TYEclipse/dsh-netdoctor
A read-only network diagnostics toolbox for DSH with seven probes: dns_lookup (A/AAAA/CNAME/MX/TXT/NS/SOA/SRV/PTR/CAA records, optionally against a custom nameserver for propagation testing), ping_host (ICMP with packet loss and min/avg/max RTT), check_port (TCP connect probe reporting open/closed/filtered/unreachable with connect time), check_tls (real TLS handshake: protocol, cipher, cert subject/issuer, validity window, days to expiry, SANs, SHA-256 fingerprint), trace_route (per-hop RTTs), my_ip (public IP with optional geo/AS info) and whois (registry lookup over TCP port 43 with automatic IANA referral-chain discovery).
Install
dsh plugin --profile web add github:TYEclipse/dsh-netdoctorREADME install (a pinned release form is also documented: dsh plugin --profile web add github:TYEclipse/dsh-netdoctor#v0.1.0). The build output (dist/) is committed to the repository, so git-hosted installs work with a single command — no build step, no approval prompts. It can also be installed from the DSH web GUI plugin browser or any dsh plugin marketplace by searching dsh-netdoctor (topic dsh-plugin).
Compatibility
DSH web profile; zero runtime dependencies (Node.js built-ins only). ping / traceroute (or tracert) are invoked with fixed argument arrays, never through a shell, and every target is validated against a strict hostname/IP pattern. Every probe has a hard timeout. The my_ip geo lookup uses ip-api.com's free keyless endpoint and can be disabled per call (includeGeo: false) or in config. Certificates are inspected but never trusted.
Details
- Repo: TYEclipse/dsh-netdoctor
- Category: Other
- Stars: 1
- Version: GitHub main (README-documented; pinned release tag v0.1.0 also documented; not published to npm — registry 404 verified 2026-09-11)
- Last push: 2026-09-10
- First seen: 2026-08-13
Recent updates
README documents the safety model explicitly: every tool is read-only, external binaries are never run through a shell, targets are pattern-validated, and geolocation can be turned off for privacy.
FAQ
- How do I install dsh-netdoctor?
- Run: dsh plugin --profile web add github:TYEclipse/dsh-netdoctor (or pin a release with #v0.1.0). dist/ is committed, so no build step or pnpm approval prompt is needed.
- What can the agent check with it?
- DNS records, ICMP reachability, TCP port state, TLS certificate validity and days to expiry, traceroute hops, the machine's public IP with optional geo info, and WHOIS registration data.
- Is it safe to let the agent run these probes?
- All seven tools are read-only; external binaries are spawned with fixed argument arrays (never through a shell), targets are validated against a strict hostname/IP pattern, and every probe has a hard timeout.