dsh-inbox-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| DSH_INBOX_URL | No | The URL of the dsh web instance. Defaults to http://127.0.0.1:3080 | http://127.0.0.1:3080 |
| DSH_INBOX_DENY | No | Additional deny patterns to append to the default dangerous command interception list (e.g., rm -rf, curl|sh). | |
| DSH_INBOX_HOUSE | Yes | The house identifier for the dsh inbox. This is used for routing and status queries. | |
| DSH_INBOX_TRUST | No | Trust ID matching the dsh web side. Optional; if set, the server validates incoming requests against it. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| dsh_inbox_deliverA | Deliver a message into a DeepSeek Harness (DSH) Web session via session.prompt. kind=auto (default): busy → steer, idle → queue. kind=steer forces mid-turn inject; kind=task always queues. Requires matching house_id + trust_id when DSH_INBOX_TRUST is set; pass from_id so DSH can see which agent sent this. Dangerous shell/exfil patterns are blocked. Requires local dsh web (default http://127.0.0.1:3080). |
| dsh_inbox_statusA | Poll DSH session status via session.list (running, title, updatedAt). Omit session_id to inspect the most recently updated non-blank session. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 2 tools
dsh_inbox_status reads/polls session state while dsh_inbox_deliver writes/sends a prompt; there is no overlap in their actions. An agent can easily choose the right tool based on whether it needs to observe or act.
Both tools share the clear dsh_inbox_ prefix and use snake_case, so they are instantly recognizable as part of one server. The minor deviation is that one name uses a noun (status) and the other uses a verb (deliver), rather than a uniform verb_noun pattern.
Two tools is at the low end of the acceptable range and feels thin for a general MCP surface. For the narrow status-and-deliver purpose the count is reasonable, but it is borderline rather than solidly well-scoped.
The core poll-and-deliver loop is covered: status tells whether the session is ready or busy, and deliver handles the different queueing modes. Mino gaps exist around inspecting queued messages or listing multiple sessions, but agents can generally work around these.