DSH Plugins Marketplace

DSH Plugins

Plugins

/

dsh-9router-web-search

d

dsh-9router-web-search

Manifest validโ˜… 1

DSH plugin: 9router-backed web search and web fetch providers

UI (client)hasBundlePatch

๐ŸŒ dsh-9router-web-search

Web search & fetch for DeepSeek Harness, powered by 9router. Wires the native web_search and web_fetch tools into 9router's /v1/search and /v1/web/fetch endpoints โ€” no server-side search tool required.

Version License: MIT Node.js ESM GitHub stars

๐Ÿ‡บ๐Ÿ‡ธ English ยท ๐Ÿ‡จ๐Ÿ‡ณ ็ฎ€ไฝ“ไธญๆ–‡


โœจ What it does

  • ๐Ÿ”Ž Search provider โ€” routes DSH's native web_search through 9router's /v1/search, returning deduplicated WebSource results (title, snippet, published date).
  • ๐Ÿ“„ Fetch provider โ€” routes DSH's native web_fetch through 9router's /v1/web/fetch, returning clean text/markdown bodies.
  • ๐ŸŽ›๏ธ Settings card โ€” a native DSH settings panel for the API key, base URL, models, timeouts, and limits.
  • ๐Ÿงฉ Zero-config wiring โ€” the bundle patch pins the web seam's search and fetch to 9router; no manual provider configuration.
  • ๐Ÿ” Credentials-aware, key-optional โ€” resolves the API key from DSH's credentials service (NINE_ROUTER_API_KEY) or a literal config value; keyless local 9router instances work out of the box; never committed to the repo.
  • ๐Ÿงฑ Zero build โ€” pure ESM, plain JavaScript, no bundler required.

๐Ÿงญ Why this plugin

DSH's default web_search uses the web-search-deepseek provider, which requires the upstream service to implement Anthropic's web_search_20250305 server-side search tool and return web_search_tool_result blocks.

9router is an OpenAI-compatible gateway: it passes that tool definition to the model as a regular function instead of executing searches server-side โ€” so it cannot provide native search by itself.

web-search-deepseek (default)9router (this plugin)
RequiresAnthropic web_search_20250305 server-side toolAny 9router-compatible gateway
Works with 9routerโŒโœ…
Search endpointmodel-providedPOST /v1/search
Fetch endpointmodel-providedPOST /v1/web/fetch

This plugin calls 9router's own endpoints directly and maps their responses to the WebSource and WebFetchBody types expected by the DSH web seam.

โš™๏ธ How it works

 web_search / web_fetch (native DSH tools)
            โ”‚
            โ–ผ
        ctx.web seam
            โ”‚  provider = "9router"
            โ–ผ
  dsh-9router-web-search
   โ”œโ”€โ”€ search  โ†’ POST {baseURL}/search      โ†’ WebSource[]
   โ””โ”€โ”€ fetch   โ†’ POST {baseURL}/web/fetch   โ†’ WebFetchBody
            โ”‚
            โ–ผ
      9router gateway
            โ”‚
            โ–ผ
   9router providers / model combos

Errors surface as machine-routable WebError codes (WEB_PROVIDER_ERROR, WEB_TIMEOUT, WEB_ABORTED, WEB_PROVIDER_CREDENTIAL_MISSING); transient network and 5xx failures are retried with backoff; non-2xx fetch responses come back as results โ€” never silent throws.

๐Ÿš€ Quick start

1. Install the plugin

npx @deepseek-ai/dsh plugin --profile web add github:lordraiden/dsh-9router-web-search

2. Wire it up

  • The plugin's bundle patch already pins web.searchProvider and web.fetchProvider to 9router โ€” no manual wiring needed (a profile's own cordis.patch.yml can override the row).
  • Set a baseURL in the settings card (or a NINE_ROUTER_BASE_URL environment value) pointing at your 9router gateway โ€” there is no implicit fallback endpoint; without a configured endpoint the provider reports itself unavailable.
  • If your 9router instance requires a key, store NINE_ROUTER_API_KEY in DSH's credentials โ€” the settings card's API key field writes it there โ€” or set a literal apiKey in the plugin settings. The secret is write-only in the UI and is never stored in this repo. Keyless instances work without any credential.

3. Restart & refresh

Restart Harness, then hard-refresh the browser. The 9router options appear in the web settings card.

๐Ÿ”’ Reproducible installs โ€” append a release tag (or commit SHA) to pin an exact version:

npx @deepseek-ai/dsh plugin --profile web add github:lordraiden/dsh-9router-web-search#v0.2.3

๐Ÿ› ๏ธ Configuration

KeyTypeDefaultDescription
baseURLstringโ€”Base URL of your 9router-compatible API (http/https only); resolved as explicit setting โ†’ NINE_ROUTER_BASE_URL env โ†’ absent (provider unavailable)
searchModelstringsearch-comboModel name for the search endpoint
fetchModelstringfetch-comboModel name for the fetch endpoint
searchTypestringwebsearch_type sent to the search endpoint
defaultMaxResultsnumber8Source cap used only when a search request does not specify maxResults (the DSH seam enforces the per-operation limit)
timeoutMsnumber30000Shared per-request timeout (per-capability defaults)
searchTimeoutMsnumber30000Search-only timeout; blank follows timeoutMs
fetchTimeoutMsnumber30000Fetch-only timeout; blank follows timeoutMs
fetchFormatstringmarkdownBody format requested from the fetch endpoint (markdown, text, html)
maxCharactersnumber50000Character cap for fetched bodies; sent to the gateway and enforced locally
apiKeysecretโ€”Literal API key (optional; no key = no Authorization header)
apiKeyEnvcredential-refNINE_ROUTER_API_KEYCredentials-service key name

Self-hosted 9router picks its search and fetch backends from its own provider configuration and ignores searchModel/fetchModel; keep those fields set for cloud gateways that route by model.

Endpoint precedence โ€” an explicit baseURL setting wins over the NINE_ROUTER_BASE_URL environment value; with neither set, no endpoint exists and the providers report themselves unavailable. There is no silent fallback to a repository-chosen remote. The schema rejects non-http(s) URLs, empty model/format strings, and non-positive numeric limits before any request is made.

Credentials โ€” NINE_ROUTER_API_KEY is resolved through DSH's credentials service; a literal apiKey is optional and wins when set. apiKeyEnv is a reference name in the credentials service, not a key. The secret is write-only in the settings UI, is never stored in git, and never appears in logs, diagnostics, or error messages.

๐Ÿ“Œ DSH compatibility

Version
Minimum supported0.1.7-rc.1 (peer range >=0.1.7-rc.1 <0.3.0)
Latest testedthe newest published 0.2.x โ€” CI installs it (currently 0.2.0-rc.2) and runs the full suite against it

CI and the release workflow both run the shared compatibility check (scripts/check-dsh-compat.mjs): once against the declared minimum and once against the latest published 0.2.x. A failing check stops the release workflow before the release is created. Versions outside the declared range โ€” including future 1.x releases โ€” are not claimed compatible until they are exercised the same way.

๐Ÿ›ก๏ธ 9router security

The web_fetch capability delegates URL extraction and SSRF protection to the 9router server: the plugin sends the target URL to POST /v1/web/fetch and trusts the gateway's fetch boundary. It implements no local SSRF policy of its own.

Run a patched, current 9router release โ€” the fetch endpoint has a published security advisory:

๐Ÿงช Development

pnpm install                 # install dependencies
pnpm test                    # run the test suite (node:test)
node scripts/validate-pack.mjs  # validate the packaged artifact

Node >=20 (CI runs Node 22) and pnpm (CI uses pnpm 10).

Repository layout

dsh-9router-web-search/
โ”œโ”€โ”€ src/                     # server-side plugin: index.js + nine-router-client.js
โ”œโ”€โ”€ client.js                # settings card
โ”œโ”€โ”€ cordis.patch.yml         # bundle patch registering the plugin
โ”œโ”€โ”€ test/                    # node --test contract suite
โ”œโ”€โ”€ scripts/                 # validate-pack.mjs, sync-storefront.mjs
โ”œโ”€โ”€ .github/workflows/       # CI (tests + packaging, DSH 0.2.x compat) and release
โ””โ”€โ”€ package.json             # ESM plugin manifest

Releases โ€” stable versions ship as v<version> GitHub Releases matching package.json; the release workflow re-runs the full suite and packaging validation against the tag before publishing.

Storefront sync โ€” node scripts/sync-storefront.mjs syncs the plugin entry into the storefront repo (manual; requires push access to the configured storefront fork).

๐ŸŒฑ Ecosystem & releases

  • ๐Ÿ“ฆ Distribution โ€” the GitHub repository is the only distribution source; stable versions ship as v<version> GitHub Releases.
  • ๐Ÿ› Issues & requests โ€” open an issue.

๐Ÿ“„ License

MIT

๐Ÿ™ Acknowledgments

This project began as a fork of rebron1900/dsh-web-search-9router โ€” thank you for the original 9router-backed web search and fetch provider for DeepSeek Harness.

Comments

Loadingโ€ฆ