Introduction

The ctx.web crack in DeepSeek Harness (DSH) provides web connectivity for agents. When implementing web search, existing general-purpose solutions usually involve model calls, which are costly or rely on third-party services. dsh-web-search-searxng is a WebSearchProvider implementation based on SearXNG. It converts search requests into direct HTTP GET calls against the JSON API of a local SearXNG instance, achieving zero model-call cost while preserving privacy.

Feature Overview

This is an implementation plugin that registers the provider to ctx.web via inject: ['web'].

  • Self-hosting and privacy: queries are sent to a local SearXNG instance and do not pass through third-party search providers.
  • Zero model cost: a single search is just one HTTP request and does not consume LLM tokens.
  • Multi-engine aggregation: leverages the SearXNG backend to aggregate results from multiple search engines such as Bing, Brave, Baidu, Google, and DuckDuckGo.
  • Flexible authentication: supports resolving the API key via ctx.credentials or environment variables.
  • Session logs: request logs are recorded only in requests initiated from an Agent session (non-Agent calls produce no logs).

Installation and Activation

Installing this plugin requires DeepSeek Harness to have the web crack mounted (standard Profiles include it by default).

dsh plugin --profile web add /path/to/dsh-web-search-searxng

After installation, DSH will automatically apply cordis.patch.yml to register the provider and switch the search source. If manual configuration is needed, edit cordis.patch.yml.

Configuration

The plugin reads environment variables first; if environment variables are not set, it uses default values or configuration-file values.

Environment Variables

Set the following environment variables before starting the DSH process:

export SEARXNG_BASE_URL=http://localhost:8080   # 默认值
export SEARXNG_MAX_RESULTS=10                    # 默认值
export SEARXNG_LANGUAGE=en                       # 默认值 'all' (不传参)

Configuration File

Configure in cordis.patch.yml or Settings:

- id: web-search-searxng
  name: '@deepseek-ai/dsh-web-search-searxng'
  config:
    baseURL: http://localhost:8080
    maxResults: 10
    language: en
    # apiKeyEnv: SEARXNG_API_KEY  # 优先读取环境变量

Security note: the apiKey field carries role('secret') and will not appear in describe responses.

Docker Desktop Caveats

If SearXNG is running in Docker Desktop, requests from the host machine are taken over by the Docker gateway (e.g., 172.18.0.1). SearXNG’s rate limiter will treat this as an external IP and trigger the API_MAX = 4/hour limit.

To avoid this issue, configure trusted proxies and IP pass-through in SearXNG’s limiter.toml, and enable forwarding headers in the plugin:

  1. Add the following to SearXNG’s limiter.toml:
    trusted_proxies = ['127.0.0.0/8']
    pass_ip = ['127.0.0.1', '172.18.0.0/16']
  1. Ensure that X-Forwarded-For header forwarding is enabled in the plugin configuration (default behavior in the code).

Request Logs

Before a search request is sent, the plugin appends a logging-only event web/searxng-search-request to the current Agent session, including the resolved endpoint and query terms. When the plugin is invoked directly through code without an active Agent session, no logs are recorded.

Ecosystem Background

DeepSeek Harness follows the “everything is a plugin” philosophy. This plugin is maintained by community developer acdcgz and is licensed under the MIT license. Its directory entry is on SkillHub, and the source code is hosted on GitHub.