
DeepSeek is moving its open-source agent harness beyond a developer-oriented command-line and web interface with official desktop versions for Windows and macOS, giving users a graphical environment for running AI agents against local files, software projects and other computer tasks.
The DeepSeek Harness, known as dsh, is not a new AI model. It is an agent runtime that connects models to tools and execution environments, allowing them to read and edit files, run commands, search the web, use skills and delegate tasks to subagents. DeepSeek released the project as a public developer preview under the MIT license in August.
The desktop release is now available through DeepSeek’s official download page for Apple silicon Macs and 64-bit Windows PCs. The company says the application can work in the background, edit local files and handle long-running tasks.
From developer setup to a desktop agent
The move changes how users access the harness. Earlier versions could be launched through the command line or a local web interface, requiring a developer-style setup. Recent releases have focused on packaging the same runtime into a more conventional desktop application.
Release candidate v0.2.0-rc.1, published on September 28, 2026, expanded the desktop experience. v0.2.0-rc.2, released on September 29, added support for bundling the dsh command in the macOS and Windows applications and managing it from the desktop menu bar without requiring users to install Node or pnpm separately.
The harness can operate on a selected local workspace. Its documented capabilities include file editing, shell execution, file and web search, planning, workflows, skills and subagents. DeepSeek also supports different runtime modes, including Standard, Code, Minimal and Creator modes.
Creator mode is aimed at modifying the harness itself. DeepSeek’s product demonstration shows the agent inspecting the runtime, using a plugin-development skill, creating files and installing a Pomodoro plugin while verifying the result inside the running environment.
The project is built around a plugin-based architecture called Cordis. DeepSeek describes the design as “Everything is a plugin,” with models, tools, skills, sessions, sandboxes, storage, scheduling, agent loops and interface components treated as replaceable components. The Cordis architecture was also described in an August 26, 2026 research paper on composable software systems.
Background tasks and broader tool support
Recent versions have expanded the harness beyond interactive coding. DeepSeek has added support for scheduled tasks that can persist across restarts and maintain execution histories. The company’s product material also demonstrates background work and recurring tasks initiated from natural-language instructions.
The harness supports more than DeepSeek’s own model endpoints. Its configuration system can work with third-party providers and custom endpoints using OpenAI-compatible or Anthropic-compatible interfaces. The product page currently uses DeepSeek-V4.1-Flash High as an example model environment.
Web search has also been integrated into the product experience. Release notes for the v0.2.0 release-candidate line state that users working with DeepSeek account models can perform web searches without separately configuring a search API key.
DeepSeek has built detailed execution records into the system as well. The harness maintains an append-only session log covering information such as model context, tool calls and results, subagent activity and other runtime events. Its Trajectory view allows developers to inspect an execution and continue or fork the session.
The expansion to desktop comes with an explicit security warning. DeepSeek’s safety documentation says the software has not undergone a security audit and should not be treated as secure or production-ready. Because the harness can execute model-generated code and commands, access files and credentials available to the environment, load plugins and interact with the network, the documentation warns that faulty model output, malicious input, configuration mistakes or malicious plugins could affect the host system.
The warning follows a security issue reported during the project’s early development. The Hacker News reported CVE-2026-82533, a vulnerability that allowed a sandboxed agent to disable its own file sandbox through a local interface. The issue affected versions through 0.1.1-rc.2, with fixes appearing in later releases.
DeepSeek adds Claude Code Mods experiment
DeepSeek’s October 3, 2026 release, v0.2.1-alpha.1, added another notable extension to the project: an experimental compatibility layer for Claude Code Mods.
The release does not claim full compatibility with Claude Code’s ecosystem. DeepSeek describes the implementation as an experiment intended to determine whether the Claude Code Mods API represents a subset of the capabilities supported by its own plugin architecture.
The same release added a “Let Agent create a plugin” option to plugin management, allowing users to enter Creator mode and have the agent build an extension from a requested capability.
A 36Kr report cited demonstrations involving tools called Token Weather, Blast Radius and Replay Theater. The examples cover context-usage monitoring, displaying the potential impact of risky commands and reviewing file modifications, while the report notes that the Claude Code Mods bridge remains experimental and that some Claude features require adaptation or cannot currently run directly.
DeepSeek continues to label Harness a public preview, and the project’s release history warns that compatibility-breaking changes are expected as development continues.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.



