Skip to content
AI EmployeeSuper-AgentsAgent-to-AgentTutorialsPricingBlogContact

What Is DeepSeek Harness? The Open Agent, Explained

At a glanceQuick answers
What is DeepSeek Harness?
DeepSeek’s open-source AI agent, called dsh, that runs on your own computer as a desktop app, web UI, command line or Python SDK. Every part of it is a plugin.
Is DeepSeek Harness free?
The harness is free under the MIT license. Model calls are billed by the provider you configure, such as DeepSeek’s API.
Is it safe to run?
DeepSeek’s own notice says it has not been security audited and is not production-ready. It recommends a disposable VM or container and least privileges.
Data illustration on off-white paper: a teal power strip labelled dsh with five plug modules reading Creator mode, Scheduled tasks, Agent teams, Voice input and, in amber, Claude Code Mods layer, cabled to a laptop and a desktop window, with the number 243K and the caption GitHub stars, Oct 4, and a tag reading MIT, public preview
Fig 0One power strip, many plugs: in DeepSeek Harness every part is a plugin. Made by CellCog's image agent, running GPT Image 2.5.

DeepSeek Harness is DeepSeek’s open-source AI agent. It ships as a desktop app, web UI, command line and Python SDK, and every part of it, down to the agent loop, is a swappable plugin. DeepSeek posted its public page on September 30, 2026. On October 2 its main account announced packaged apps for macOS and Windows, and the launch post has passed 958,000 views on X. It is MIT-licensed and in developer preview, and its own safety notice says it has not had a security audit. This page reads it from DeepSeek’s repository, site and release notes as of October 4, 2026.

On this page · 10 sectionsOpen
  1. What it is
  2. Everything is a plugin
  3. What shipped, dated
  4. The Claude Code Mods layer
  5. Which models it runs
  6. What its own safety notice says
  7. How it compares
  8. What we are watching
  9. The record
  10. Sources
Key points6 · 8 min full read
  1. DeepSeek Harness (dsh) is DeepSeek’s open-source AI agent: a desktop app, web UI, command line and Python SDK, MIT-licensed and in developer preview as of October 4, 2026.
  2. Every part is a plugin, including the model adapter, tool registry, session log and agent loop, on DeepSeek’s Cordis framework; Creator mode writes new plugins from chat.
  3. DeepSeek posted its public page on September 30, 2026, and its main account announced packaged macOS and Windows apps on October 2. The launch post has passed 958,000 views on X.
  4. It runs DeepSeek models by default and Anthropic, OpenAI, Kimi or GLM models with your own key; OAuth sign-ins such as Codex are not supported yet.
  5. On October 3 it added an experimental Claude Code Mods compatibility layer, which DeepSeek says exists to show mods are broadly a subset of its plugins, not to give full compatibility.
  6. Its own SAFETY.md says it has not had a security audit, is not production-ready, and should run in a disposable VM or container with least privileges.

§ 01What it is

Question Answer Source
Who makes it DeepSeek AI Repository README
Short name dsh; one command starts the web UI: npx @deepseek-ai/dsh web Repository README
License MIT GitHub
Status Developer preview; all 25 GitHub releases are marked pre-release GitHub releases
Surfaces Desktop for macOS (Apple silicon) and Windows (64-bit), web UI, command line, Python SDK, ACP deepseek.com/harness, CLI README
Architecture Everything is a plugin, on DeepSeek’s Cordis framework Architecture doc
Models DeepSeek by default; Anthropic, OpenAI, Kimi and GLM with your key; any compatible custom endpoint Models guide
Adoption 243,198 GitHub stars and 29,151 forks GitHub API, Oct 4
Table 1DeepSeek Harness, read on October 4, 2026

§ 02Everything is a plugin

The design is the product. DeepSeek’s architecture document puts it plainly: “Every part of the product is a plugin, including the model adapter, the tool registry, the session log, and the agent loop itself, so each is replaceable from configuration.” The same document adds: “There is no privileged core to patch”.

Under it sits Cordis, a framework DeepSeek describes in an August 26 arXiv paper, “A Programming Paradigm for Spatiotemporal Composability”. In plain terms, a plugin can be loaded and unloaded while the agent runs, and whatever it registered is undone when it leaves.

You do not have to write the plugins yourself. DeepSeek’s launch page says you can “Install plugins, or create them through chat in “Creator mode”, to extend tools, skills, and the interface.” Its demo builds a floating Pomodoro timer that way. The official plugin list on that page includes Agent teams, Auto approval review, Scheduled tasks and Voice input, each marked Experimental, alongside Terminal, Agent loop and Subagents.

§ 03What shipped, dated

Date (UTC) What Source
August 13 GitHub repository created GitHub API
August 26 Cordis paper posted to arXiv arXiv 2608.25512
September 28 v0.2.0-rc.1: first 0.2 candidate; DeepSeek-account sessions get web search with no extra API key Release notes
September 29 v0.2.0-rc.2: the dsh command bundled with the macOS and Windows apps Release notes
September 30, 16:13 @DeepSeekHarness posts the launch page X, 958,194 views
October 2, 07:00 @deepseek_ai announces packaged desktop apps X, 420,132 views
October 3, 06:42 v0.2.1-alpha.1: experimental Claude Code Mods compatibility layer Release notes
Table 2The DeepSeek Harness line, August to October 2026, X times read from post IDs
Public page on Sep 30, desktop apps announced Oct 2, Mods layer on Oct 3.Timeline from the August 13 repository through the August 26 Cordis paper, the September 28 release candidate, the September 30 public launch highlighted, the October 2 desktop announcement and the October 3 Mods compatibility alphaAug 13Repository createdAug 26Cordis paperSep 28v0.2.0 candidateSep 30Public launch pageOct 2Desktop apps announcedOct 3Mods layer alphaPublic page on Sep 30, desktop apps announced Oct 2, Mods layer on Oct 3.Timeline from the August 13 repository through the August 26 Cordis paper, the September 28 release candidate, the September 30 public launch highlighted, the October 2 desktop announcement and the October 3 Mods compatibility alphaAug 13Repository createdAug 26Cordis paperSep 28v0.2.0 candidateSep 30Public launch pageOct 2Desktop apps announcedOct 3Mods layer alpha
Fig 1Public page on Sep 30, desktop apps announced Oct 2, Mods layer on Oct 3.

DeepSeek’s main account put it in one line on October 2: “We just released packaged desktop versions for macOS and Windows”. Linux users install the npm package instead.

§ 04The Claude Code Mods layer

Two days after Anthropic opened Claude Code to mods, DeepSeek shipped a compatibility layer for them in v0.2.1-alpha.1. The release note is candid about the aim: “At this stage, the main goal is to verify that the Claude Code Mods API’s capabilities are broadly a subset of what DeepSeek Harness plugins can do, rather than to offer users complete, practical compatibility.”

So the layer is a statement about design, not a way to run your Claude Code mods today. The same release added a “Let Agent create a plugin” entry to plugin management, which opens Creator mode from there.

§ 05Which models it runs

DeepSeek’s own models come first: the models guide has you paste a DeepSeek API key in Settings. Third-party providers ship in its catalog, with ids such as anthropic, openai, moonshotai for Kimi and zai for GLM. A custom model API accepts any endpoint that speaks OpenAI Chat Completions, OpenAI Responses or Anthropic Messages. One gap: “Providers that sign in with OAuth, such as Codex, are not supported here yet.”

The session picker in DeepSeek’s demo shows its newest model, DeepSeek V4.1 Flash. The harness itself is free under MIT; the model calls are billed by whichever provider you configure.

§ 06What its own safety notice says

DeepSeek’s SAFETY.md is unusually direct. “It has not undergone a security audit and must not be treated as secure or production-ready.” It lists what can go wrong when the agent runs model-generated code and loads third-party plugins, and it says: “Sandboxing, approval prompts, and permission controls can reduce risk, but they do not guarantee isolation or prevent damage.”

Its advice: run with the least privileges needed, prefer a disposable virtual machine or container, keep backups, and review plugins and proposed commands before allowing them to run. The README adds a warning in capitals: “THERE WILL BE COMPATIBILITY-BREAKING CHANGES.”

§ 07How it compares

DeepSeek Harness Claude Code CellCog
Where it runs Your machine: desktop, web UI, command line, Python SDK Your terminal and the Claude desktop app CellCog’s cloud; each AI employee has its own secure VM, file system, browser identity and logins
How you extend it Plugins on Cordis; Creator mode writes them from chat Mods, plugins, hooks, skills and MCP servers Tools, 1,500+ app connectors and skills
Models DeepSeek by default; Anthropic, OpenAI, Kimi, GLM or a custom endpoint Anthropic’s Claude models Claude Opus 5.5 on every tier
What its own docs warn No security audit; not production-ready A mod runs with your permissions and is not sandboxed Commands that reach your world pass approval thresholds you set
Price of the harness Free, MIT Included with Claude plans Plans from $8 a month; you pay for the work
Table 3Where three agent harnesses run and how they extend, read October 4, 2026

DeepSeek Harness is the most open of the three and the youngest. It suits developers who want to own every layer and can sandbox it themselves. Our agent harness ranking has the full field.

§ 08What we are watching

  • A stable, non-pre-release 0.2 build, which would end the developer-preview label.
  • An independent security review, the gap SAFETY.md names itself.
  • Support for DeepSeek’s next model; our DeepSeek V5 tracker follows the release.
  • Whether the Claude Code Mods layer grows from a proof into real compatibility.

§ 09The record

As of October 4, 2026, 13:10 UTC: page opened. Star, fork and release counts were read from the GitHub API at that time; X view counts were read in a browser at 13:05 UTC and each post time computed from its ID. The README, SAFETY.md, architecture doc, models guide and release notes were read from DeepSeek’s repository; the launch page on deepseek.com; the Cordis paper on arXiv.

§ 10Sources

Frequently asked5 questions

Q1How do I install DeepSeek Harness?

Download the desktop app for macOS (Apple silicon) or Windows (64-bit) from deepseek.com/harness, or run npx @deepseek-ai/dsh web with Node.js installed to start the web UI. Linux users install the npm package. A Python SDK installs with pip install deepseek-harness-sdk.

Q2Which models does DeepSeek Harness support?

DeepSeek’s models with a DeepSeek API key, plus catalog providers including Anthropic, OpenAI, Kimi and GLM with your own key, and any custom endpoint that speaks OpenAI Chat Completions, OpenAI Responses or Anthropic Messages. Providers that sign in with OAuth, such as Codex, are not supported yet.

Q3Does DeepSeek Harness run Claude Code mods?

Not in practice yet. Version 0.2.1-alpha.1 added an experimental compatibility layer, but DeepSeek says its main goal is to verify that the Mods API is broadly a subset of its plugins, rather than to offer complete, practical compatibility.

Q4Is DeepSeek Harness production-ready?

No, by DeepSeek’s own account. Every GitHub release is marked pre-release, the README warns of compatibility-breaking changes, and SAFETY.md says it has not undergone a security audit.

Q5Does CellCog use DeepSeek Harness?

No. CellCog runs its own harness, with every tier on Anthropic’s Claude Opus 5.5, and each AI employee works in its own secure VM with its own file system, browser identity and logins. We track DeepSeek because many of our readers build with it.

Published 04 October 2026 All Choosing a platform →