Skills Plugins MCP Prompt Model 导航 博客 资讯 我的中心

dsh-web-allowlist-fetch

IP/domain allowlist web_fetch provider for DeepSeek Harness: lets web_fetch reach allowlisted hosts/IPs freely (incl. proxy fake-IP addresses like 198.18.x.x) while keeping the default public-IP safety check for everything else.

xain @xain ⬇ 1 ★ 0 main

安装

dsh plugin --profile web add github:xain/dsh-web-allowlist-fetch
下载安装清单

需要可复现安装时,可在仓库后追加 #commit 固定提交。

IP/domain allowlist web_fetch provider for DeepSeek Harness: lets web_fetch reach allowlisted hosts/IPs freely (incl. proxy fake-IP addresses like 198.18.x.x) while keeping the default public-IP safety check for everything else.

该插件未提供要点说明,请参考仓库 README。

  1. 安装并启动 DeepSeek Harness:npx @deepseek-ai/dsh web
  2. 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
  3. 用 dsh plugins list 确认已安装,必要时重启 Harness 生效

插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。

代码仓库github.com/xain/dsh-web-allowlist-fetch
许可证MIT
主要语言main
下载量1
GitHub 星标0
最近推送2026-09-09
收录日期2026-09-19
分类模型与提供方

事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。

以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。

# dsh-web-allowlist-fetch

IP/domain **allowlist** `web_fetch` provider for [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness).

`web_fetch` in Harness refuses any host that resolves to a **non-public IP**
(the `http` provider's `isPublicIpAddress` / `unicast` guard). In proxy
environments that use **RFC 2544 fake-IP** (Clash / Surge / Mihomo TUN mode, the
`198.18.0.0/15` range), ordinary public domains resolve to fake, non-public IPs
and get blocked — so fetching an otherwise-fine site fails with
`URL hostname "…" resolves to a non-public IP address`.

This plugin registers a `web_fetch` provider (`id: allowlist`) that:

- **allowlists** the hosts / IPs / CIDRs you configure, and fetches them freely
  (bypassing the public-IP guard — a fake-IP address is fine once its domain or
  the fake IP range is allowlisted);
- keeps the **stock public-IP safety check** for every other host, so the
  default posture is unchanged.

The allowlist is editable from the web client's **Settings → 插件配置** surface;
see [Configuration](#configuration).

## Install

Publish this package (or install from your git URL), then in your Harness home:

```sh
dsh plugin --profile web add dsh-web-allowlist-fetch
```

The bundle's `cordis.patch.yml` registers the provider and routes
`web.config.fetchProvider` → `allowlist`.

> **install-time note:** a patch row targets a Cordis row by id and replaces its
> **whole config**. The bundled patch therefore sets the full `web` config (both
> `fetchProvider` and `searchProvider`). Edit `searchProvider` in the patch to
> match your search setup, or the value set by another layer will be overwritten.

## Configuration

The allowlist is exposed as a **settings namespace** (`dsh-web-allowlist-fetch`)
and edited from the **Settings → 插件配置** surface in the web client: open the
plugin's card and edit the allowlist (one host/IP entry per line). A committed
override lands in `$DSH_HOME/settings.yaml` and applies on the next fetch
without restarting.

The composed default (what the card starts from) is the bundle's patch — edit
it in your profile's `cordis.patch.yml` (or the settings layer):

```yaml
- insert:
    - id: web-fetch-allowlist
      name: dsh-web-allowlist-fetch
      config:
        allowlist: []
- id: web
  config:
    fetchProvider: allowlist
    searchProvider: ddg
```

You can also set the namespace directly in your settings layer:

```yaml
dsh-web-allowlist-fetch:
  allowlist:
    - weather.com            # this domain + any subdomain
    - 198.18.0.0/15          # Clash fake-IP range (any host resolving here)
    - 127.0.0.1              # a single IP literal
```

### Entry forms

| Form              | Matches                                            |
| ----------------- | -------------------------------------------------- |
| `example.com`     | `example.com` and every `*.example.com`            |
| `.example.com`    | `example.com` and every subdomain                  |
| `*.example.com`   | every subdomain                                    |
| `192.168.1.10`    | that exact IP literal                              |
| `198.18.0.0/15`   | any host/IP within that CIDR network               |
| `2001:db8::/32`   | any host/IP within that IPv6 CIDR network          |

## How it behaves

- **Allowlisted host/IP** → fetched directly via global `fetch` (follows
  redirects). Body decoded as text/html and capped at `maxBodyChars`.
- **Non-allowlisted host that resolves only to public IPs** → fetched directly.
- **Non-allowlisted host resolving to any non-public IP** → rejected with a
  descriptive error (unchanged from stock `http` behavior).

## Safety

This is an **escape hatch**, not a blanket disable. Only entries you list are
released from the public-IP guard. Do not allowlist `0.0.0.0/0`, `198.18.0.0/0`,
or `10.0.0.0/8` unless you fully understand the implication for a model that can
choose URLs — it would let the model reach your private network.

## Development

```sh
pnpm install
pnpm run check   # build (tsdown) + node --test tests
```

Build output: `lib/index.js` (ESM). Host peers resolve from the Harness profile
at runtime and stay external.

数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

提交后我们会发送一封确认邮件,点击邮件里的链接才会开始收信。

完全免费,取消任意时间。我们不会发送垃圾邮件。