# What Is DeepSeek Harness? The Open Agent, Explained

> DeepSeek Harness is DeepSeek's open-source, plugin-based AI agent, now on macOS and Windows. What it does, which models it runs, and its safety notes.

- Author: Nitish Garg, Founder & CEO, CellCog
- Published: 2026-10-04
- Canonical (HTML): https://cellcog.ai/blog/what-is-deepseek-harness/
- Section: Guides / Choosing a platform
- Publisher: CellCog (https://cellcog.ai), the AI employee platform. Blog index for agents: https://cellcog.ai/blog/llms.txt

## Key points

- DeepSeek Harness (dsh) is DeepSeek's open-source AI agent: a desktop app, web UI, command line and Python SDK, MIT-licensed and in developer preview as of October 4, 2026.
- Every part is a plugin, including the model adapter, tool registry, session log and agent loop, on DeepSeek's Cordis framework; Creator mode writes new plugins from chat.
- DeepSeek posted its public page on September 30, 2026, and its main account announced packaged macOS and Windows apps on October 2. The launch post has passed 958,000 views on X.
- It runs DeepSeek models by default and Anthropic, OpenAI, Kimi or GLM models with your own key; OAuth sign-ins such as Codex are not supported yet.
- On October 3 it added an experimental Claude Code Mods compatibility layer, which DeepSeek says exists to show mods are broadly a subset of its plugins, not to give full compatibility.
- Its own SAFETY.md says it has not had a security audit, is not production-ready, and should run in a disposable VM or container with least privileges.

## At a glance

- **What is DeepSeek Harness?** DeepSeek's open-source AI agent, called dsh, that runs on your own computer as a desktop app, web UI, command line or Python SDK. Every part of it is a plugin.
- **Is DeepSeek Harness free?** The harness is free under the MIT license. Model calls are billed by the provider you configure, such as DeepSeek's API.
- **Is it safe to run?** DeepSeek's own notice says it has not been security audited and is not production-ready. It recommends a disposable VM or container and least privileges.

**DeepSeek Harness is DeepSeek's open-source AI agent. It ships as a desktop app, web UI, command line and Python SDK, and every part of it, down to the agent loop, is a swappable plugin.** DeepSeek posted its public page on September 30, 2026. On October 2 its main account announced packaged apps for macOS and Windows, and the launch post has passed 958,000 views on X. It is MIT-licensed and in developer preview, and its own safety notice says it has not had a security audit. This page reads it from DeepSeek's repository, site and release notes as of October 4, 2026.

## What it is

*Table: DeepSeek Harness, read on October 4, 2026*

| Question | Answer | Source |
|---|---|---|
| Who makes it | DeepSeek AI | Repository README |
| Short name | dsh; one command starts the web UI: npx @deepseek-ai/dsh web | Repository README |
| License | MIT | GitHub |
| Status | Developer preview; all 25 GitHub releases are marked pre-release | GitHub releases |
| Surfaces | Desktop for macOS (Apple silicon) and Windows (64-bit), web UI, command line, Python SDK, ACP | deepseek.com/harness, CLI README |
| Architecture | Everything is a plugin, on DeepSeek's Cordis framework | Architecture doc |
| Models | DeepSeek by default; Anthropic, OpenAI, Kimi and GLM with your key; any compatible custom endpoint | Models guide |
| Adoption | 243,198 GitHub stars and 29,151 forks | GitHub API, Oct 4 |

## Everything is a plugin

The design is the product. DeepSeek's [architecture document](https://github.com/deepseek-ai/deepseek-harness/blob/master/docs/architecture.md) puts it plainly: "Every part of the product is a plugin, including the model adapter, the tool registry, the session log, and the agent loop itself, so each is replaceable from configuration." The same document adds: "There is no privileged core to patch".

Under it sits Cordis, a framework DeepSeek describes in an [August 26 arXiv paper](https://arxiv.org/abs/2608.25512), "A Programming Paradigm for Spatiotemporal Composability". In plain terms, a plugin can be loaded and unloaded while the agent runs, and whatever it registered is undone when it leaves.

You do not have to write the plugins yourself. DeepSeek's [launch page](https://www.deepseek.com/en/harness/) says you can "Install plugins, or create them through chat in “Creator mode”, to extend tools, skills, and the interface." Its demo builds a floating Pomodoro timer that way. The official plugin list on that page includes Agent teams, Auto approval review, Scheduled tasks and Voice input, each marked Experimental, alongside Terminal, Agent loop and Subagents.

## What shipped, dated

*Table: The DeepSeek Harness line, August to October 2026, X times read from post IDs*

| Date (UTC) | What | Source |
|---|---|---|
| August 13 | GitHub repository created | GitHub API |
| August 26 | Cordis paper posted to arXiv | arXiv 2608.25512 |
| September 28 | v0.2.0-rc.1: first 0.2 candidate; DeepSeek-account sessions get web search with no extra API key | Release notes |
| September 29 | v0.2.0-rc.2: the dsh command bundled with the macOS and Windows apps | Release notes |
| September 30, 16:13 | @DeepSeekHarness posts the launch page | X, 958,194 views |
| October 2, 07:00 | @deepseek_ai announces packaged desktop apps | X, 420,132 views |
| October 3, 06:42 | v0.2.1-alpha.1: experimental Claude Code Mods compatibility layer | Release notes |

DeepSeek's main account put it in one line on [October 2](https://x.com/i/status/2105915715241062644): "We just released packaged desktop versions for macOS and Windows". Linux users install the npm package instead.

## The Claude Code Mods layer

Two days after Anthropic [opened Claude Code to mods](https://cellcog.ai/blog/claude-code-mods/), DeepSeek shipped a compatibility layer for them in [v0.2.1-alpha.1](https://github.com/deepseek-ai/deepseek-harness/releases). The release note is candid about the aim: "At this stage, the main goal is to verify that the Claude Code Mods API's capabilities are broadly a subset of what DeepSeek Harness plugins can do, rather than to offer users complete, practical compatibility."

So the layer is a statement about design, not a way to run your Claude Code mods today. The same release added a "Let Agent create a plugin" entry to plugin management, which opens Creator mode from there.

## Which models it runs

DeepSeek's own models come first: the [models guide](https://github.com/deepseek-ai/deepseek-harness/blob/master/docs/user/guide/providers.md) has you paste a DeepSeek API key in Settings. Third-party providers ship in its catalog, with ids such as anthropic, openai, moonshotai for Kimi and zai for GLM. A custom model API accepts any endpoint that speaks OpenAI Chat Completions, OpenAI Responses or Anthropic Messages. One gap: "Providers that sign in with OAuth, such as Codex, are not supported here yet."

The session picker in DeepSeek's demo shows its newest model, [DeepSeek V4.1 Flash](https://cellcog.ai/blog/deepseek-v4-1-flash-release-date/). The harness itself is free under MIT; the model calls are billed by whichever provider you configure.

## What its own safety notice says

DeepSeek's [SAFETY.md](https://github.com/deepseek-ai/deepseek-harness/blob/master/SAFETY.md) is unusually direct. "It has not undergone a security audit and must not be treated as secure or production-ready." It lists what can go wrong when the agent runs model-generated code and loads third-party plugins, and it says: "Sandboxing, approval prompts, and permission controls can reduce risk, but they do not guarantee isolation or prevent damage."

Its advice: run with the least privileges needed, prefer a disposable virtual machine or container, keep backups, and review plugins and proposed commands before allowing them to run. The README adds a warning in capitals: "THERE WILL BE COMPATIBILITY-BREAKING CHANGES."

## How it compares

*Table: Where three agent harnesses run and how they extend, read October 4, 2026*

| | DeepSeek Harness | Claude Code | CellCog |
|---|---|---|---|
| Where it runs | Your machine: desktop, web UI, command line, Python SDK | Your terminal and the Claude desktop app | CellCog's cloud; each AI employee has its own secure VM, file system, browser identity and logins |
| How you extend it | Plugins on Cordis; Creator mode writes them from chat | Mods, plugins, hooks, skills and MCP servers | Tools, 1,500+ app connectors and skills |
| Models | DeepSeek by default; Anthropic, OpenAI, Kimi, GLM or a custom endpoint | Anthropic's Claude models | Claude Opus 5.5 on every tier |
| What its own docs warn | No security audit; not production-ready | A mod runs with your permissions and is not sandboxed | Commands that reach your world pass approval thresholds you set |
| Price of the harness | Free, MIT | Included with Claude plans | Plans from $8 a month; you pay for the work |

DeepSeek Harness is the most open of the three and the youngest. It suits developers who want to own every layer and can sandbox it themselves. Our [agent harness ranking](https://cellcog.ai/blog/best-ai-agent-harnesses/) has the full field.

## What we are watching

- A stable, non-pre-release 0.2 build, which would end the developer-preview label.
- An independent security review, the gap SAFETY.md names itself.
- Support for DeepSeek's next model; our [DeepSeek V5 tracker](https://cellcog.ai/blog/deepseek-v5-release-date/) follows the release.
- Whether the Claude Code Mods layer grows from a proof into real compatibility.

## The record

As of October 4, 2026, 13:10 UTC: page opened. Star, fork and release counts were read from the GitHub API at that time; X view counts were read in a browser at 13:05 UTC and each post time computed from its ID. The README, SAFETY.md, architecture doc, models guide and release notes were read from DeepSeek's repository; the launch page on deepseek.com; the Cordis paper on arXiv.

## Sources

- DeepSeek, [DeepSeek Harness repository](https://github.com/deepseek-ai/deepseek-harness), README, [SAFETY.md](https://github.com/deepseek-ai/deepseek-harness/blob/master/SAFETY.md), [architecture](https://github.com/deepseek-ai/deepseek-harness/blob/master/docs/architecture.md) and [models guide](https://github.com/deepseek-ai/deepseek-harness/blob/master/docs/user/guide/providers.md).
- DeepSeek, [release notes](https://github.com/deepseek-ai/deepseek-harness/releases), v0.2.0-rc.1, v0.2.0-rc.2 and v0.2.1-alpha.1.
- DeepSeek, [DeepSeek Harness launch page](https://www.deepseek.com/en/harness/).
- [A Programming Paradigm for Spatiotemporal Composability](https://arxiv.org/abs/2608.25512), arXiv, August 26, 2026.
- @DeepSeekHarness on X, [September 30, 2026](https://x.com/i/status/2105330281389662575); @deepseek_ai on X, [October 2, 2026](https://x.com/i/status/2105915715241062644).
- Our records on [Claude Code mods](https://cellcog.ai/blog/claude-code-mods/) and the [agent harness ranking](https://cellcog.ai/blog/best-ai-agent-harnesses/).

## FAQ

**How do I install DeepSeek Harness?**

Download the desktop app for macOS (Apple silicon) or Windows (64-bit) from deepseek.com/harness, or run npx @deepseek-ai/dsh web with Node.js installed to start the web UI. Linux users install the npm package. A Python SDK installs with pip install deepseek-harness-sdk.

**Which models does DeepSeek Harness support?**

DeepSeek's models with a DeepSeek API key, plus catalog providers including Anthropic, OpenAI, Kimi and GLM with your own key, and any custom endpoint that speaks OpenAI Chat Completions, OpenAI Responses or Anthropic Messages. Providers that sign in with OAuth, such as Codex, are not supported yet.

**Does DeepSeek Harness run Claude Code mods?**

Not in practice yet. Version 0.2.1-alpha.1 added an experimental compatibility layer, but DeepSeek says its main goal is to verify that the Mods API is broadly a subset of its plugins, rather than to offer complete, practical compatibility.

**Is DeepSeek Harness production-ready?**

No, by DeepSeek's own account. Every GitHub release is marked pre-release, the README warns of compatibility-breaking changes, and SAFETY.md says it has not undergone a security audit.

**Does CellCog use DeepSeek Harness?**

No. CellCog runs its own harness, with every tier on Anthropic's Claude Opus 5.5, and each AI employee works in its own secure VM with its own file system, browser identity and logins. We track DeepSeek because many of our readers build with it.

## Related

- [Best AI Agent Harnesses: October 2026 Rankings](https://cellcog.ai/blog/best-ai-agent-harnesses/index.md)
- [Claude Code Mods: What They Can Do and What They Can Reach](https://cellcog.ai/blog/claude-code-mods/index.md)
- [DeepSeek V4.1 Flash: Price, Specs, and the Rumor Scorecard](https://cellcog.ai/blog/deepseek-v4-1-flash-release-date/index.md)
- [DeepSeek V5 Release Date: The Leak vs the Record](https://cellcog.ai/blog/deepseek-v5-release-date/index.md)

## The AI employee for this read

[AI Software Engineer](https://cellcog.ai/ai-employees/ai-software-engineer): I built this page. For what it covers, hire an engineer: it works in your repo behind an approval gate, so nothing reaches your world unclassified.

---

Markdown alternate of https://cellcog.ai/blog/what-is-deepseek-harness/. Try CellCog free, no credit card needed: https://cellcog.ai/signup
