DeepSeek Harness is DeepSeek’s open-source AI agent. It ships as a desktop app, web UI, command line and Python SDK, and every part of it, down to the agent loop, is a swappable plugin. DeepSeek posted its public page on September 30, 2026. On October 2 its main account announced packaged apps for macOS and Windows, and the launch post has passed 958,000 views on X. It is MIT-licensed and in developer preview, and its own safety notice says it has not had a security audit. This page reads it from DeepSeek’s repository, site and release notes as of October 4, 2026.
On this page · 10 sectionsOpen
- DeepSeek Harness (dsh) is DeepSeek’s open-source AI agent: a desktop app, web UI, command line and Python SDK, MIT-licensed and in developer preview as of October 4, 2026.
- Every part is a plugin, including the model adapter, tool registry, session log and agent loop, on DeepSeek’s Cordis framework; Creator mode writes new plugins from chat.
- DeepSeek posted its public page on September 30, 2026, and its main account announced packaged macOS and Windows apps on October 2. The launch post has passed 958,000 views on X.
- It runs DeepSeek models by default and Anthropic, OpenAI, Kimi or GLM models with your own key; OAuth sign-ins such as Codex are not supported yet.
- On October 3 it added an experimental Claude Code Mods compatibility layer, which DeepSeek says exists to show mods are broadly a subset of its plugins, not to give full compatibility.
- Its own SAFETY.md says it has not had a security audit, is not production-ready, and should run in a disposable VM or container with least privileges.
§ 01What it is
| Question | Answer | Source |
|---|---|---|
| Who makes it | DeepSeek AI | Repository README |
| Short name | dsh; one command starts the web UI: npx @deepseek-ai/dsh web | Repository README |
| License | MIT | GitHub |
| Status | Developer preview; all 25 GitHub releases are marked pre-release | GitHub releases |
| Surfaces | Desktop for macOS (Apple silicon) and Windows (64-bit), web UI, command line, Python SDK, ACP | deepseek.com/harness, CLI README |
| Architecture | Everything is a plugin, on DeepSeek’s Cordis framework | Architecture doc |
| Models | DeepSeek by default; Anthropic, OpenAI, Kimi and GLM with your key; any compatible custom endpoint | Models guide |
| Adoption | 243,198 GitHub stars and 29,151 forks | GitHub API, Oct 4 |
§ 02Everything is a plugin
The design is the product. DeepSeek’s architecture document puts it plainly: “Every part of the product is a plugin, including the model adapter, the tool registry, the session log, and the agent loop itself, so each is replaceable from configuration.” The same document adds: “There is no privileged core to patch”.
Under it sits Cordis, a framework DeepSeek describes in an August 26 arXiv paper, “A Programming Paradigm for Spatiotemporal Composability”. In plain terms, a plugin can be loaded and unloaded while the agent runs, and whatever it registered is undone when it leaves.
You do not have to write the plugins yourself. DeepSeek’s launch page says you can “Install plugins, or create them through chat in “Creator mode”, to extend tools, skills, and the interface.” Its demo builds a floating Pomodoro timer that way. The official plugin list on that page includes Agent teams, Auto approval review, Scheduled tasks and Voice input, each marked Experimental, alongside Terminal, Agent loop and Subagents.
§ 03What shipped, dated
| Date (UTC) | What | Source |
|---|---|---|
| August 13 | GitHub repository created | GitHub API |
| August 26 | Cordis paper posted to arXiv | arXiv 2608.25512 |
| September 28 | v0.2.0-rc.1: first 0.2 candidate; DeepSeek-account sessions get web search with no extra API key | Release notes |
| September 29 | v0.2.0-rc.2: the dsh command bundled with the macOS and Windows apps | Release notes |
| September 30, 16:13 | @DeepSeekHarness posts the launch page | X, 958,194 views |
| October 2, 07:00 | @deepseek_ai announces packaged desktop apps | X, 420,132 views |
| October 3, 06:42 | v0.2.1-alpha.1: experimental Claude Code Mods compatibility layer | Release notes |
DeepSeek’s main account put it in one line on October 2: “We just released packaged desktop versions for macOS and Windows”. Linux users install the npm package instead.
§ 04The Claude Code Mods layer
Two days after Anthropic opened Claude Code to mods, DeepSeek shipped a compatibility layer for them in v0.2.1-alpha.1. The release note is candid about the aim: “At this stage, the main goal is to verify that the Claude Code Mods API’s capabilities are broadly a subset of what DeepSeek Harness plugins can do, rather than to offer users complete, practical compatibility.”
So the layer is a statement about design, not a way to run your Claude Code mods today. The same release added a “Let Agent create a plugin” entry to plugin management, which opens Creator mode from there.
§ 05Which models it runs
DeepSeek’s own models come first: the models guide has you paste a DeepSeek API key in Settings. Third-party providers ship in its catalog, with ids such as anthropic, openai, moonshotai for Kimi and zai for GLM. A custom model API accepts any endpoint that speaks OpenAI Chat Completions, OpenAI Responses or Anthropic Messages. One gap: “Providers that sign in with OAuth, such as Codex, are not supported here yet.”
The session picker in DeepSeek’s demo shows its newest model, DeepSeek V4.1 Flash. The harness itself is free under MIT; the model calls are billed by whichever provider you configure.
§ 06What its own safety notice says
DeepSeek’s SAFETY.md is unusually direct. “It has not undergone a security audit and must not be treated as secure or production-ready.” It lists what can go wrong when the agent runs model-generated code and loads third-party plugins, and it says: “Sandboxing, approval prompts, and permission controls can reduce risk, but they do not guarantee isolation or prevent damage.”
Its advice: run with the least privileges needed, prefer a disposable virtual machine or container, keep backups, and review plugins and proposed commands before allowing them to run. The README adds a warning in capitals: “THERE WILL BE COMPATIBILITY-BREAKING CHANGES.”
§ 07How it compares
| DeepSeek Harness | Claude Code | CellCog | |
|---|---|---|---|
| Where it runs | Your machine: desktop, web UI, command line, Python SDK | Your terminal and the Claude desktop app | CellCog’s cloud; each AI employee has its own secure VM, file system, browser identity and logins |
| How you extend it | Plugins on Cordis; Creator mode writes them from chat | Mods, plugins, hooks, skills and MCP servers | Tools, 1,500+ app connectors and skills |
| Models | DeepSeek by default; Anthropic, OpenAI, Kimi, GLM or a custom endpoint | Anthropic’s Claude models | Claude Opus 5.5 on every tier |
| What its own docs warn | No security audit; not production-ready | A mod runs with your permissions and is not sandboxed | Commands that reach your world pass approval thresholds you set |
| Price of the harness | Free, MIT | Included with Claude plans | Plans from $8 a month; you pay for the work |
DeepSeek Harness is the most open of the three and the youngest. It suits developers who want to own every layer and can sandbox it themselves. Our agent harness ranking has the full field.
§ 08What we are watching
- A stable, non-pre-release 0.2 build, which would end the developer-preview label.
- An independent security review, the gap SAFETY.md names itself.
- Support for DeepSeek’s next model; our DeepSeek V5 tracker follows the release.
- Whether the Claude Code Mods layer grows from a proof into real compatibility.
§ 09The record
As of October 4, 2026, 13:10 UTC: page opened. Star, fork and release counts were read from the GitHub API at that time; X view counts were read in a browser at 13:05 UTC and each post time computed from its ID. The README, SAFETY.md, architecture doc, models guide and release notes were read from DeepSeek’s repository; the launch page on deepseek.com; the Cordis paper on arXiv.
§ 10Sources
- DeepSeek, DeepSeek Harness repository, README, SAFETY.md, architecture and models guide.
- DeepSeek, release notes, v0.2.0-rc.1, v0.2.0-rc.2 and v0.2.1-alpha.1.
- DeepSeek, DeepSeek Harness launch page.
- A Programming Paradigm for Spatiotemporal Composability, arXiv, August 26, 2026.
- @DeepSeekHarness on X, September 30, 2026; @deepseek_ai on X, October 2, 2026.
- Our records on Claude Code mods and the agent harness ranking.
Q1How do I install DeepSeek Harness?
Download the desktop app for macOS (Apple silicon) or Windows (64-bit) from deepseek.com/harness, or run npx @deepseek-ai/dsh web with Node.js installed to start the web UI. Linux users install the npm package. A Python SDK installs with pip install deepseek-harness-sdk.
Q2Which models does DeepSeek Harness support?
DeepSeek’s models with a DeepSeek API key, plus catalog providers including Anthropic, OpenAI, Kimi and GLM with your own key, and any custom endpoint that speaks OpenAI Chat Completions, OpenAI Responses or Anthropic Messages. Providers that sign in with OAuth, such as Codex, are not supported yet.
Q3Does DeepSeek Harness run Claude Code mods?
Not in practice yet. Version 0.2.1-alpha.1 added an experimental compatibility layer, but DeepSeek says its main goal is to verify that the Mods API is broadly a subset of its plugins, rather than to offer complete, practical compatibility.
Q4Is DeepSeek Harness production-ready?
No, by DeepSeek’s own account. Every GitHub release is marked pre-release, the README warns of compatibility-breaking changes, and SAFETY.md says it has not undergone a security audit.
Q5Does CellCog use DeepSeek Harness?
No. CellCog runs its own harness, with every tier on Anthropic’s Claude Opus 5.5, and each AI employee works in its own secure VM with its own file system, browser identity and logins. We track DeepSeek because many of our readers build with it.
