dsh-memory (FuRongJun-1999/dsh-memory) is an MCP server listed on the M8ven Trust Index. It scores 74 out of 100, grade C. It declares 37 tools. No publisher has claimed this listing.

C
Emerging
74/100

dsh-memory

白箱AGI架构探索:元认知(自我认知循环)、持续学习(知识飞轮)、世界模型(条件空间+语义时空图)、自我改进(自举纪律)、零LLM白箱管线与可审计信任护栏。

Emerging. No concerning findings. Grades remain capped until the project builds reputation through adoption. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

FuRongJun-1999

Source: github_repo_search

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Secret credentials may flow to a network call
3 flows detected: HIVE_WEB_SEARCH_KEY, HIVE_API_KEY, MDCG_LLM_KEY. We can’t prove the destination matches the brand the credential belongs to.
🔐
You'll be asked for 9 credentials: MDCG_TOKEN, ROLEPLAY_EDIT_KEY, HIVE_API_KEY, HIVE_WEB_SEARCH_KEY, DEEPSEEK_API_KEY, MDCG_LLM_KEY, GLM_API_KEY, BIGMODEL_API_KEY, AEIS_DESIGNER_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configMDCG_AUTO_ISSUE
configMDCG_LEGACY_ENV_AUTH
🔐 secretMDCG_TOKENDSH 采用 Cordis bundle 机制,新增或更新插件后必须重启 DSH 进程(或刷新 Web UI 页面)才会重新加载;通过 setx 配置 后同理,须重启才可见(见[写入凭据](#-写入凭据让记忆真正落盘))。
configPYTHONPATH复制插件内 mcp.json.example 为项目根 .mcp.json,填 PYTHONPATH
🔐 secretROLEPLAY_EDIT_KEY
configMDCG_MCP_SURFACE
configMDCG_SUSTAIN_NAME
configMDCG_SUSTAIN
configMDCG_SUSTAIN_BEAT
configMDCG_SUSTAIN_HEAL
configMDCG_SUSTAIN_AUTOHEAL
configMDCG_SCRUB_INTERVAL
configMDCG_AUTO_SCRUB
configMDCG_EVOLVE_INTERVAL
configMDCG_AUTO_EVOLVE
configMDCG_TIDY_INTERVAL
configMDCG_AUTO_TIDY
configMDCG_DSH_SESSIONS_ROOT
configMDCG_SESSION
configDSH_SESSION_ID
configMDCG_HARNESS
configMDCG_UNIT
configMDCG_TENANT
configMDCG_CAN_ADMIN
configMDCG_CAN_WRITE
configMDCG_ACTOR
configMDCG_CLEARANCE
configMDCG_ROOT
configHIVE_CONFIG
configHIVE_JOBS_DIR
configHIVE_EXE
🔐 secretHIVE_API_KEY
configHIVE_API_BASE
configHIVE_WORKERS
configMDCG_HOME
configHIVE_WEB_SEARCH
configHIVE_WEB_SEARCH_BASE
🔐 secretHIVE_WEB_SEARCH_KEY
configHIVE_LLM_EXEC_PY
configHIVE_WM_DIR
configMDCG_POLICY_FILE
configMDCG_CODE_TEST_CMD
configMDCG_CODE_TEST_TIMEOUT
configBENCH6_EMBED_BASE
configBENCH6_EMBED_MODEL
configBENCH6_EN_QUESTIONS
configBENCH6_COMPET
configMDCG_EN_ATOMS
configMDCG_SEMANTIC
configZH_PROBE_MODEL
🔐 secretDEEPSEEK_API_KEY
🔐 secretMDCG_LLM_KEY
configMDCG_LLM_MODEL
configMDCG_LLM_BASE
configMDCG_CN_GRAMS
configMDCG_SCORE_MODE
configMDCG_REDTEAM_REQUIRED
configMDCG_SUSTAIN_DIR
configMDCG_WHITEBOX_CMD
configMDCG_WHITEBOX_ARGS
configMDCG_WHITEBOX_TIMEOUT
configMDCG_WRITELIMIT
configGAP_DEBUG
configLINGSHU_PYTHON
configDEEPSEEK_PROVIDER_HINT
🔐 secretGLM_API_KEY
🔐 secretBIGMODEL_API_KEY
configWHITEBOX_DB
configMDCG_WHITEBOX_DB
🔐 secretAEIS_DESIGNER_KEY
configAEIS_WORKSPACE
configLINGSHU_KB
configLINGSHU_DB
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

37/37 tools missing one or more hints — mdcg_remember (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); mdcg_recall (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); mdcg_search (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +34 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Shell command execution

1 call in production code run through a shell (src/lib/mutual.ts:97)

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Domain consistency

npm scope @furongjun1999 doesn't match GitHub owner furongjun-1999

Use the same org name across GitHub, npm, and your homepage so users can verify the publisher.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/furongjun-1999/dsh-memory)](https://m8ven.ai/mcp/furongjun-1999/dsh-memory)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: 8fffc24b61c7a5bf9aa6500e851aeff9a77aec58
code hash: 8dcd668001331a8c7e0cb1ba819db88922f8b08ce25e2ab19614629ed7f52e51
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client