Preface

One of the core capabilities of DeepSeek Harness (DSH) is web_fetch, which allows agents to retrieve external information through web-connected tools. However, the default network request implementation may expose Server-Side Request Forgery (SSRF) risks and lacks strict restrictions on request content types.

dsh-safe-web-fetch is an SSRF-resistant WebFetchProvider plugin. It registers safe-http as the ctx.web service provider for DSH, providing a stricter network access control strategy without breaking DSH’s existing tool and Profile systems.

Core Features

This plugin enhances security through the following mechanisms:

  • DNS validation: Checks every DNS answer before opening a socket, including IPv4-mapped IPv6 and special-use address ranges.
  • Connection isolation: Makes connections through an isolated Undici dispatcher, ensuring address checks are bound to the actual request.
  • Redirect control: Re-checks same-origin redirects and rejects cross-origin redirects.
  • Rate and size limits: Limits response bytes, decoded characters, redirect count, concurrent request count, and total timeout.
  • Content filtering: Returns only text-based media types (text, HTML, JSON, XML).
  • Privacy protection: Does not add cookies, authorization headers, browser state, or request bodies.
  • URL rules: Accepts only HTTP/HTTPS URLs without embedded credentials.

Installation and Activation

Install the plugin and activate the corresponding Profile layer to enable it.

  1. Install using the Next version:
    dsh plugin --profile safe add dsh-safe-web-fetch@next
After installation, run `dsh --profile safe --dump-config` to verify that the configuration took effect.
  1. For production deployments, pin a tested version:
    dsh plugin --profile production add dsh-safe-web-fetch@0.1.0-next.0
  1. Alternatively, install a specific Git commit:
    dsh plugin --profile safe add github:MostlyHarmlessxyz/dsh-safe-web-fetch#<commit-sha>

Configuration

The plugin provides a set of configurable parameters with conservative defaults.

Setting Default Maximum
maxUrlLength 2048 16384
maxResponseBytes 5000000 100000000
maxBodyChars 100000 10000000
timeoutMs 30000 Node timer limit
maxRedirects 5 20
maxConcurrentRequests 16 128

Additionally, allowHosts (allow list), denyHosts (deny list), and userAgent can be configured. In DSH, configuration lines are replaced entirely, so all fields must be included when modifying the configuration.

- id: safe-web-fetch
  name: dsh-safe-web-fetch
  config:
    maxUrlLength: 4096
    maxResponseBytes: 10000000
    maxBodyChars: 200000
    timeoutMs: 30000
    maxRedirects: 3
    maxConcurrentRequests: 8
    allowHosts:
      - '*.docs.example.com'
    denyHosts: []
    userAgent: my-company-fetch/1.0

Use Cases and Considerations

This plugin is suitable for agent development scenarios that require restricted web operations in DSH environments.

Notes:

  • Content trust: Public addresses do not imply trusted content. The plugin is not responsible for handling prompt injection, malware, or HTML sanitization; these must still be handled at the application layer.
  • System-level limits: OS-level third-party resolvers cannot be fully blocked by this plugin. This is a known security boundary.
  • Functional boundary: This plugin does not add cookies, authorization headers, browser state, or request bodies.
  • Not a gateway policy: It is not a firewall, content scanner, approval screen, or proxy policy. For organizational zero-trust networks, appropriate controls must still be deployed at the network boundary.

Conclusion

dsh-safe-web-fetch provides basic SSRF protection for DeepSeek Harness through strict DNS validation, connection isolation, and content filtering. As part of the plugin ecosystem, it follows DSH’s “everything is a plugin” design philosophy, allowing developers to flexibly integrate it based on Profile requirements.