omdsh-dev/dsh-tool-json
DSH JSON query tool plugin: JMESPath subset query, zero-dependency recursive descent parser
A JSON query tool plugin for DSH: a JMESPath-inspired path-query subset (dot access foo.bar, bracket index items[0], bracket property items['key'], wildcard projection items[*].name, free nesting) with a zero-dependency recursive-descent parser. Structured paths avoid grep-style false matches between keys and values. Security: Object.hasOwn guards prototype pollution; resource caps (query ≤ 200 chars, depth ≤ 20, input ≤ 1,000,000 bytes, nesting ≤ 100, wildcard projection ≤ 100,000 elements); typed JsonQueryError categories (MISSING_PROPERTY / TYPE_MISMATCH / INDEX_OUT_OF_BOUNDS / INVALID_QUERY). Dual-form input: object direct-pass or JSON string passthrough.
Install
dsh plugin --profile web add github:omdsh-dev/dsh-tool-jsonProfile Bundle (recommended, DSH 0.1.2-alpha.1): dsh plugin --profile web add github:omdsh-dev/dsh-tool-json (also headless: dsh plugin --profile headless add github:omdsh-dev/dsh-tool-json), or npm pack then dsh plugin --profile web add ./dsh-tool-json-*.tgz. The dsh.bundle.patch inside the package auto-adds the plugin layer. Startup: npx -p @deepseek-ai/dsh@next dsh web.
Compatibility
DSH 0.1.2-alpha.1 (profile bundle); web and headless profiles. Hand-written recursive-descent parser — no eval/new Function.
Details
- Repo: omdsh-dev/dsh-tool-json
- Category: uncategorized
- Stars: 3
- Version: GitHub source (profile-bundle install; no npm registry package)
- Last push: 2026-08-14
- First seen: 2026-08-05
Recent updates
json query tool (JMESPath subset); zero-dependency parser; prototype-pollution guard; typed error categories; dual-form input.
FAQ
- How is it different from grep?
- It walks structured paths instead of string-matching, so key/value collisions and nested same-name keys don't confuse results.
- What query syntax is supported?
- Dot access, bracket index, bracket property, wildcard projection on arrays, and free nesting — e.g. data.items[0].name.
- Is it safe on untrusted JSON?
- Yes — no eval/new Function, Object.hasOwn guards, input/depth/wildcard caps, and typed error categories.
Alternatives
omdsh-dev/dsh-tool-regex · omdsh-dev/dsh-tool-diff · omdsh-dev/dsh-tool-time