ssrf 10
Configurable User-Agent and non-public address allowlists for DeepSeek Harness web_fetch
dsh plugin add dsh-web-fetch-enhancedSSRF-resistant HTTP(S) fetch provider for DeepSeek Harness
dsh plugin add dsh-safe-web-fetchIP/domain allowlist web_fetch provider for DeepSeek Harness: lets web_fetch reach allowlisted hosts/IPs freely (incl. proxy fake-IP addresses like 198.18.x.x) while keeping the default public-IP safety check for everything else.
dsh plugin add dsh-web-allowlist-fetchfake-ip-aware WebFetchProvider for the DeepSeek Harness web seam — keeps the web_fetch tool working under mihomo/Clash fake-ip DNS without disabling fake-ip or setting proxy environment variables.
dsh plugin add dsh-web-fetch-fakeipEgress policy for DeepSeek Harness: a host allowlist on web_fetch and web_search enforced at connect time, audit-mode by default, with OCSF Network Activity records
dsh plugin add dsh-netguardRuntime security guard for DeepSeek Harness (DSH) — blocks command injection, SSRF, credential exfiltration, and destructive operations at runtime.
dsh plugin add dsh-ccs-securityCorrectover runtime security for DeepSeek Harness (DSH): CCS 7-dimension verification, command-injection/SSRF/credential-exfil blocking, Ed25519 receipts, audit-first. Install with `dsh plugin add dsh-correctover`.
dsh plugin add dsh-correctoverAuthenticated, policy-gated WebFetchProvider for the DeepSeek Harness web capability seam (ctx.web)
dsh plugin add @yadsh/dsh-web-fetch-authenticatedLocal HTTP(S) fetch provider for dsh with SSRF protection (personal plugin)
dsh plugin add @frost_with_snow/dsh-web-fetchDSH bundle: a tools/pre-execute guard that blocks SSRF (private/loopback/link-local/metadata) and enforces an allow-list or explicit consent for the Cue Omni Reader parse tool.
dsh plugin add @cueai/dsh-omni-reader-guard