
/data/install.schema.jsonInstallJSON Schema for the install endpoint
/data/stars.jsonStar LeaderboardGitHub star leaderboard — plugin / eco plugin / eco app boards, top 100 each
/data/stars.schema.jsonStar LeaderboardJSON Schema for the star leaderboard feed
/data/npm-downloads.jsonnpm DownloadsTop-100 weekly npm download ranking — the homepage board as a feed
/data/npm-downloads.schema.jsonnpm DownloadsJSON Schema for the npm downloads feed
/data/star-trend.jsonStar Trend BoardTop-100 GitHub star gainers over a 1-week window
/data/star-trend.schema.jsonStar Trend BoardJSON Schema for the star trend feed
/data/npm-popular.jsonnpm DownloadsTop-100 all-time npm downloads popularity ranking
/data/npm-popular.schema.jsonnpm DownloadsJSON Schema for the npm popularity feed

JSON endpoints allow cross-origin reads: Access-Control-Allow-Origin: *. No API key or registration is required.

05 Conventions

One way to address. Single-plugin endpoints are addressed only as /artifact/@author/plugin.json (likewise /data/install/@author/plugin.json and /plugin/@author/plugin.json) — the @ author part is the plugin author's npm scope or GitHub username; the id inside every JSON stays the canonical slug. Bare-slug .json addresses are no longer issued.
Static & cached. Prerendered JSON with Cache-Control: public, max-age=3600 and cross-origin headers.
Append-only fields. Existing fields are never removed or renamed; new fields ship with a schema update.
Provenance-bearing. Records quote their source verbatim — no invented defaults (honesty principle).
Attribution. Free to reuse with attribution to dsh.so — the link embeds a utm_source marker, please keep it so we can track reuse traffic; each API page documents its update cadence.
License. All feeds are CC BY 4.0 — redistribution must preserve freshness markers (generatedAt / asOf / checkedAt).
Disputes. Plugin authors can contest a scan result — see Dispute a scan result.

Security scan data and install-test states are aggregated from public GitHub repositories and append-only verification records by the dsh.so pipelines. Sample responses above are excerpts; field shapes follow the live endpoints. Check changelog for additions.

Was this page helpful?