Foreword

DeepSeek Harness (DSH) adopts the “everything is a plugin” philosophy. Existing tools such as web_fetch or web_search usually convert target web pages into Markdown documents. This is suitable for reading, but not for debugging network exchange details or scenarios requiring precise control over the HTTP protocol.

dsh-http-debug provides DSH with a generic HTTP client. It focuses on raw HTTP semantics (methods, headers, bodies, status codes, timing, and sizes), and includes SSRF / private network protection, session request history, and HAR export. For developers who need fine-grained network debugging within the DSH ecosystem, this is a zero-dependency CLI tool.

Core Features

  • Generic HTTP client: Supports fully defined requests (method, headers, body, timeout, redirect policy) and structured responses (status, headers, body, timing, sizes).
  • SSRF and private network protection: Blocks loopback addresses, RFC 1918 private ranges, CGNAT, link-local addresses, multicast, and reserved addresses by default. All redirects are also checked.
  • Request history and replay: An in-memory ring buffer stores each request/response pair, supporting listing, inspecting details, or replaying.
  • WAF-friendly: Provides optional default User-Agent and Referer headers to avoid triggering simple Web Application Firewalls.
  • Response inspection and export: Supports JSON validation and HAR 1.2 format export. Includes hard size limits to prevent oversized responses from causing context overflow.
  • Zero-dependency CLI: A standalone command-line tool that does not depend on other libraries.

Installation and Enablement

The plugin is distributed as a Bundle and includes the cordis.patch.yml configuration file. After installation, it registers three tools into ctx.tools, available for direct invocation by the Agent.

Install it into a specified Profile using the dsh plugin command:

dsh plugin --profile <name> add dsh-http-debug

Or install it directly from the GitHub repository:

dsh plugin --profile <name> add github:JohnXu22786/net-debug

After installation, you can verify tool availability in the REPL or Agent, or adjust parameters such as the SSRF whitelist and timeouts in the configuration.

Main Tool Usage

The plugin provides three DSH tools:

1. http_request

Executes or replays an HTTP interaction. Parameters include:
* url: Absolute HTTP(S) URL (can be omitted when replaying).
* method: Request method (GET, POST, PUT, PATCH, DELETE, etc.).
* headers / body: Request headers and request body (UTF-8 text or Base64).
* timeout_ms / max_redirects: Timeout and maximum number of redirects.
* validate_json / include_har: Validate the response JSON and export a HAR document.
* bypass_ssrf: Dangerous, disables SSRF checks for a single request.

Returns a structured response object. Network errors (timeout, network, SSRF block) throw exceptions with error codes.

2. http_history

Manages request history within the session.
* action: Operation type (list to list summaries, get to get details, clear to clear, stats for statistics).
* id: History record ID (required for get only).

3. http_rules

Manages runtime SSRF whitelist rules.
* action: list, add, remove, clear.
* rule: Hostname, wildcard (e.g., *.example.com), IP, or CIDR.

Note: Rules added through this tool are only valid for the current session. Persistent configuration must be set by configuring ssrf.whitelist in the plugin configuration file.

Notes

  • Body size limit: To prevent oversized responses from causing prompt context overflow, the plugin enforces a hard size limit on captured response bodies (default 131072 bytes).
  • SSRF risk: The bypass_ssrf flag carries security risks and should be used cautiously only when absolutely necessary.
  • Development preview: DSH internal mechanisms are still evolving rapidly. The specific implementation of the Profile mechanism and Loader may change with versions.

Summary

dsh-http-debug provides the DSH ecosystem with a secure and controllable HTTP debugging entry point. It compensates for the lack of protocol-level control in high-level document extraction tools, making it suitable for scenarios requiring precise interaction or troubleshooting network issues.