Introduction¶
The sandbox mechanism of DeepSeek Harness (DSH) mainly constrains file reads and writes, with limited control over network traffic. In the source code, web_fetch is described as an SSRF (Server-Side Request Forgery) primitive with private-network protections not yet implemented. The dsh-netguard plugin aims to fill this gap by providing network control capabilities that DSH itself cannot implement.
Installation and Configuration¶
Before installation, ensure that the Harness version is between 0.1.0-rc.6 and 0.1.1 (0.1.2-alpha.* versions are incompatible).
- Use the following commands to install the plugin:
dsh plugin --profile <name> add @deepseek-ai/dsh-headless@0.1.0-rc.6
dsh plugin --profile <name> add dsh-netguard
dsh --profile <name> --dump-config # 检查 dsh-netguard 行是否出现
- After installation, the component must be configured in
cordis.patch.yml. Becausectx.webhas no priority or last-wins rule,fetchProvidermust be explicitly set todsh-netguard.
# $DSH_HOME/profiles/<name>/cordis.patch.yml
- id: web
config:
fetchProvider: dsh-netguard
searchProvider: deepseek-official
- id: dsh-netguard
config:
mode: audit
allow: []
deny: []
spoolPath: /var/log/dsh/netguard.ocsf.jsonl
Core Features¶
The plugin provides three types of control capabilities:
- Connection-time host checking: Performs allowlist/denylist checks on target hosts for the
web_fetchandweb_searchtools. - Parameter pre-checking: Before
bash,pwsh, orrun_codecommands are executed, checks whether their parameters contain target hostnames. - Audit and logging: Uses audit mode by default, and records one OCSF Network Activity (4001) entry for each decision made.
Typical Usage¶
The default mode is audit, in which denied requests are logged but still allowed to pass. To actually block traffic, set mode: enforce.
The following configuration allows access to GitHub and a specific npm registry source, while denying access to internal domains:
- id: dsh-netguard
config:
mode: enforce
allow: ['**.github.com', 'registry.npmjs.org:443']
deny: ['*.internal.example']
spoolPath: /var/log/dsh/netguard.ocsf.l
shell:
enabled: true
readTextHosts: false
After installation is complete, use the CLI to view logs:
dsh-netguard report # 查看所有日志
dsh-netguard report --since 24h # 查看最近24小时的日志
dsh-netguard report --suggest # 根据已观察的主机生成允许列表建议
Applicable Scenarios and Cautions¶
Applicable scenarios:
* Prevent the model from initiating unauthorized network requests through web_fetch.
* Prevent the model from injecting malicious URLs in commands such as bash and pwsh.
Important limitations:
* Not a firewall: The plugin cannot see byte streams sent after a child process starts (for example, curl "$(cat url.txt)"), so it cannot detect URLs passed through variables.
* Not a boundary: The plugin runs in-process under the uid of the agent and cannot prevent potential data leakage through the model channel itself.
* Audit-first: mode: enforce must be explicitly configured to achieve a blocking effect; otherwise, it only serves a monitoring role.
Conclusion¶
dsh-netguard is a key component in the DeepSeek Harness plugin ecosystem for strengthening network control. By using host allowlists and command parameter checks, it fills the gap in DSH’s network-layer controls. When installing, be sure to review the source code and license, and adjust the audit mode and enforce mode according to actual requirements.