Preface¶
One of the core capabilities of DeepSeek Harness (DSH) is web_fetch, which allows agents to retrieve external information through web-connected tools. However, the default network request implementation may expose Server-Side Request Forgery (SSRF) risks and lacks strict restrictions on request content types.
dsh-safe-web-fetch is an SSRF-resistant WebFetchProvider plugin. It registers safe-http as the ctx.web service provider for DSH, providing a stricter network access control strategy without breaking DSH’s existing tool and Profile systems.
Core Features¶
This plugin enhances security through the following mechanisms:
- DNS validation: Checks every DNS answer before opening a socket, including IPv4-mapped IPv6 and special-use address ranges.
- Connection isolation: Makes connections through an isolated Undici dispatcher, ensuring address checks are bound to the actual request.
- Redirect control: Re-checks same-origin redirects and rejects cross-origin redirects.
- Rate and size limits: Limits response bytes, decoded characters, redirect count, concurrent request count, and total timeout.
- Content filtering: Returns only text-based media types (text, HTML, JSON, XML).
- Privacy protection: Does not add cookies, authorization headers, browser state, or request bodies.
- URL rules: Accepts only HTTP/HTTPS URLs without embedded credentials.
Installation and Activation¶
Install the plugin and activate the corresponding Profile layer to enable it.
- Install using the Next version:
dsh plugin --profile safe add dsh-safe-web-fetch@next
After installation, run `dsh --profile safe --dump-config` to verify that the configuration took effect.
- For production deployments, pin a tested version:
dsh plugin --profile production add dsh-safe-web-fetch@0.1.0-next.0
- Alternatively, install a specific Git commit:
dsh plugin --profile safe add github:MostlyHarmlessxyz/dsh-safe-web-fetch#<commit-sha>
Configuration¶
The plugin provides a set of configurable parameters with conservative defaults.
| Setting | Default | Maximum |
|---|---|---|
maxUrlLength |
2048 |
16384 |
maxResponseBytes |
5000000 |
100000000 |
maxBodyChars |
100000 |
10000000 |
timeoutMs |
30000 |
Node timer limit |
maxRedirects |
5 |
20 |
maxConcurrentRequests |
16 |
128 |
Additionally, allowHosts (allow list), denyHosts (deny list), and userAgent can be configured. In DSH, configuration lines are replaced entirely, so all fields must be included when modifying the configuration.
- id: safe-web-fetch
name: dsh-safe-web-fetch
config:
maxUrlLength: 4096
maxResponseBytes: 10000000
maxBodyChars: 200000
timeoutMs: 30000
maxRedirects: 3
maxConcurrentRequests: 8
allowHosts:
- '*.docs.example.com'
denyHosts: []
userAgent: my-company-fetch/1.0
Use Cases and Considerations¶
This plugin is suitable for agent development scenarios that require restricted web operations in DSH environments.
Notes:
- Content trust: Public addresses do not imply trusted content. The plugin is not responsible for handling prompt injection, malware, or HTML sanitization; these must still be handled at the application layer.
- System-level limits: OS-level third-party resolvers cannot be fully blocked by this plugin. This is a known security boundary.
- Functional boundary: This plugin does not add cookies, authorization headers, browser state, or request bodies.
- Not a gateway policy: It is not a firewall, content scanner, approval screen, or proxy policy. For organizational zero-trust networks, appropriate controls must still be deployed at the network boundary.
Conclusion¶
dsh-safe-web-fetch provides basic SSRF protection for DeepSeek Harness through strict DNS validation, connection isolation, and content filtering. As part of the plugin ecosystem, it follows DSH’s “everything is a plugin” design philosophy, allowing developers to flexibly integrate it based on Profile requirements.