What it does
System monitoring tool for the dsh web GUI: live CPU, RAM, disk, network, and top processes in a floating, collapsible panel.
Installation
dsh plugin --profile web add dsh-topInstall method: npm · not yet tested in container (L3+)
Compatibility
| DSH Version | Status |
|---|---|
| not stated | Declared — not tested |
Requirements
- • Node.js: not stated
- • DSH: declared "not stated"
- • External credentials: none detected
Security Report
Automated static scan, not manual review.
Critical findings in non-blocking categories (dynamic code execution, shell execution, install scripts, obfuscation). Common in CLI/terminal plugins but worth reviewing.
code-exec ×1c6cec465af322026-08-17—The scan result is only valid for the scanned commit. If the latest commit differs, the badge shows outdated until the daily pipeline rescans.
Disclaimer: automated static analysis, not a security guarantee. Always review what you install.
• Static heuristic scan: done (4 files)
• Dependency vulnerabilities: requires deep audit (L3+)
• Permission sandboxing: requires runtime testing (L4+)
Scan findings · 5
- infoMakes network requests (fetch / axios)lib/client.js:191fetch(STATS_PATH, { cache: "no-store" })
- criticalChild process module usage (Node.js)lib/index.js:11import { execFileSync } from "node:child_process";
- warningShell command execution (exec / execSync)lib/index.js:38return execFileSync("cat", [path], { encoding: "utf8", maxBuffer: 1 << 20 });
- warningShell command execution (exec / execSync)lib/index.js:58const df = execFileSync("df", ["-P", "/"], { encoding: "utf8", maxBuffer: 1 << 20 })
- warningShell command execution (exec / execSync)lib/index.js:77const psOut = execFileSync("ps", ["-eo", "pid,pcpu,pmem,rss,comm", "--sort=-pcpu", "--no-headers"],
Heuristic static scan — may produce false positives. Review the source yourself before trusting.
Activity
Last commit 2026-08-17 · activity: Active
• Repo created: 2026-08-17
• Stars: ★ 0 · Forks: 0
• Health: Active — committed within last 30 days
Source
GitHub: github.com/glenngit/dsh-top
