izwarm195/dsh-net-tools 预览 preview

izwarm195/dsh-net-tools

Plugin插件 Native原生 ⭐ 3 MIT Approval & Security审批与安全

dsh-net-tools:为沙箱化 DSH 代理提供可靠的出站网络连接 — net_fetch(通过代理 CONNECT 隧道进行 HTTP 获取)和 net_proxy_status(代理诊断)。

Project Overview项目介绍

This is a native plugin built exclusively for DeepSeek Harness (DSH) that resolves common network access issues when DSH executes commands inside its isolated file sandbox. On Windows systems, the schannel-based TLS implementation used by curl and PowerShell inside the sandbox cannot retrieve valid credentials, which causes all HTTPS requests to fail immediately with a SEC_E_NO_CREDENTIALS error. The plugin runs outside the sandbox in DSH’s host Node.js process, so it has full access to the host system’s working TLS stack and network configuration to handle requests properly.

The plugin adds two tools for DSH agents to use. The first tool, net_fetch, pulls HTTP or HTTPS content through a user-configured local proxy without relying on the sandbox’s broken network stack. It automatically follows redirects, enforces configurable timeouts, maximum response size limits, and SSRF protection for all outgoing requests. The second tool, net_proxy_status, reports the currently active proxy configuration and checks if the configured proxy is reachable from the host.

Installing the plugin is straightforward using DSH’s built-in plugin management command. After running the dsh plugin add command for your DSH profile (either web or desktop), you just need to restart DSH for the new tools to become available to agents. The plugin is released under the permissive open source MIT license, and it includes strict security defaults that block requests to private network addresses by default to prevent SSRF attacks. Users can override this default with an explicit flag if needed.

这是一个专为DeepSeek Harness(DSH)开发的原生插件,用于解决DSH在文件沙箱中执行命令时遇到的网络访问问题。在Windows系统上,沙箱中基于schannel的TLS(curl、PowerShell使用)无法获取凭据,会导致所有HTTPS请求失败,本插件运行在DSH宿主Node.js进程中,位于沙箱外,可正常使用TLS。

本插件提供两个实用工具:net_fetch可通过用户本地代理隧道抓取HTTP(S)内容,net_proxy_status可报告当前生效代理并检测连通性。net_fetch支持自动跟随重定向,内置超时限制、响应大小上限和SSRF防护,插件会按照固定优先级顺序自动发现用户可用的代理配置。

安装方式十分简单,只需要通过DSH的插件管理命令添加本包,安装完成后重启DSH即可让Agent使用这两个工具。本插件采用MIT许可开源,拥有严谨的安全设计:仅允许HTTP/HTTPS协议,默认拦截私有网络地址,可手动配置开放,保障使用安全。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 3 stars - very few users, little community feedback星标只有 3,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:izwarm195/dsh-net-tools

把 izwarm195/dsh-net-tools 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-net-tools

让DSH使用你的魔法:把沙箱里的 agent 接上你本地的 HTTP 代理,一条命令就能抓取被墙的网站、文档和 API。

English · 简体中文

🤖 关于本项目

本项目由 AI 完全开发与维护:代码、测试与文档均由 AI(DeepSeek Harness 编码代理)生成,人工仅负责审阅、验收与发布。

要解决的问题

DSH 在文件沙箱(workspace-write)里执行命令时:

  • Windows 基于 schannel 的 TLS(curl、PowerShell)无法获取凭据,所有 HTTPS 请求都会失败并报 SEC_E_NO_CREDENTIALS;
  • Node.js 自带独立的 TLS 实现不受影响,但沙箱 shell 依然无法稳定联网;
  • 本机代理(如 127.0.0.1:7897)只有在每个工具都记得手动传入时才会被使用,极易漏配。

这个插件做了什么

工具运行在 DSH 宿主进程(Node.js)中,位于文件沙箱之外,TLS 正常工作。插件提供:

  • net_fetch —— 通过用户代理的手动 CONNECT 隧道抓取 HTTP(S) 内容(不走 schannel、零依赖)。自动跟随重定向、执行超时/大小上限/SSRF 防护,返回文本(或截断后的响应体)。
  • net_proxy_status —— 报告 DSH 进程会使用哪个代理(用户级环境变量、当前进程环境变量、Windows 系统代理),并检测其可达性。

代理发现顺序:显式 proxy 参数 → HTTPS_PROXY / HTTP_PROXY 环境变量 → Windows 系统代理(注册表 Internet Settings)。

安装

dsh plugin --profile web add <本包>
# 或:dsh plugin --profile desktop add <本包>

安装后重启 DSH,agent 即可使用这两个工具。

使用示例

抓取一个被墙的页面(自动走代理):

net_fetch(url: "https://github.com/")
→ [200] https://github.com/ (via proxy) 1212ms …

排查代理配置:

net_proxy_status(checkReachability: true)
→ effective: http://127.0.0.1:7897
  proxy reachable: true
  probe: [204] https://www.gstatic.com/generate_204 ok=true

实际效果:agent 思考过程中连续调用 net_fetch 抓取网页(截图):

net_fetch 使用示例

测试

npm test
# 沙箱内无法 spawn 子进程时,用同进程模式:
node --test --test-isolation=none test/fetch.test.js

安全设计

  • 仅允许 http: / https: 协议;
  • SSRF 防护:默认拒绝私网 / 回环 / 链路本地地址(传 allowPrivate: true 可放行);
  • 响应大小上限(默认 1 MiB)、超时上限(默认 30 秒);
  • 重定向最多 5 次,且每次重定向都重新执行同样的安全校验。

许可

MIT © 2026 izwarm195

← 上一个 Prev dsh-plugins 下一个 Next deepseek-vl-support →