Introduction

The ctx.web interface in DeepSeek Harness (DSH) provides agents with web connectivity. In environments without a proxy or API Key, directly calling a search engine or scraping a web page may encounter anti-bot measures, network restrictions, or SSRF risks. The websearch-plugins plugin encapsulates this process as a standard DSH plugin by providing aggregation across 16 domestic and international search engines and SSRF-protected fetching, making the web_search and web_fetch tools available without relying on external API keys.

Core Features

Aggregated Search and Result Filtering

The plugin includes 16 built-in search engines, including domestic engines such as Baidu, Sogou, 360, Shenma, and Bing China, as well as international engines such as Google, Bing, DuckDuckGo, Yahoo, and Yandex. By default, it uses phantom-aggregate to provide aggregated search. The system sends requests in parallel and automatically filters out failed results caused by timeouts, blocks, 403 responses, or empty parsing, ultimately returning deduplicated valid entries.

Direct Fetching and SSRF Protection

The web_fetch tool can directly fetch a target URL. The plugin implements SSRF protection based on DNS resolution and redirect detection, rejecting access to loopback addresses (127.0.0.0/8), private network segments (10.x/172.16.x/192.168.x), link-local addresses, and reserved addresses. It also limits HTML to 1MB and text to 512KB; any excess content is truncated and marked as truncated.

Browser Simulation and Zero Dependencies

The plugin does not depend on any external runtime libraries and directly uses the built-in fetch in Node.js. At the request layer, it simulates the behavior of a real browser: it sends complete Chrome desktop-level headers (sec-ch-ua, etc.) and maintains an in-process cookie jar. For anti-bot pages that require JavaScript rendering, the plugin provides a fetchMode: auto mode, which automatically invokes a persistent headless Blink renderer (based on CDP) to parse the content.

Installation and Activation

This plugin is a standard DSH plugin and is installed using the dsh plugin command.

dsh plugin --profile web add github:asdshuaishuai/websearch-plugins

After installation, you need to restart the DSH Web process (press Ctrl+C and then run dsh web again) and refresh the page for the configuration to take effect.

Usage

After installation is complete, you can directly call the following interfaces in the Harness environment:

  • Aggregated search: Call web_search(query), with phantom-aggregate selected by default.
  • Single-engine search: Call web_search(query) and specify a provider, such as baidu or google.
  • Web page fetching: Call web_fetch(url), using the phantom-http provider.

Notes

  • Environment dependency: The plugin depends on @deepseek-ai/dsh-web as a peer dependency. If it is not installed locally, the plugin may fail to resolve WebError or related type definitions.
  • SSRF restrictions: web_fetch intercepts all private network and loopback requests. To access local services, bypass this plugin and use low-level network tools directly.
  • Network and risk control: The availability of a search engine depends on the current machine’s outbound network environment. For engines restricted by the local network or triggering IP-based risk controls (such as Shenma or Yandex), the plugin automatically filters them at the result layer, so the overall request does not fail.