When developing or debugging DeepSeek Harness (dsh) workflows, network connectivity, system proxy configuration conflicts, and local Hosts file interference are common blockers. When an agent cannot access GitHub or a specific API, manual intervention is often required to investigate proxy ports, DNS resolution, and Hosts records. dsh-netassist aims to provide agents with a set of read-only network diagnostic capabilities, directly answering specific questions such as “is it reachable,” “what is the proxy status,” and “is the port alive.”

This is a DSH plugin maintained by Edge-Echo and part of the dsh-toolkit family. It uses PowerShell in Windows environments to execute a series of read-only diagnostic scripts, providing a complete diagnostic chain from DNS resolution to TCP connection to HTTPS status codes, and supporting scans of local hosts file entries for GitHub records.

Core Features

  • GitHub connectivity check: Verifies DNS resolution and TCP port 443 reachability.
  • System proxy detection: Reads proxy settings from the Windows registry (ProxyEnable/ProxyServer/ProxyOverride) and environment variables.
  • Proxy port probing: Probes the liveness of common local proxy ports (10808, 10809, 7890, 7897, 8888, 1080).
  • Complete diagnostic chain: For any Host and Port, runs a full-chain diagnosis from DNS to TCP to HTTPS status code.
  • Hosts file conflict scan: Checks whether the hosts file contains GitHub-related domain records.

Installation and Enablement

Run the following commands in the terminal to install the plugin:

dsh plugin --profile web add dsh-netassist
dsh web   # 重启服务以加载插件

Typical Usage

After installation, the following capabilities can be invoked through natural language or tool names:

  • Check GitHub reachability: “check if github.com is reachable” -> triggers net_github_status
  • View system proxy: “what proxy is my system using?” -> triggers net_proxy_status
  • Check proxy ports: “is my proxy running?” -> triggers net_proxy_probe
  • Troubleshoot network issues: “why can’t I reach api.example.com:8443?” -> triggers net_diag host=api.example.com port=8443
  • Check hosts conflicts: “any github entries in my hosts?” -> triggers net_hosts_check

Notes

  • Platform limitation: Windows only. On non-Windows platforms, the tools will report an error (spawn powershell.exe ENOENT).
  • Safety mechanism: All diagnostics are read-only operations with no write permissions. User input is passed via Base64 to prevent command injection.
  • Performance: Each tool has a cold-start time of about 20 seconds. net_doctor (full-chain diagnostics) may take more than 60 seconds because multiple checks run in parallel. The default 60-second timeout of MCP clients may be insufficient, so call tools individually or adjust the timeout.
  • PowerShell policy: If execution fails, check the PowerShell execution policy. Although the plugin uses -NoProfile -NonInteractive, it normally does not rely on RemoteSigned.

The plugin provides a standardized diagnostic interface to help agents quickly locate network-layer issues, making it suitable for debugging DSH workflows.

GitHub: https://github.com/Edge-Echo/dsh-netassist
NPM: https://www.npmjs.com/package/dsh-netassist