dsh-aginxbrowser
Verifieddsh-aginxbrowser · v0.1.1 · Apache-2.0
aginxbrowser plugin for DeepSeek Harness: fetch JS-rendered / Cloudflare-protected pages as clean markdown, aggregated web search (Baidu/Sogou/WeChat and 11 more), and indexed interactive sessions (click / type / scroll / eval / screenshot) against a host
Install
dsh plugin add dsh-aginxbrowser Confirm the layer applied with dsh --profile default --dump-config — see the install guide.
Source
Tags
Creators
Readme
aginxbrowser — DeepSeek Harness plugin
Web access for DSH agents: fetch JS-rendered / protected pages as clean markdown, aggregated search across 14 engines, and stateful interactive sessions — all against a single-binary Rust browser engine, no local Chrome, no Node runtime.
Every session returns a live view URL: open it in any browser to watch the agent browse frame-by-frame and take over with the mouse. Oversight without screen-sharing.
Why this instead of a headless-Chromium tool
- Markdown first, pixels on demand. Reads default to clean markdown (with prompt-injection stripping); screenshots are opt-in. In our benchmarks the engine settles a page in ~0.5s and ~227MB where headless Chrome needs ~4s and 2.1GB/tab — and markdown output skips the pixel→vision→coordinate round-trip entirely.
- Interactive elements come as an indexed list (
[0] <a href=…>Learn more</a>with rects) — click by index or coordinates, no DOM-dump spelunking. - Sessions hold logins. Persistent sessions survive engine restarts (same id revives logged-in); cookies can be seeded from a DevTools "Copy as cURL" paste.
- Search with a memory. 14 engines (Baidu, Sogou, WeChat 公众号 articles, Bing, …) deduped and scored, cached locally for repeat queries, with per-engine health surfaced honestly.
- The human can always look.
live_view_urlper session — watch, or click into the same session.
Install
The plugin talks to an aginxbrowser engine over HTTP. The default is the hosted instance at https://browser.aginx.net; to run your own, see Self-hosting.
Install via dshx — the package is on npm (dsh-aginxbrowser), so the registry tarball works directly (local npm pack tgz and git URL work too):
dshx install aginxbrowser https://registry.npmjs.org/dsh-aginxbrowser/-/dsh-aginxbrowser-0.1.1.tgz
dshx list # should show: [on] aginxbrowser
For DSH Desktop profiles, reference the package under its real name in both places — the package.json dependency key and the dsh.profile.bundles entry:
"dependencies": { "dsh-aginxbrowser": "^0.1.0" }
DSH Desktop 2.0.5+ enforces dependency-key == actual package name and drops into recovery mode otherwise.
For developing this plugin against a harness checkout, overlay the source directly:
# cordis.yml
plugins:
'@deepseek-ai/dsh':
$overlay:
- insert:
- id: 'dsh-aginxbrowser': '/absolute/path/to/dsh-aginxbrowser/lib/index.js'
pnpm i
pnpm dsh web --patch ./cordis.yml # Web UI at 127.0.0.1:3080
Config
| key | default | |
|---|---|---|
baseUrl |
https://browser.aginx.net |
Engine base URL. Point at your own instance to run fully local. |
apiKey |
(empty) | Bearer token, if the instance requires one. |
timeoutMs |
90000 |
Per-request timeout against the engine. |
screenshotDir |
$TMPDIR/aginxbrowser-dsh |
Where agx_session_screenshot writes PNGs. |
Tools
Read side:
agx_fetch— one page as markdown/html/text. Auto tier tries plain HTTP first, renders only when needed (render_tierto force). Cloudflare-style challenges, stealth TLS fingerprints, JS-state extraction (js_extract), background XHR body capture (capture_xhr).agx_search— 14-engine aggregated search;fetch_topalso pulls top-N page contents.agx_doctor— engine health: live engines, feature gates. Tell engine-side issues from site-side ones.
Session side (stateful, indexed, live-viewable):
agx_session_create— open a session; returnssession_id+live_view_url. Viewport pinning, cookie seeding,persistent(survives restarts),keepalive, mobile emulation.agx_session_state— the page as[N] <tag …>listings with rects; N feeds click/input.agx_session_navigate/agx_session_click/agx_session_click_xy/agx_session_input/agx_session_scroll/agx_session_wait/agx_session_eval— the interaction set;waitsupports selector or JS predicate;click_xydoes full mouse-event fidelity for canvas surfaces.agx_session_screenshot— PNG to a local file (default captures the live viewport including unsaved form input).agx_session_list/agx_session_close— housekeeping.
Typical loop: agx_fetch for one-shot reads; for interaction, agx_session_create → agx_session_state → agx_session_click/agx_session_input → agx_session_state again.
Live view
agx_session_create returns e.g. https://browser.aginx.net/live.html?session=s_42. The page polls frames from the session and forwards your mouse clicks into it — the same session the agent is driving. Hand it to whoever is supervising the agent.
Self-hosting
curl -fsSL https://browser.aginx.net/install.sh | sh # single static binary
aginxbrowser --bind 127.0.0.1:8788
Also on Docker (ghcr.io/yinnho/aginxbrowser), Homebrew (brew install yinnho/tap/aginxbrowser), and as an Umbrel app. Then set baseUrl: http://127.0.0.1:8788.
Security notes
- Page content is returned as data, not instructions; the engine's fetch/search output strips prompt-injection payloads (zero-width chars, instruction-shaped lines, hidden text) with an observable
sanitize_report. - Cookies you pass to sessions are secrets — this plugin never logs them.
- SSRF posture is the engine's job, not the client's: the hosted instance enforces its own network policy regardless of what URLs tools request.
- Treat
agx_session_evalresults like any other web content: untrusted data.
License
Apache-2.0. Engine source and HTTP API docs: yinnho/aginxbrowser.