Introduction

By default, DeepSeek Harness (DSH) points web_search to cloud search and does not mount a web_fetch provider. If you run a self-hosted SearXNG instance for privacy or offline scenarios, the existing tool chain still sends queries to third-party providers. The dsh-searxng-web plugin intervenes, takes over the native tools, and routes requests to your SearXNG instance.

What It Is

dsh-searxng-web is a DeepSeek Harness plugin developed by maintainer maxwell-feng. It replaces the DSH native web_search and web_fetch tool backends with a self-hosted SearXNG instance, enabling search and fetching without third-party providers or API keys.

Core Features

  • Native Tool Support: Takes over the web_search and web_fetch tools, so models do not need to change tool call names.
  • SSRF Protection: web_fetch is protected against SSRF, restricting fetch targets.
  • Three-Stack Endpoint Support and Failover: Supports configuring multiple endpoints (such as IPv4, IPv6, and intranet) with automatic failover.
  • Private and Key-Free: Connects directly to a self-hosted instance without third-party services.

Installation and Activation

Before installing, the following requirements must be met:
1. Node.js version >= 22
2. DeepSeek Harness (dsh) is installed, with version 0.1.5-rc.2 verified
3. An accessible SearXNG instance has been deployed, and JSON output is enabled in the configuration (settings.yml → search.formats: [html, ])

Install the plugin:

dsh plugin --profile web add dsh-searxng-web

Restarting DSH after installation activates the plugin.

Typical Usage

After the plugin takes over, models can invoke your SearXNG using the native tool names:
- web_search → ctx.web → searxng-web → your SearXNG → configured search engines
- web_fetch → ctx.web → searxng-web-fetch → target page (protected against SSRF, HTML converted to Text)

Verify the configuration:

dsh --profile web --dump-config | grep -A5 searxng

In the GUI, Settings → Web Search displays the provider readiness status.

Configuration

The default Base URL is http://127.0.0.1:8080. Override the configuration in DSH’s cordis.patch.yml:

- id: searxng-web
  config:
    baseUrl: 'http://10.42.1.159:8080'
    timeoutMs: 15000
    fetchTimeoutMs: 30000
    fetchMaxChars: 200000
    ssrfGuard: true
    search:
      language: ''       # e.g. 'zh-CN', 'en'
      safesearch: 0      # 0 off, 1 moderate, 2 strict

Use Cases and Notes

  • Use Cases: Developers who need full control over search results, value privacy, deploy in offline or intranet environments, or prefer not to use third-party search providers.
  • Note: The plugin runs with the current DSH process permissions. Ensure DSH has permission to access the SearXNG instance. It is recommended to review the source code and license before installation.

Conclusion

This plugin makes self-hosted search solutions practical by seamlessly integrating with DSH’s native tool chain. For more details and source code, see the plugin directory or the GitHub repository.