Install
Inside DeepSeek Harness, with dsh-market
dsh plugin --profile web add dshmarket
Or from the command line
dsh plugin --profile web add github:wjt0321/dsh-git-proxy
Installing runs third-party code with your own permissions — it can read your files, use your credentials and reach the network. Review the source first, and pin a commit (github:owner/repo#sha) when you can.
README
dsh-git-proxy
On-demand GitHub proxy for DeepSeek Harness. Toggle the git/SSH proxy for github.com from the Web UI settings, save your proxy address, and test connectivity before downloading.
Install
From the plugin market, or:
dsh plugin --profile web add github:wjt0321/dsh-git-proxy
Restart the Web UI, then open Settings → Git Proxy.
Usage
- Enter your proxy address (e.g.
127.0.0.1:10808) and click Save. - Click Enable proxy — it configures:
- git (https):
git config --global http.https://github.com.proxy http://<addr> - SSH (
git@github.com:): a plugin-ownedProxyCommandon theHost github.comblock of~/.ssh/config, using theconnecttool shipped with Git for Windows
- git (https):
- Use Test connectivity to verify the proxy port and the
github.com:443/github.com:22tunnels. - Click Disable proxy when downloads finish — both configurations are removed immediately.
Screenshots

Enabled — git and SSH proxy are on.

Disabled — clicking Disable proxy turns both off and restores direct connections.
Security
- Only
github.comgit operations are affected (https and SSH). npm/pnpm package downloads are untouched. - The proxy address is validated (host characters + port range) and stored per profile at
<profile>/git-proxy.json. ~/.ssh/configedits are conservative: only plugin-ownedProxyCommandlines (the quoted-connect format this plugin writes) are ever replaced or removed — a pre-existing userProxyCommandline is kept and the plugin line is inserted before it (ssh_config is first-match-wins). Everything else in the file survives byte-for-byte; configs containingMatchsections or multi-hostgithub.comlines are left untouched (the UI reports this).- Mutating routes accept only same-origin POSTs.
Known limitations
- SSH proxying requires the
connecttool (ships with Git for Windows). Without it the SSH part is reported unavailable; https still works. - Authenticated proxies (user/password) are not supported.
- IPv6 proxy addresses are not supported.
- If the proxy software is off while the proxy is enabled, git operations fail until you disable it (the test button warns beforehand).
- Any user
ProxyCommandline that happens to match the plugin's format (quoted path +-H+%h %p) is treated as plugin-owned. - Editing a CRLF ssh config normalizes line endings to LF.
Development
pnpm install
pnpm test # vitest suites
pnpm typecheck
pnpm build # tsc host + tsdown client bundle (lib/client.js)
The client bundle is a __ModuleLoader__ factory (id dsh-git-proxy) served by client-modules via the exports["./client"] subpath.
License
MIT