TYEclipse/dsh-netdoctor

A read-only network diagnostics toolbox for DSH with seven probes: dns_lookup (A/AAAA/CNAME/MX/TXT/NS/SOA/SRV/PTR/CAA records, optionally against a custom nameserver for propagation testing), ping_host (ICMP with packet loss and min/avg/max RTT), check_port (TCP connect probe reporting open/closed/filtered/unreachable with connect time), check_tls (real TLS handshake: protocol, cipher, cert subject/issuer, validity window, days to expiry, SANs, SHA-256 fingerprint), trace_route (per-hop RTTs), my_ip (public IP with optional geo/AS info) and whois (registry lookup over TCP port 43 with automatic IANA referral-chain discovery).

Other ★ 1 updated 2026-09-10 ✅ runtime-tested
View on GitHub ↗

Install

dsh plugin --profile web add github:TYEclipse/dsh-netdoctor

README install (a pinned release form is also documented: dsh plugin --profile web add github:TYEclipse/dsh-netdoctor#v0.1.0). The build output (dist/) is committed to the repository, so git-hosted installs work with a single command — no build step, no approval prompts. It can also be installed from the DSH web GUI plugin browser or any dsh plugin marketplace by searching dsh-netdoctor (topic dsh-plugin).

Compatibility

DSH web profile; zero runtime dependencies (Node.js built-ins only). ping / traceroute (or tracert) are invoked with fixed argument arrays, never through a shell, and every target is validated against a strict hostname/IP pattern. Every probe has a hard timeout. The my_ip geo lookup uses ip-api.com's free keyless endpoint and can be disabled per call (includeGeo: false) or in config. Certificates are inspected but never trusted.

Details

Recent updates

README documents the safety model explicitly: every tool is read-only, external binaries are never run through a shell, targets are pattern-validated, and geolocation can be turned off for privacy.

FAQ

How do I install dsh-netdoctor?
Run: dsh plugin --profile web add github:TYEclipse/dsh-netdoctor (or pin a release with #v0.1.0). dist/ is committed, so no build step or pnpm approval prompt is needed.
What can the agent check with it?
DNS records, ICMP reachability, TCP port state, TLS certificate validity and days to expiry, traceroute hops, the machine's public IP with optional geo info, and WHOIS registration data.
Is it safe to let the agent run these probes?
All seven tools are read-only; external binaries are spawned with fixed argument arrays (never through a shell), targets are validated against a strict hostname/IP pattern, and every probe has a hard timeout.

More plugins in Other

Browse more in Other

Guides for Other plugins