DeepSeek Harness, shortened to dsh, is an open-source AI agent application made by DeepSeek. You run it as a desktop app or start a local web UI with one npx command, point it at a project folder, and connect a model. The agent can then read and edit files in that workspace, run shell commands, delegate work, keep a plan, and run recurring tasks through a scheduler plugin. Almost every part of it is a plugin, and you can ask the agent to write new plugins for you. The code is MIT licensed, so the software is free; you pay for the model API, whether that is DeepSeek, another listed provider, or your own OpenAI-compatible server. On safety, the honest answer is that it is safer than an agent with no guardrails but not safe by default. Unlike some terminal agents, dsh has a file sandbox and approval prompts, with a default preset that limits writes to your workspace and asks before wider actions. But DeepSeek's own safety notice says the project is experimental developer-preview software, has not been security audited, must not be treated as secure or production-ready, and can damage files or leak credentials through bad model output, malicious input, or untrusted plugins. It recommends a disposable VM, container, or dedicated environment, and backups. Treat it as a capable preview to try in isolation, not a tool to run on a machine holding production secrets.
What is DeepSeek Harness, and is it safe to use?
DeepSeek Harness, or dsh, is an open-source agent application from DeepSeek, released under the MIT license and currently in developer preview. It runs as a desktop app or a local web UI, and the agent can read and edit files, run commands, research, and run scheduled tasks, with plugins for almost everything else. The software is free; you pay for the model API you connect. Its own safety notice says it has not been security audited, is not production-ready, and should not be your only protection for untrusted work.
Published · Updated · Evidence-linked, not search-volume ranked.
Why this question is current
Exact query-volume data was unavailable, so RepoRadar uses these as current demand and intent signals rather than a claimed volume ranking.
- what is deepseek harness · Google Suggest · US; English · checked 2026-10-03T22:26:28Z
Observed completions: what is deepseek harness, what is deepseek harness used for, what is deepseek harness github, what deepseek harness can do, what does deepseek harness do. A formulation signal captured at this time, not a volume or ranking claim. - deepseek harness · Google Suggest · US; English · checked 2026-10-03T22:26:28Z
Observed completions: deepseek harness desktop, deepseek harness github, deepseek harness plugins, deepseek harness agent, deepseek harness cli, deepseek harness vs pi, deepseek harness vs hermes, deepseek harness vs opencode, deepseek harness paper, deepseek harness vs claude code. A formulation signal captured at this time, not a volume or ranking claim. - is deepseek harness safe · Google Suggest · US; English · checked 2026-10-03T22:26:28Z
Observed completions: is deepseek harness safe. A formulation signal captured at this time, not a volume or ranking claim. - is deepseek harness free · Google Suggest · US; English · checked 2026-10-03T22:26:28Z
Observed completions: is deepseek harness free. A formulation signal captured at this time, not a volume or ranking claim. - stories with more than 50 points, trailing 48 hours · Hacker News Algolia search_by_date · global English-language developer community · checked 2026-10-03T22:26:06Z
Story 49929489, DeepSeek Harness Desktop for macOS and Windows (deepseek.com), created 2026-10-02T03:11Z, 405 points and 216 comments at check time. Interest signal, not search volume.
Who this helps
- developers and power users deciding whether to try DeepSeek Harness alongside other agent apps
- builders who want a plugin-based agent they can extend or embed through its Python SDK
- anyone who plans to run an agent on a machine that holds credentials, client files, or SSH keys
What DeepSeek Harness actually is
DeepSeek calls it an open-source agent harness. In plain terms it is the application around a model: the part that gives the model tools, keeps the conversation and plan, asks you for approval, and records what happened. Our answer on agent harnesses explains why that layer matters as much as the model.
The product page lists four kinds of work: everyday tasks such as organizing files, analyzing data, and drafting documents or slides; coding, including exploring repositories, fixing bugs, building features, and running tests; research with cited sources; and background tasks such as scripts and batch processing. A scheduled tasks plugin can run recurring work.
The design rule is that everything is a plugin, built on an open-source framework called Cordis. Tools, skills, and parts of the interface are all plugins, and a Creator mode lets the agent write a new plugin from a chat request. The latest release also adds an experimental compatibility layer for Claude Code plugins, which its release notes say is meant to test the idea rather than offer complete compatibility.
How you run it, and what it costs
There are two ways in. DeepSeek offers a desktop download, and the README shows a one-line start for the web version: install Node.js, then run npx @deepseek-ai/dsh web, which serves the interface on your own machine at 127.0.0.1 port 3080. You then add a workspace folder and a model before the chat box unlocks.
The software is free under the MIT license. The model is what costs money. The quickstart starts with a DeepSeek API key, and the model guide adds built-in providers such as Anthropic, OpenAI, Moonshot for Kimi, and Z.ai for GLM, plus a custom option for any gateway or self-hosted server that speaks the OpenAI or Anthropic API format. That custom option is how you would point it at a local model server. Sign-in style providers such as Codex are not supported yet. API keys are stored in a credentials file under the dsh home folder, and the settings page never displays them again after saving.
It is a preview. The README says, in capitals, that there will be compatibility-breaking changes. When we checked on October 3, 2026, the newest GitHub release was a prerelease tagged dsh-v0.2.1-alpha.1, and the npm latest tag pointed to 0.2.0-rc.2.
Is it safe? What its own safety notice says
DeepSeek is direct about this. The SAFETY file in the repository says DeepSeek Harness is experimental developer-preview software, has not undergone a security audit, and must not be treated as secure or production-ready. It says the project can run model-generated code and commands, load third-party plugins, and reach the network, processes, credentials, and files made available to it, and that bad model output, defects, misconfiguration, malicious input, or untrusted plugins may damage your computer, delete files, or disclose data or credentials.
Its advice is the standard advice for any local agent: run with the least access needed, prefer a disposable virtual machine, container, or dedicated environment, keep backups of anything it can touch, do not expose credentials you are not prepared to lose, and review plugins and proposed commands before letting them run. It also says not to rely on dsh as the only security control for untrusted workloads.
What its sandbox and approval prompts do and do not cover
dsh does ship guardrails. Its permission presets bundle a file sandbox mode with an approval policy. The default table offers workspace-write, where commands can write only inside your workspace and a temp area and the agent asks before going wider, and danger-full-access, which removes confinement and stops asking. An experimental auto-review option also exists.
The limits are in the documentation too. The sandbox modes govern file effects only; network access and process visibility are outside them. The enforcement backends are Linux bubblewrap and Landlock, macOS Seatbelt, and a Windows restricted-token runner, and the docs say the Windows runner and older Linux Landlock versions provide only partial enforcement. Installing a plugin package can run its build scripts. If you expose the web UI beyond your own machine, the printed URL carries a process credential and the backend speaks plain HTTP unless a proxy adds TLS.
That is a real step up from agents that ship no sandbox at all, such as Pi, whose documentation says so plainly. It is still not isolation. A prompt injection hidden in a file, web page, or plugin can try to use whatever network and file access the current mode allows, which is why the safety notice points you to a VM or container.
Who it suits, and who should wait
It suits developers and power users who want an agent app that does more than code, like the plugin model, and are comfortable running preview software in a throwaway environment. It also suits builders who want to extend an agent through plugins or drive it from the Python SDK.
Wait, or isolate it first, if you would run it on your main machine with production credentials, client data, or signing keys, if you need a stable interface that will not change under you, or if you want to leave it running unattended. RepoRadar has not run hands-on tests of DeepSeek Harness; this answer is based on its repository, documentation, and release notes, and we make no claim about its output quality.
Limits of this answer
Facts here come from the DeepSeek Harness product page, the deepseek-ai/deepseek-harness repository README, SAFETY file, LICENSE, permission-preset and sandbox documentation, the model configuration guide, and the release list, checked on October 3, 2026. The project is in preview and changes quickly, so check the current docs before relying on any detail, especially provider support and sandbox behavior on your operating system.
A useful next action
If you want to try it, start it inside a VM or container that holds a copy of one project and no real credentials beyond a spend-limited API key. Keep the workspace-write preset, read each approval before accepting, and install only plugins whose source you have looked at. Commit the project to git first so every change can be reviewed and rolled back.
Sources checked
- DeepSeek: DeepSeek Harness product page ↗ checked · vendor product page, global
States public preview worldwide and open source, the everything-is-a-plugin design on Cordis, desktop app or web UI, the everyday, coding, research, background task and plugin use cases, Creator mode, and the scheduled tasks plugin.
- GitHub: deepseek-ai/deepseek-harness README ↗ checked · public repository, global
MIT license per the API and LICENSE file, repository created 2026-08-13, developer preview with compatibility-breaking changes, npx @deepseek-ai/dsh web serving at 127.0.0.1:3080, and links to the safety notice.
- GitHub: deepseek-harness SAFETY.md ↗ checked · public repository, global
Experimental developer preview, no security audit, not secure or production-ready; can execute model-generated code and access network, processes, credentials and files; sandboxing does not guarantee isolation; recommends least privilege, disposable VM or container, backups, and plugin review.
- GitHub: deepseek-harness permission presets documentation ↗ checked · public repository, global
Default presets workspace-write (workspace-write sandbox plus ask) and danger-full-access (no confinement plus never), and the reserved experimental auto preset.
- GitHub: deepseek-harness process sandbox documentation ↗ checked · public repository, global
Sandbox modes cover file effects only, not network or process visibility; backends are Linux bwrap and Landlock, macOS Seatbelt and a Windows ACL restricted-token runner; partial enforcement on the Windows runner and older Landlock ABIs.
- DeepSeek Harness docs: Configure models ↗ checked · official documentation, global
DeepSeek API key setup, keys stored write-only in the dsh home credentials file, built-in third-party providers such as anthropic, openai, moonshotai and zai, custom OpenAI or Anthropic protocol endpoints for gateways or self-hosted servers, and no OAuth providers such as Codex yet.
- DeepSeek Harness docs: Publish the Web UI behind a reverse proxy ↗ checked · official documentation, global
The web UI listens over plain HTTP on loopback, the printed URL carries a process credential, and TLS must be terminated at a proxy.
- GitHub: deepseek-harness releases ↗ checked · public repository, global
Newest release dsh-v0.2.1-alpha.1 published 2026-10-03 as a prerelease, with an experimental Claude Code Mods compatibility layer and a Let Agent create a plugin entry.
RepoRadar separates factual source claims from analysis. Recheck vendor docs before purchase, deployment, or policy decisions.