MostlyHarmlessxyz/dsh-safe-web-fetch

SSRF-resistant public-only HTTP(S) WebFetchProvider plugin for DeepSeek Harness

dsh-safe-web-fetch gives DeepSeek Harness a safer web_fetch by plugging into the existing ctx.web service rather than adding a second search API. The core idea: a hostname must resolve to a public address before any connection opens, and every request hop is pinned to the addresses that were checked. It accepts only HTTP/HTTPS URLs without embedded credentials, applies optional exact host allow/deny lists (*.example.com for subdomains), checks every DNS answer (IPv4-mapped IPv6 and special-purpose ranges included) before opening a socket, connects through an isolated Undici dispatcher pinned to the checked address, rechecks same-origin redirects and rejects cross-origin ones, limits response bytes / decoded chars / redirects / concurrency / total time, and returns only text-like media types (text, HTML, JSON, XML) in DSH's usual result shape. Defaults are deliberately modest (maxResponseBytes 5 MB, maxBodyChars 100k, timeoutMs 30 s, maxRedirects 5, maxConcurrentRequests 16) and all tunable. It deliberately adds no cookies, auth headers, browser state or bodies, and is not an egress firewall or content scanner — those stay at the network boundary.

Other ★ 0 updated 2026-08-14 ✅ runtime-tested
View on GitHub ↗

Install

dsh plugin --profile safe add dsh-safe-web-fetch@next

npm dsh-safe-web-fetch dist-tag next → 0.1.0-next.0 verified 2026-09-03 (repository field → github.com/MostlyHarmlessxyz/dsh-safe-web-fetch; README EN primary). Documented installs: dsh plugin --profile safe add dsh-safe-web-fetch@next for the pre-release line, dsh plugin --profile production add dsh-safe-web-fetch@0.1.0-next.0 to pin, or a git install dsh plugin --profile safe add github:MostlyHarmlessxyz/dsh-safe-web-fetch#<commit-sha> (git builds run prepare; an npm package/tarball is the simpler option for prebuilt files). The published peer range covers DSH 0.1.0-rc.5 through the 0.1.x line and Cordis 4.x.

Compatibility

DSH 0.1.0-rc.5 – 0.1.x, Cordis 4.x; plugs into DSH's existing ctx.web service (fetchProvider: safe-http).

Details

Recent updates

DNS-pinned public-only fetching; exact host allow/deny lists; IPv4-mapped-IPv6 + special-range checks; same-origin redirects only; byte/char/redirect/concurrency/time limits; text-only media types.

FAQ

How does it stop SSRF-style fetches?
Every DNS answer must resolve to a public address before a socket opens, the connection is pinned to the checked address via an isolated dispatcher, and redirects are rechecked and restricted to the same origin.
Is this a full egress firewall?
No — it is an additional per-fetch check. The README recommends keeping organizational zero-trust controls at the network boundary.
Which content types are returned?
Text-like media types only (text, HTML, JSON and XML), capped by configurable response-size and body-character limits.

Alternatives

Biogod2020/dsh-bing-search · bocha-ai/dsh-web-search-bocha · LTctfer/dsh-web-search-brave

More plugins in Other

Browse more in Other

Guides for Other plugins