Hardening guard for mcp__omni__parse in DeepSeek Harness: a tools/pre-execute listener that denies private/reserved host URLs (SSRF), enforces an allow-list or ask (consent), and is fail-closed when allowedRoots is empty.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:sensedeal/cue-skills#path:/dsh/cue-omni-reader-guard
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
An optional DeepSeek Harness bundle that hardens the Omni Reader parse tool.
It registers a tools/pre-execute listener that gates mcp__omni__parse so a
model cannot silently parse an arbitrary URL. Install it after/alongside the
@cueai/dsh-omni-reader wiring bundle.
What it does
Before a mcp__omni__parse call dispatches, the guard classifies the source:
| source | outcome |
|---|---|
private / loopback / link-local / cloud-metadata host (10/8, 172.16/12, 192.168/16, 127/8, 169.254.169.254, 100.64/10, fe80::, fc00::, ::1, localhost, *.local, metadata…) |
deny (SSRF guard) |
allow-listed host (allowList) |
allow |
| other external host | policyForUnknown — deny (default), ask, or allow |
local path inside an explicitly configured allowedRoots |
allow |
local path outside allowedRoots, or no allowedRoots set |
deny (fail-closed) |
Every other tool passes through untouched (the guard keys on mcp__omni__parse). It gates
the source argument and the url alias (Bridge 1.5+ accepts exactly one of the two).
Install
dsh plugin --profile web add @cueai/dsh-omni-reader-guard
# or one-off
dsh web --patch ./dsh/cue-omni-reader-guard/cordis.patch.yml
Configure
Via the bundle's cordis.patch.yml config (no secrets, no hardcoded deployment paths):
| Field | Type | Default | Meaning |
|---|---|---|---|
blockPrivate |
boolean | true |
deny private/reserved hosts (the SSRF gate) |
allowList |
string[] | [] |
hosts/domains that bypass consent (a bare domain also admits subdomains; *.x for subdomains only) |
allowedRoots |
string[] | [] (local files denied) |
absolute dirs a local source must fall under. Set explicitly to allow local parsing; empty = fail-closed |
policyForUnknown |
'deny'|'ask'|'allow' |
'deny' |
outcome for an external host not in allowList |
consentReason |
string | … | prompt text for policyForUnknown: ask |
Example: allow a trusted API host and require consent elsewhere.
config:
blockPrivate: true
allowList: ['api.example.com']
policyForUnknown: ask
Verify
node --test dsh/cue-omni-reader-guard/test/policy.test.js
python3 scripts/verify_dsh_bundles.py
Notes
askrequires DSH's approval service to returnallowed-once; without one it becomes a denial (fail-closed) — see thetools/pre-executewaterfall contract.- This is a guard, not a sandbox: it filters hosts and local roots, it does not
rewrite arguments. Keep
allowedRootsminimal and preferdeny+ an explicitallowListfor unattended agents. - The core policy (
policy.js) is pure Node (node:url/node:net), so the security logic is testable without a live DSH.
License
MIT — see LICENSE.
Links
More in this category
toby-bridges/api-relay-audit★ 870
Runs local security audits of AI API relays and LLM proxies from DeepSeek Harness, producing Markdown reports for prompt injection, model substitution signals, tool-call rewriting, error leakage, stream integrity, and profile-gated Web3 risks.
SeaOf0/dsh-redteam-model★ 668
Authorized-security DSH collection: nine work modes (redteam coordinator, pentest, code audit, binary analysis, attack-defense, AV evasion, incident response, cloud security, CTF solving) and fifteen runtime plugins, managed from a settings page with one-click deploy, install, update and uninstall.
howmp/dsh-pentest★ 598
Authorized pentest mode for DeepSeek Harness — exploration chain, assets and findings with a Web view.
PerryLink/dsh-auto-review★ 234
Second-model auto-review on the approval answerer chain: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default.
NanmiCoder/dsh-auto-mode★ 165
Adds an Auto permission preset between Workspace Write and Full access: routine work stays in the official workspace-write sandbox while the current session model reviews escalation and destructive calls, granting one exact wider access once, asking when the intent is ambiguous, and denying critical paths.
PerryLink/dsh-permission-rules★ 121
Claude Code-style declarative permission rules: ordered allow/deny/ask YAML rules matching tool names, arguments, workspace paths, and agent identity on the tools/pre-execute waterfall, with full session-log audit, dry-run mode, and hot reload.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.