Install
$ agentstack add mcp-dongsheng123132-dsh-cad-review ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
dsh-cad-review
[](https://github.com/dongsheng123132/dsh-cad-review/actions/workflows/check.yml) [](LICENSE) [](package.json) [](https://github.com/dongsheng123132/awesome-dsh-plugins#2origin-plugin-lab)
Evidence-first ASCII DXF inspection and deterministic CAD rule review for DeepSeek Harness.
This plugin does not infer engineering defects from screenshots. It reads CAD entities, hashes the source drawing, and emits issues tied to entity handle/index, layer, source line range and geometric location. Unsupported entities remain visible as an evidence gap.
Version 0.2.0 is host-neutral and stock-Cordis-loader safe: it imports no private ToolRuntime helper and exposes no default export, preserving the module-level inject = ['tools'] contract. TEXT/MTEXT bodies and malformed numeric tokens are represented only by SHA-256 plus length, so evidence output does not reproduce drawing prose.
This scope complements broader robotics suites such as dsh-robotic-harness: that project inventories robot assets and validates URDF/MJCF/SDF workflows, while this plugin remains a small deterministic ASCII-DXF entity/rule evidence layer.
Install
dsh plugin --profile add github:dongsheng123132/dsh-cad-review
Configure a workspace root and project-owned policy:
- id: dsh-cad-review
name: dsh-cad-review
config:
workspaceRoot: C:/absolute/project/path
maxBytes: 20971520
policy:
requiredLayers: ["WALL"]
forbiddenLayers: ["DEFPOINTS"]
forbiddenEntityTypes: ["3DSOLID"]
requireClosedPolylines: true
minTextHeight: 2.5
maxDrawingSpan: 1000
requiredInsUnits: 4
maxEntities: 100000
maxIssues: 500
Paths must be .dxf files relative to workspaceRoot. Traversal, symlink escape, binary DXF and oversized input are refused.
DSH tools
dsh_cad_inspect_dxf— source SHA-256, units, bounds, layers, entity counts and exact entity geometry/line evidence.dsh_cad_review_dxf— the same evidence plus a deterministic policy report. A per-callpolicyJsoncan override configured policy.
The extractor understands LINE, LWPOLYLINE, CIRCLE, ARC, TEXT, MTEXT, POINT and INSERT geometry. Other types are retained and reported as structurally unsupported rather than silently treated as reviewed.
MCP proof surface
The formal .mcp.json declaration exposes cad_dxf_inspect_inline and cad_dxf_review_inline. They accept an explicit bounded ASCII DXF string, share the same parser and rule core, and return redacted structured evidence entirely in memory. The MCP server cannot read files, access the network, execute drawing content, start subprocesses, or write artifacts.
Checks cover malformed numbers, zero-length lines, non-positive radii, polyline closure and declared vertex count, exact duplicate geometry, required/forbidden layers, forbidden entity types, text height, units, drawing span and entity limits. Severity overrides use stable rule IDs.
CLI
dsh-cad-review inspect drawing.dxf
dsh-cad-review review drawing.dxf --policy examples/strict-mm-policy.json
review exits 2 when error-severity issues exist.
Evidence boundary
- v0.1 reads ASCII DXF only. Binary DXF and DWG are refused, not guessed.
- A source SHA-256 identifies the exact reviewed bytes; it does not prove authorship.
- Rules are project-owned. This package does not claim a universal building, mechanical or electrical code.
- A passing report means the supplied deterministic policy found no error; it is not professional engineering approval.
- Unsupported entity types make extraction incomplete and remain explicit in the report.
Verify
npm test
npm run check
npm run smoke:plugin
npm run smoke:mcp
npm run smoke:cli
DSH_CHECKOUT=/path/to/deepseek-harness npm run smoke:dsh
MIT
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: dongsheng123132
- Source: dongsheng123132/dsh-cad-review
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.