sduwall/dsh-wall-mcp-manager ↗★ 0

@sduwall/dsh-wall-mcp-manager

DSH 插件:集中管理 MCP 服务配置,并展示每个 MCP 的工具清单、参数与返回契约 适合需统一管理多个 MCP 服务的用户,默认不挂载任何服务。

Package
@sduwall/dsh-wall-mcp-manager
Compatibility
Unverified
Harness peer range
^0.1.0-rc.6
Cordis peer range
^4.0.1
Version
0.1.0
License
MIT
Last updated
Aug 29, 2026

Install

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:sduwall/dsh-wall-mcp-manager

配置

配置命名空间为 dsh-wall-mcp-manager(settings 命名空间只允许小写 kebab-case, 不带 npm scope),形如:

dsh-wall-mcp-manager:
  servers:
    filesystem:
      enabled: true
      transport: stdio
      description: 本地文件访问
      command: npx
      args:
        - -y
        - '@modelcontextprotocol/server-filesystem'
        - D:/workspace
      env:
        LANG: zh_CN
      secretEnv:             # 凭据类环境变量;没有凭据就整段省略,不要写成 {}
        API_TOKEN: xxx
      cwd: ''
      toolCallTimeoutMs: 60000
      failOnStartupError: false
    weather:
      transport: streamable-http
      url: https://mcp.example.com/mcp
      headers:
        X-Trace: 'on'
      secretHeaders:         # 凭据类请求头
        Authorization: Bearer xxx
字段默认值说明
enabledtrue停用则不挂载该服务(保留配置)
transportstdiostdio(本地子进程)或 streamable-http(远程 HTTP)
description''备注,仅本界面展示,不传给 mcp-client
command''stdio 必填:启动命令
args[]stdio:命令参数,逐项填写(不会按空格拆分)
env{}stdio:环境变量(明文,可在界面查看)
secretEnv无stdio:凭据类环境变量,role('secret'),永不出网
cwd''stdio:工作目录,留空继承 DSH 进程
url''streamable-http 必填:服务地址
headers{}streamable-http:请求头(明文,可在界面查看)
secretHeaders无streamable-http:凭据类请求头,role('secret'),永不出网
toolCallTimeoutMs60000工具调用超时(毫秒,≥1000)
failOnStartupErrorfalse启动失败是否让该实例整体失败

secretEnv / secretHeaders 在挂载时被合并进 env / headers(同名以凭据为准)—— 对 mcp-client 而言它们和普通环境变量、普通请求头没有区别,拆成两个字段只是因为 明文项要能在界面查看编辑,而凭据项必须只写不读,两者需要不同的 role。

两个凭据字段没有默认值(显式 .default(undefined)):界面判断「已配置 / 未配置」 依据的是脱敏视图里的 set 标记,而它按「值是否为 undefined」判定;schemastery 会给 每个 dict 无条件补上 {} 默认值,若不压回 undefined,从没填过的凭据槽位也会显示 「已配置」。因此手写 yaml 时不要写 secretEnv: {},没有凭据就整段省略。

为什么不照抄 mcp-client 的 Schema

mcp-client 自身的 Config 是 z.union([stdio, streamable-http]),但 settings 的 redactSecrets 只穿透 object / dict / array 三种容器,遇到 union 会原样返回整棵子树 (其源码注释明确 "a secret buried inside a union branch is not reachable and must not be modeled that way")。若按 union 建模,凭据就会随 describe 原文出网。

因此这里用扁平 object + transport 判别字段,挂载时再由 toMcpConfig 按分支重新 组装出合法的实例配置——只输出该分支该有的字段,多带一个别分支字段会被 union 直接拒绝。

半成品不影响其他服务

「填了一半的服务」在配置界面里是常态。校验失败(缺 command、名称非法、 transport 不支持)只让该项被跳过并在界面标出原因,不会让整份配置或其他服务失效。 单个服务挂载失败(命令不存在、远端不可达)同样只记为该项的失败,绝不外溢成插件整体卸载。