DeepSeek Harness 插件

dsh-top

System monitoring tool for the dsh web GUI: live CPU, RAM, disk, network, and top processes in a floating, collapsible panel.(英文原文)

跳到安装方式

来源信息

GitHub 仓库
glenngit/dsh-top
最近更新
2026年8月17日
分类
工具与能力
GitHub stars
0
载体类型
plugin
目录证据
上游声明已找到 dsh.bundle
证据路径
package.json#dsh.bundle
核对版本
0.1.0-rc.8
上游核对日期
2026-08-20

该证据由上游目录提供。本站没有安装、运行或安全审核这个插件。

安装

默认先复制一段 Prompt,让 Agent 读 GitHub 仓库和源码;需要自己装时再切到命令。

复制这段 Prompt,发给 DSH、Codex 或其他 Agent,让它先读 GitHub 仓库和源码。

请先不要安装或执行任何命令。阅读这个插件的 GitHub 仓库、README 和关键源码,然后用清楚、直接的方式回答以下问题,帮助我判断它是否适合我的需求:

1. 这个插件是什么,解决什么问题;
2. 适合哪些用户和典型使用场景;
3. 安装后如何使用,并给出一个最小使用示例;
4. 有哪些已知限制,以及隐私、安全、兼容性或维护风险;
5. 给出“推荐 / 有条件推荐 / 不推荐”的明确建议和理由。

请区分仓库明确说明、根据源码推断和未知信息。证据不足时请明确说明,不要猜测或照抄 README。

GitHub:https://github.com/glenngit/dsh-top
插件名:dsh-top
作者:glenngit

检查来源文件

安装前先看这个插件目录里的 README 和其他文件。

文件资源管理器3 个文件
README.md来源说明 · 只读预览

dsh-top

A plugin for the DeepSeek Harness (DSH) web GUI: a system monitoring tool that shows live system stats in a floating, collapsible panel pinned to the top-right corner.

<p align="center"> <img src="docs/screenshot.png" alt="dsh-top System Monitor panel" width="342" /> </p>

![dsh.so security](https://www.dsh.so/artifact/dsh-top/)

Features

  • CPU — live utilisation (computed from /proc/stat deltas) + core count
  • MEM — used / total with percentage bar
  • DISK — used / total with percentage bar
  • NETWORK — download / upload throughput (computed from /proc/net/dev byte deltas)
  • Top 6 processes — PID, name, CPU%, MEM%
  • Dark color-coded palette (cyan CPU, magenta RAM, yellow disk, blue/green network), monospace
  • Draggable via the title bar, collapsible via the / + button
  • Transient monitor processes (ps, awk, head, …) are filtered out of the top-processes list

How it works

PartFileWhat it does
Host halflib/index.jsRegisters GET /api/dsh-top-stats; reads CPU, memory, disk, network and top processes with read-only /proc + ps + df reads.
Browser halflib/client.jsdsh.client web bundle; registers the panel into the frame-wide shell.overlay slot; polls every 2 s.
Compositioncordis.patch.ymlThe dsh.bundle patch layer that inserts the loader entry.

Security

Because it is a system monitor, the host half reads host-wide process, CPU, memory and disk state. To do that it invokes the fixed read-only binaries cat, ps and df via execFileSync with a static argv array (never a shell string), so there is no shell-injection surface and no attacker-controlled input. No data leaves the host, no credentials are read, and every read is read-only.

> dsh.so's static scanner flags the node:child_process import as "critical". That is a heuristic signal on the mere presence of process access — not a vulnerability. Process access is intrinsic to a monitoring tool; review the (small) source yourself: the commands are hard-coded, read-only, and argument-confined.

Install

dsh plugin --profile web add dsh-top

Then restart the web app and refresh the page — the panel appears at the top-right.

License

[MIT](LICENSE)