Preface¶
When answering questions, DeepSeek Harness (DSH) agents often need to obtain full web pages rather than search snippets. Making direct HTTP requests from the local machine to target URLs introduces a Server-Side Request Forgery (SSRF) attack surface. The dsh-fetch-third-party plugin solves this with a “courier mode”: the local machine does not connect directly to the target URL; instead, it delegates fetch requests to a user-configured third-party service. All API keys are stored in the DSH-managed credential vault, and the plugin includes session-level budgeting and fetch caching.
Core Features¶
This plugin provides secure third-party web-fetching capabilities, including the following features:
- Secure proxied fetching: The local machine does not connect directly to arbitrary URLs, eliminating the SSRF attack surface.
- Multi-provider support: Supports Tavily, Jina Reader, Firecrawl, and custom services compliant with contract v1.
- Secure credential storage: API keys are written only to
~/.dsh/.credentials.yaml(permission 0600), and neither the plugin nor GUI cards display keys in plaintext. - Session-level budgeting: By default, fetching is limited to 10 requests per session; exceeding the limit is denied with a prompt.
- Fetch caching: Requests for the same URL within the validity period (default 600 seconds) use in-memory cache, without consuming third-party quota or budget.
- Self-hosted Crawl4AI stack management: When a local custom service is configured, the plugin can automatically manage the Crawl4AI container and wrapper process.
- Structured output:
web_fetch_urlreturns information such as title, outline, links, word count, and estimated reading time.
Installation and Enablement¶
Before installation, ensure that DeepSeek Harness (dsh) and pnpm are installed.
Run the following command to install the plugin:
dsh plugin --profile web add https://github.com/tallahandsome-ux/dsh-fetch-third-party.git
After installation, restart dsh web. In Settings → Plugins → Plugin Configuration, find the “Web Fetch (Third-party)” card to confirm successful installation.
Usage Instructions¶
Configuring a Third-party Provider¶
- Open the settings interface and find the “Web Fetch (Third-party)” card.
- In the “Provider” dropdown, select the target service (for example,
Jina Reader). - Click “Test Connection” to verify that the configuration is available.
- Enter the server endpoint in the “Endpoint address” field (the default is usually sufficient).
- Configure a proxy address in the “Local proxy” field (for example,
http://127.0.0.1:27822) to resolve network blocking issues.
Custom Services and Self-hosted Stacks¶
If you need to use a self-hosted fetching tool (such as Crawl4AI), configure a custom contract service:
- Select the “Custom” type on the card.
- Set a name (for example,
crawl4ai). - Choose
custom (contract v1)for the type. - Set the endpoint address to a local loopback address (for example,
http://127.0.0.1:8787). - After saving, the plugin will automatically start the corresponding local service stack.
Security Mechanisms¶
- Credential isolation: The plugin forbids reading keys in plaintext; all keys are stored only in the DSH-managed vault. The settings card shows only the “Configured / Not configured” state.
- Defense in depth: Before forwarding a request, the plugin rejects private-network or reserved-address targets, preventing SSRF attacks.
- Single egress path: The only outbound connection from the local machine is directed to the user-configured third-party endpoint.
Summary¶
This plugin enables secure web fetching by delegating requests to external services, making it suitable for scenarios that require safely retrieving full web information in the DSH environment. Developers can refer to the GitHub repository for source code and documentation, or view more information in the Skill Hub directory.