When developing agents or using DeepSeek Harness (DSH), you may sometimes need to impersonate a specific client or bypass checks on target sites (such as a WAF). Editing configuration directly is cumbersome and may affect global behavior. The plugin provides a mechanism to inject request headers by domain, allowing you to modify HTTP request headers for specific hosts. Headers with the same name overwrite the original values.

Plugin Overview

The plugin is maintained by ZhiGangCai and is a request header injection tool. It supports injecting HTTP request headers based on host rules. Headers with the same name overwrite the original values, and header names are case-insensitive. The default configuration predefines one rule: inject User-Agent for agentrouter.org to bypass the WAF. The plugin is released under the MIT License.

How It Works

The plugin works by patching the global fetch function, so no changes to the DSH source code are required. It primarily targets the openai-completions and anthropic-messages pathways. When a request is sent, the system matches the host against rules in order and uses the first matching rule. After a match, it applies the set of request headers defined by the injection rule, overwriting same-name headers, and forwards the request. Requests that do not match any rule are passed through unchanged, with zero impact.

Installation and Enabling

Install the plugin via the command line. After installation, restart the DSH Web backend for the plugin to take effect.

dsh plugin --profile web add /path/to/dsh-header-injection

Configuration

The DSH settings panel provides a visual configuration entry point and supports applying changes immediately.

  1. Go to DSH Settings -> Plugins -> Request Header Injection.
  2. Configuration options:
    - enabled: Controls whether injection is enabled. Defaults to true.
    - rules: An array of injection rules. Each rule includes hosts (a list of hosts) and headers (a set of request headers).
  3. Rule format:
    - Host: A comma-separated list of host suffixes. Subdomain matching is supported (for example, example.org, foo.com matches a.example.org and foo.com).
    - Request headers: Multi-line text, with one name: value entry per line. When injecting, Headers.set semantics are used, meaning same-name headers are overwritten.
  4. Shorthand form: Within a rule, you can use the ua field instead of multi-line headers (for example, {hosts: "example.org", ua: "MyUA/1.0"}), which is equivalent to a single User-Agent header. If both are present, headers takes precedence.

After saving the configuration, the settings are persisted to the dsh-header-injection: section of ~/.dsh/settings.yaml and take effect without a restart.

2. Environment Variable Fallback

When the settings service is unavailable, environment variables can be used for configuration.

Environment Variable Default Description
AR_UA_ENABLED 1 Stop injection while keeping the patch when 0
AR_UA_HOSTS agentrouter.org Comma-separated list of hosts
AR_UA_VALUE RooCode/0.15.0 UA value
AR_UA_RULES - JSON array of multiple rules
AR_UA_HEADERS - Multi-line request header text (single-rule format)

Usage

1. Status Summary

Use the dsh-header-injection command to view the current list of rules and the hit/rewrite counts.

dsh-header-injection

2. Health Check

Visit the HTTP health route GET /dsh-header-injection/health. This route returns the rules array and the hit/rewrite counts.

Typical Use Case: Bypassing the AgentRouter Client WAF

The AgentRouter frontend has deployed an Alibaba Cloud WAF, which performs triple verification on clients (TLS fingerprint + SDK request headers + request structure). The default User-Agent of DSH (deepseek-harness/<version>) is intercepted and returns unauthorized_client_error.

By injecting User-Agent: RooCode/0.15.0, the WAF allows the request to proceed to the token verification stage. Current testing shows that modifying only the UA is sufficient to bypass the fingerprint check, without needing to add extra headers such as X-Title or X-Stainless-*.

Notes

  1. Only injected headers are overwritten: The plugin only overwrites the injected request headers. Headers not mentioned in the rules remain unchanged.
  2. TLS fingerprint not spoofed: The current version does not spoof TLS fingerprints. Although agentrouter.org currently does not reject this UA combination based on fingerprints, if the target site tightens WAF checks, you need to add more headers to the rule.
  3. Source code inspection: Before installing, inspect the source code and license to ensure they meet your environment requirements.

Ecosystem Context

The DSH philosophy is “everything is a plugin.” The community directory is an independent site and has no official affiliation with DeepSeek / Huanfang.

  • Plugin Directory: https://www.skillhub.cn/plugins/ZhiGangCai/dsh-header-injection
  • GitHub Repository: https://github.com/ZhiGangCai/dsh-header-injection