Open-source project
deepseek-ai/deepseek-harness avatar
deepseek-ai/deepseek-harness

DeepSeek Harness: an agent harness where everything is a plugin

DeepSeek Harness: Everything is a Plugin.

239,890 stars28,805 forksTypeScriptMIT

At a glance

What is it?
DeepSeek Harness (dsh) is a TypeScript agent harness from DeepSeek AI built on the Cordis plugin kernel. It ships as a developer preview, so the interesting question is not what it does today but how much of it you can replace without forking.
Who is it for?
Adopt DeepSeek Harness if you want an agent runtime whose parts are plugins you can swap, and you accept a developer preview that the README says will break compatibility. Do not adopt it if you need a stable API surface for a product you ship this quarter, or if you cannot read TypeScript and the Cordis plugin model to debug it.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository received new commits within the last day.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

DEEP OPEN-SOURCE ANALYSIS

What DeepSeek Harness solves, and who it is actually for

Most agent frameworks give you a fixed loop: a prompt template, a tool registry, a memory store, a UI. You can configure them, but replacing the loop itself usually means forking. DeepSeek Harness takes the opposite position, stated in its own tagline: everything is a plugin. The harness is the host, and the parts that make it an agent are plugins loaded into that host.

That matters for a specific kind of user. If you are building an agent product and you disagree with one layer of an existing framework, dsh lets you replace that layer rather than abandon the framework. The README points plugin authors at the dsh-plugin GitHub topic for discoverability, which tells you the intended workflow is publishing and consuming plugins, not patching the core.

It is not aimed at someone who wants a finished assistant. There is no promise of a curated plugin marketplace, and the README spends its length on running the thing and on contribution mechanics, not on a feature tour. The audience is engineers who are comfortable reading TypeScript and who treat the harness as a substrate.

The Cordis plugin kernel underneath dsh

The architecture rests on Cordis, a plugin framework whose design the README attributes to a paper titled A Programming Paradigm for Spatiotemporal Composability. That citation is the clearest signal about the design intent: the project is not treating plugins as an extension point bolted onto a monolith, but as the composition model itself.

The practical consequence is visible in the repository layout. There is a packages/ directory with a nested workspace pattern (packages/*/*), plus apps/, native/, vendor/, and python/. The root package.json declares pnpm workspaces across vendor/*, packages/*/*, native/system, native/system/packages/*, apps/*, and website. So the harness is not one package pretending to be modular; it is a monorepo where the host, the client, the web frontend, and a desktop app are separate workspace packages.

The build reflects that split. There are distinct TypeScript project files for host and client (tsconfig.host.json, tsconfig.client.json), and the build scripts pass a DSH_BUILD_FACE environment variable of either host or client to tsdown. In other words, the same source tree is compiled into two faces. If you plan to write a plugin, knowing which face it belongs to is the first architectural decision you make, and the README does not walk you through it.

Installing dsh and getting the Web UI running

The README gives two paths. The short one needs only Node.js installed, and it runs the published package directly. The command starts a Web UI and, for a local launch, opens it in your default browser at the address shown below.

bash
npx @deepseek-ai/dsh web

The README states the default address is http://127.0.0.1:3080. Two behaviours are worth knowing before you run it. On an SSH launch, the command only prints the host URL, because the SSH client or editor owns the local forwarded address, so nothing opens automatically. And if you want the server without a browser window, pass the flag the README documents:

bash
npx @deepseek-ai/dsh web --no-open

If you would rather run from a checkout, the README gives a four-step sequence. The build step produces the artifacts, and the final command uses those artifacts without rebuilding.

bash
git clone https://github.com/deepseek-ai/deepseek-harness.git
cd deepseek-harness
pnpm install
pnpm run build
pnpm dsh web

One constraint to check first: the root package.json sets engines to node ^22.19.0 || >=24.0.0, and pins packageManager to [email protected]. An older Node release will not satisfy the engine range. The README does not document a rollback path if a preview release misbehaves, so pinning the version you install is your own responsibility.

The developer preview warning is the most important line in the README

DeepSeek Harness is labelled a developer preview, and the README says in capitals that there will be compatibility-breaking changes. The release history supports taking that literally. The published tags run dsh-v0.1.1-rc.1 and dsh-v0.1.1-rc.2 on 2026-08-21, then dsh-v0.1.2-alpha.1 on 2026-08-27, while the root package.json in the repository carries version 0.1.5-rc.2. The repository is ahead of its own latest release tag, which is normal for active work but also means the code you clone and the package you install from npm are not the same revision.

That gap is the real failure mode. A plugin written against the checkout may not load against the published package, and a plugin written against the published package may not load against master. The README also asks you to review a safety notice before running the project, which is a reasonable place to start if you intend to let the agent touch a real machine.

A second limitation is structural rather than temporal. An everything-is-a-plugin design moves complexity from the core into the seams between plugins. When something misbehaves, the bug may live in the host, in a plugin, or in how the two were composed. The README does not document a debugging story for that, and the architecture documentation is a separate file you have to go read.

How dsh differs from wiring an agent into an existing editor or CLI

The obvious alternative is not another DeepSeek product but the pattern most teams already use: take a general-purpose coding agent that runs inside an editor or a terminal, and extend it through whatever configuration surface it exposes, typically a tool or server protocol. That approach wins on time to first result. You install one thing, point it at a repository, and it works.

The difference in approach is where the extension boundary sits. In the editor-integrated pattern, the agent loop is owned by the vendor and you attach capabilities to it. In DeepSeek Harness, the loop is composed from plugins, so the boundary is inside the product rather than at its edge. You gain the ability to replace the loop; you pay for it by having to understand the Cordis composition model before you can change anything meaningful.

That trade is not obviously good. For a team that just wants an agent to refactor a module, the harness is more machinery than the job needs. It becomes the better choice when the agent itself is the product and the loop is the part you need to differentiate.

Maintenance cost, licence and what to verify before committing

The repository is not archived, and the last push was on 2026-08-27, so this is a project being worked on rather than one left behind. The release cadence is fast and the version numbers are pre-1.0 with rc and alpha suffixes, which is consistent with the preview label.

On licensing, the root package.json declares MIT and the README links a LICENSE file, so the harness itself is permissively licensed. The README also points to THIRD_PARTY_NOTICES.md for dependencies and their licences. That file is the one to read if you plan to redistribute a build, because a permissive licence on the harness says nothing about the terms of everything bundled with it. This is a description of what the repository contains, not legal advice.

The upgrade cost is the part worth budgeting. With breaking changes announced in advance, every bump is a potential plugin break, and the build is not trivial: a pnpm workspace spanning vendor, packages, native, apps and website, with separate host and client compilation and a pnpm run build step that must precede pnpm dsh web. Before you commit, verify three things: that your Node version satisfies the engine range, that SAFETY.md describes a risk profile you accept, and that the specific plugin you depend on is maintained against the version you plan to run.

Editorial conclusion

Adopt DeepSeek Harness if you want an agent runtime whose parts are plugins you can swap, and you accept a developer preview that the README says will break compatibility. Do not adopt it if you need a stable API surface for a product you ship this quarter, or if you cannot read TypeScript and the Cordis plugin model to debug it. Before installing, read SAFETY.md, confirm your Node version satisfies the ^22.19.0 or >=24.0.0 engine range, and check whether the plugin you need already carries the dsh-plugin topic on GitHub.

Frequently asked questions

How do I install and run DeepSeek Harness?

Install Node.js and run npx @deepseek-ai/dsh web, which starts the Web UI at http://127.0.0.1:3080 by default. To run from a checkout, clone the repository, run pnpm install, pnpm run build, then pnpm dsh web.

What is DeepSeek Harness and how does it work?

It is an open-source agent harness from DeepSeek AI, written in TypeScript and built on an everything-is-a-plugin architecture powered by Cordis. The harness is the host and the agent capabilities are plugins loaded into it.

Is DeepSeek Harness similar to GitHub?

No. GitHub is a code hosting and collaboration platform, while DeepSeek Harness is an agent harness you run locally. The README does point to GitHub Discussions for feedback and to the dsh-plugin topic for plugin discoverability, which is where the overlap ends.

What is the role of DeepSeek Harness?

It acts as the host runtime for an agent, composing the agent loop and its capabilities from plugins built on Cordis. The README positions plugin authors as first-class users, with a dsh-plugin GitHub topic for discoverability.

What is deepseek harness?

DeepSeek Harness, abbreviated dsh, is a developer-preview agent harness released under the MIT licence by DeepSeek AI. Its README states that compatibility-breaking changes will occur, so it is not a stable target for production dependencies.

Official sources

  1. Official documentation
  2. Official README
  3. Project repository
  4. Release notes
For maintainers

Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/deepseek-ai-deepseek-harness.svg)](https://hysenlabs.com/projects/deepseek-ai-deepseek-harness)
Community notes

Community notes