dsh-egress-router: An On-Demand Egress Routing Plugin for DeepSeek Harness
gswenxue/dsh-egress-router
An on-demand egress routing DSH plugin: import vless/vmess/trojan/ss nodes, route only blocked traffic through them, fall back automatically, and mark dead nodes instead of deleting them.
dsh-egress-router is an on-demand egress routing plugin for DeepSeek Harness that turns which traffic uses a node and which stays direct into a configurable policy. Aimed at unreachable GitHub, stalled pip installs, and agents that cannot fetch pages, it lets you import your own vless / vmess / trojan / ss nodes, send only the traffic that needs a node through it, fall back automatically when a direct connection fails, and mark failed nodes without deleting them. Terminal curl, git, pip, and npm plus the agent-side tool follow the same policy, while model calls stay unaffected.
How to Install
dsh plugin --profile web add github:gswenxue/dsh-egress-router- Category
- Integrations & Connections
- Platform
- DSH Plugin
- Author
- gswenxue
- Distribution
- Plugin
dsh-egress-router Key Features
dsh-egress-router Repo Summary
What Does It Do?
It is a DSH plugin for DeepSeek Harness that turns selective egress into a configurable routing policy. It solves the problem of GitHub being unreachable, pip installs stalling, or an agent failing to fetch pages, without routing all traffic through an overseas node: import your own vless / vmess / trojan / ss nodes, send only the traffic that needs a node through it, keep everything else direct, and fall back automatically when a direct connection fails. Maintained by gswenxue under the MIT license, written in JavaScript and last updated in 2026-10.
Core Features
- Three modes: Off (all direct), Smart (listed domains go through a node, the rest stay direct with automatic fallback), and Global (everything through a node); Smart is the default.
- On-demand fallback rather than "only when unreachable": a CONNECT tunnel with no return bytes within 4 seconds is treated as a black hole, so the plugin switches to a node and replays the TLS bytes the client already sent; plain HTTP requests retry with the same body after 6 seconds without response headers, and domains that fell back are remembered.
- Nodes are stateful and never auto-deleted: states are normal, failed, and unavailable on this machine; a failure only changes the state and makes later calls avoid it, while deletion happens only when you click it yourself.
- Four link types with batch import: vless (including Reality), vmess, trojan, and ss can be pasted across multiple lines, and the note taken from the # fragment is visible to the agent.
- Core fetched on demand: sing-box ships as a release asset, downloaded and SHA-256 verified the first time it is needed, keeping the repository small, with a mirror address or manual placement as alternatives.
- It never touches the harness egress policy: only subprocess proxy environment variables are injected, the harness network dispatcher is never replaced, so model calls are not slowed down or interrupted.
How to Use This Plugin?
After enabling it in DSH, open Settings → Network Proxy, paste one or more node share links and import them, then click Test on a node or Test All in the toolbar until the state reads normal. Smart mode is the default and usually needs no change; switch to Global when everything should go through a node. The agent gains a net_proxy tool with status, list, import, remove, use, mode, route, test, clean, fetch, and core operations, where fetch retrieves pages through nodes and falls back across healthy ones; curl, git, pip, and npm in the terminal follow the same policy without adding -x to every command. With "inject agent shell environment" enabled, subprocess proxy variables point at the local router and are restored when disabled or switched to Off mode. Node data stays local, so do not share the credential-bearing state file.
How to Troubleshoot This Plugin?
When GitHub access is restricted on your machine and the core download fails, point the mirror address in settings at any location serving the same file names, since the plugin appends the asset name to it; alternatively download the core manually and place it in the plugin's bin directory, where it will be used directly. If a node shows as unavailable on this machine, it usually means the local host lacks the matching egress, such as an IPv6-only node without an IPv6 route; switch to another node, as the plugin will not delete it automatically.
This page is an independent rewrite of the plugin's official README — for authoritative documentation and the latest changes, refer to the source: gswenxue/dsh-egress-router. The plugin is third-party code that runs on your machine once installed; inclusion does not imply endorsement — please review the source before installing.
