Introduction

The sandbox mechanism of DeepSeek Harness (DSH) mainly constrains file reads and writes, with limited control over network traffic. In the source code, web_fetch is described as an SSRF (Server-Side Request Forgery) primitive with private-network protections not yet implemented. The dsh-netguard plugin aims to fill this gap by providing network control capabilities that DSH itself cannot implement.

Installation and Configuration

Before installation, ensure that the Harness version is between 0.1.0-rc.6 and 0.1.1 (0.1.2-alpha.* versions are incompatible).

  1. Use the following commands to install the plugin:
    dsh plugin --profile <name> add @deepseek-ai/dsh-headless@0.1.0-rc.6
    dsh plugin --profile <name> add dsh-netguard
    dsh --profile <name> --dump-config      # 检查 dsh-netguard 行是否出现
  1. After installation, the component must be configured in cordis.patch.yml. Because ctx.web has no priority or last-wins rule, fetchProvider must be explicitly set to dsh-netguard.
    # $DSH_HOME/profiles/<name>/cordis.patch.yml
    - id: web
      config:
        fetchProvider: dsh-netguard
        searchProvider: deepseek-official

    - id: dsh-netguard
      config:
        mode: audit
        allow: []
        deny: []
        spoolPath: /var/log/dsh/netguard.ocsf.jsonl

Core Features

The plugin provides three types of control capabilities:

  1. Connection-time host checking: Performs allowlist/denylist checks on target hosts for the web_fetch and web_search tools.
  2. Parameter pre-checking: Before bash, pwsh, or run_code commands are executed, checks whether their parameters contain target hostnames.
  3. Audit and logging: Uses audit mode by default, and records one OCSF Network Activity (4001) entry for each decision made.

Typical Usage

The default mode is audit, in which denied requests are logged but still allowed to pass. To actually block traffic, set mode: enforce.

The following configuration allows access to GitHub and a specific npm registry source, while denying access to internal domains:

- id: dsh-netguard
  config:
    mode: enforce
    allow: ['**.github.com', 'registry.npmjs.org:443']
    deny: ['*.internal.example']
    spoolPath: /var/log/dsh/netguard.ocsf.l
    shell:
      enabled: true
      readTextHosts: false

After installation is complete, use the CLI to view logs:

dsh-netguard report                  # 查看所有日志
dsh-netguard report --since 24h      # 查看最近24小时的日志
dsh-netguard report --suggest        # 根据已观察的主机生成允许列表建议

Applicable Scenarios and Cautions

Applicable scenarios:
* Prevent the model from initiating unauthorized network requests through web_fetch.
* Prevent the model from injecting malicious URLs in commands such as bash and pwsh.

Important limitations:
* Not a firewall: The plugin cannot see byte streams sent after a child process starts (for example, curl "$(cat url.txt)"), so it cannot detect URLs passed through variables.
* Not a boundary: The plugin runs in-process under the uid of the agent and cannot prevent potential data leakage through the model channel itself.
* Audit-first: mode: enforce must be explicitly configured to achieve a blocking effect; otherwise, it only serves a monitoring role.

Conclusion

dsh-netguard is a key component in the DeepSeek Harness plugin ecosystem for strengthening network control. By using host allowlists and command parameter checks, it fills the gap in DSH’s network-layer controls. When installing, be sure to review the source code and license, and adjust the audit mode and enforce mode according to actual requirements.