mafeis/dsh-net-proxy 预览 preview

mafeis/dsh-net-proxy

Project Overview项目介绍

This is a native network proxy plugin built exclusively for DeepSeek Harness (DSH). It routes all network requests initiated by the DSH agent, including web search, content fetching, and external API calls, through a user-specified HTTP, HTTPS-CONNECT, or SOCKS5 proxy. The plugin stores configuration persistently, loads it automatically when DSH starts, and adds a native-style visual settings page directly to the DSH interface. To install, you can run the DSH CLI command dsh plugin --profile web add github:mafeis/dsh-net-proxy, or manually add the plugin entry to your local profile's cordis.patch.yml file.

The plugin covers both the agent's global fetch calls and DSH's native web_fetch proxy layer, so all outgoing requests are handled consistently. It can automatically follow your system's proxy settings, checking for changes every 3 seconds to update ports or toggle proxy status without any manual reconfiguration. It also automatically merges your Windows system's ProxyOverride bypass list into the plugin's local NO_PROXY rule set. This tool is purpose-built for personal developers who need their DSH agent to route all outgoing traffic through a local proxy service running on their machine.

This plugin has zero external runtime dependencies, as all proxy logic, logging, and frontend UI elements are implemented with Node.js native modules. The entire uncompressed release package is only 72.6 KB in size. All request logs are stored only in an in-memory circular buffer that holds up to 500 recent entries, capped at less than 1 MB total size, and are never written to disk or sent to any external server. The project is released under the open-source MIT license, and currently does not support automatic PAC proxy configuration, which requires manual setup by the user.

这是一款专为DeepSeek Harness(DSH)开发的原生网络代理插件,作用是将DSH agent主动发起的所有网络请求(包括web_search、web_fetch和外部API调用)路由到用户配置的HTTP、HTTPS-CONNECT或SOCKS5代理。它支持配置持久化,启动后自动生效,还提供了和DSH原生界面风格一致的内置可视化设置页。用户可以通过DSH CLI命令dsh plugin --profile web add github:mafeis/dsh-net-proxy安装,也可以手动在profile的cordis.patch.yml中添加插件条目。

该插件覆盖agent全局fetch和DSH web_fetch代理层两类请求,停用或卸载后可以完整还原原有网络配置。它支持自动跟随系统代理设置,每3秒读取一次系统配置,自动启停和切换端口,还会自动把Windows的ProxyOverride绕过列表并入本地NO_PROXY规则。所有经过代理的请求都会生成日志,包含方法、URL、状态码、耗时和流量信息,日志仅存在内存环形缓冲区,不会落盘也不外发,适合需要让DSH agent走本地代理的开发者使用。

该插件没有额外运行时依赖,所有代理逻辑、日志处理和前端图表都使用Node原生模块实现,整个发布包仅72.6KB。它对日志存储有明确的硬限制:最多保留最近500条请求日志,总占用不超过1MB,单条请求详情不超过256KB,总详情池不超过4MB。所有请求和响应内容仅存内存,清空日志后即彻底消失,不会泄露隐私。该插件采用MIT许可证开源,目前不支持PAC模式自动跟随,需要手动配置。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 note1 项提示
  • 13 stars - an early-stage project星标 13,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:mafeis/dsh-net-proxy

把 mafeis/dsh-net-proxy 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-net-proxy

awesome · DSH plugin

DeepSeek Harness 网络代理插件:让 agent 自己发起的网络请求(web_search / web_fetch / 外部 API)走你配置的 HTTP / HTTPS-CONNECT / SOCKS5 代理,配置持久化、启动即自动生效,并提供可视化设置页。

安装

dsh plugin --profile web add github:mafeis/dsh-net-proxy

安装后重启 dsh web,在 设置 → 网络代理 里启用并填写代理地址(如 127.0.0.1:7890)。

也可手动在 profile 的 cordis.patch.yml 加入:

- insert:
    - id: net-proxy
      name: 'dsh-net-proxy'

主要功能

双通道代理生效:包装 agent 进程的全局 fetch(手写 HTTP/SOCKS5 转发,零第三方依赖),同时把生效策略同步安装进 web_fetch 实际使用的 harness 代理层——两类请求全覆盖,停用/卸载完整还原。

跟随系统代理:每 3 秒读取系统代理设置,自动启停、自动跟随端口变化(v2rayN / Clash 切换无需改配置);系统关闭时自动直连;Windows ProxyOverride 绕过列表自动并入 NO_PROXY。

请求日志:经插件代理的每条请求一条记录——方法、URL、状态码、耗时、上下行流量、发送/返回内容预览;全部内存环形缓冲(最近 500 条),不落盘、不外发,占用有硬上限(< 1MB,可熔断)。

本地中继:web_fetch 流量经本地回环中继过插件之手——可观测、可统计,同时解除 harness 层的 SOCKS5 限制(socks5 配置现在全覆盖)。

流量图表:请求日志实时聚合为时间线 / 状态分布 / 耗时分布 / 通道分布 / 目标主机 TOP 10 五张自绘图表,前端纯函数聚合、零新增存储、5 秒刷新。

JSON 详情:日志点条目展开关键信息,「详情」弹窗内查看完整请求/响应内容;JSON 体自动渲染为可折叠树视图(键左对齐、缩进网格、长字符串点击展开全文),完整内容按需加载(单条 ≤256KB / 总池 ≤4MB 硬上限)。

设置页:一个一级菜单 + 页内二级标签(代理设置 / 请求日志 / 流量图表),连通性探测、地址过滤、渐进加载;配色全部走宿主主题变量,视觉与宿主一致。

最近调整

  • 总开关语义明确:「代理已启用」徽章只反映「启用代理」总开关;跟随模式下横幅格式统一「(跟随系统): 地址」(地址为真实读取的系统代理),生效与否只用红/绿横幅色表达。
  • 开关即时生效:「启用代理」「跟随系统」勾选立即应用;「保存」按钮只负责地址/端口等输入项。
  • 健壮性专项(全量代码审查,11 处):连接失败时流量日志条目收尾(防 2000 条熔断后日志永久失效);配置文件坏端口/坏协议在加载期拦截并回退默认(不再每条请求报连接错);中继背压与解压泵挂死兜底;设置页保存不再重置手改的日志配置;修复 JSON 长字符串条件 Hook 可能导致设置页白屏。
  • 修复 harness 层误杀本地中继(影响 v0.5.0–v0.7.0):「先还原再装」的中间步骤把刚启动的中继停掉,策略指向死端口——日志与自检正常但 web_fetch 全断。已修复并新增生命周期回归测试。
  • 新增中继存活看护:中继意外停止时 5 秒内自动重装策略(新端口重指),不再出现指向死端口的静默断网。
  • 日志详情弹窗:点击条目行内展开关键信息,点「详情」弹出居中详情卡片(Esc/遮罩关闭),JSON 树行式布局重做、长 URL 单行截断。
  • TOP 主机 8 → 10;配色全面回归宿主主题变量(撤销全部自定硬编码色)。

修复中继意外关闭后状态假活导致看护永不自愈的问题;跟随模式语义修正:总开关=硬闸(关=永不转发),系统代理关闭时回退手填地址而非强制直连。

  • 中继端口终身制:中继端口在插件进程内终身不变(总开关切换/策略重装不再换端口,仅卸载时关闭),保证第三方单例代理组件的地址引用永不过期。完整变更历史见 GitHub Releases。

配置字段(net-proxy.json)

字段 默认 含义
enabled false 是否启用代理
followSystem false 跟随系统代理
protocol http http(含 CONNECT 隧道)或 socks5
host / port 127.0.0.1 / 7890 代理地址
username / password 空 可选认证
noProxy ["127.0.0.1","localhost","::1"] 命中则直连
logEnabled true 请求日志开关(关闭后不再记录新条目)
logPreviewBytes 512 每侧内容预览的最大字节数(0–8192,0 = 不记内容)

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-expert-mode 下一个 Next dsh-from-scratch →