DeepSeek Harness Review: The Harness and the Plugins
DeepSeek Harness (dsh) went from its 13 August 2026 launch to a plugin ecosystem large enough that curation is now the hardest part of using it. This review covers what dsh is, how much friction the install and plugin model really carry, what the measured ecosystem looks like, and where it falls short — including what we could not verify.
How we reviewed this
Most harness reviews test the software hands-on. We run a plugin directory, so ours works differently — and we would rather say so than imply otherwise.
- What we did. We read the project's own documentation, fetched 2026-09-22: the root README, SAFETY.md, the CLI README, the Web UI guide and the development guide. We measured the plugin ecosystem from the directory's own data — 2,961 listed plugins, 1,651 of them reviewed — on every build.
- What we did not do. We did not benchmark model quality, latency, token cost or agent success rates, and we did not run the harness through long autonomous sessions. Where a claim would need that testing, we leave it out instead of guessing.
- What "verified" means here. An install command we print is copied from the plugin's own README or registry metadata and cross-checked against the registry. No number on this page is typed by hand.
What DeepSeek Harness is
dsh is an open-source agent harness published by DeepSeek AI under the MIT licence and built on Cordis, a plugin framework. Its README describes the architecture in four words — everything is a plugin — and that is literal: the Web UI, the tools, the memory backends and the model providers all arrive as plugins rather than as built-ins. Adoption has been fast: the repository reported 233,376 stars and 28,027 forks on 2026-09-22, roughly six weeks after it was created on 13 August 2026.
Two warnings come from the project itself, not from us. It is in developer preview, and the README states in capitals that there will be compatibility-breaking changes. SAFETY.md adds that it has not undergone a security audit and must not be treated as secure or production-ready.
Installing it
The npm path is unusually short for a project this size. With Node.js installed:
npx @deepseek-ai/dsh web
That serves the Web UI on http://127.0.0.1:3080 and opens a browser locally; --no-open suppresses the browser. Launched over SSH it only prints the host URL, because the client or editor owns the forwarded address. Model setup is one entry in Settings → Models that takes effect without a restart, and the step that stops newcomers is choosing a workspace — the session composer stays disabled until you add one. Our step-by-step tutorial walks the whole first run.
Source builds are a different job, because this is a large TypeScript monorepo: Node.js 22.19+ or 24+ (CI also covers 26), Corepack-enabled pnpm with the repo pinning [email protected], and Git 2.26 or newer — then pnpm install, pnpm run build and pnpm dsh web. The development guide treats setup as complete only when pnpm run typecheck exits clean.
Verdict on install: the npm path is about as easy as an agent harness gets. The source path is a real contributor setup, and the documentation does not pretend otherwise.
The plugin model: profiles, bundles and patches
The extension unit is a profile: an ordered stack of plugin bundles plus your own patch layer, stored under $DSH_HOME/profiles/<name>. Adding a capability is one command that forwards to pnpm inside the profile directory:
dsh plugin --profile web add <package-name>
Five profiles ship and initialize themselves on first use — web, headless, sdk, sdk-minimal and acp — while the name desktop is reserved for the Electron host. One install therefore runs interactively, as a one-shot headless job, as an SDK server or as an ACP endpoint.
The power and the cost are the same fact. Because the agent loop itself is composed from plugins, a dsh plugin can replace almost anything — which also means the whole stack becomes something you maintain. This is a harness where "it works on my profile" is a real category of bug.
The plugin ecosystem, measured
GitHub reported 15,845 repositories carrying the dsh-plugin topic on 2026-09-22, and 3,082 with "dsh-plugin" in the repository name. That is raw supply, counted before anyone checks whether a repository installs, runs or is even maintained. Curation is the scarce resource, which is the problem this directory exists to solve.
Our own measured state at build time: 2,961 English-visible plugins across 27 categories, of which 1,651 carry a completed review. Of the reviewed plugins, 1,583 publish a verified install command, 1,349 use the harness-managed dsh plugin form and 1,188 name the web profile; the rest install a documented other way, such as a global npm install or a build from source.
What the numbers do not flatter
- The long tail is very long. 757 of the 2,961 listed plugins have zero stars and the median is 2, so the ecosystem is wide but shallow: most repositories are one-person experiments rather than products.
- Category concentration is high. "Other" is the single largest bucket at 490 plugins, which is a curator's way of saying the taxonomy has not yet caught up with what people are building.
- Review coverage is about half the directory. 1,651 of 2,961 listings are reviewed; the other 1,310 are catalogued but not yet verified, which is why a plugin page can honestly say install command not yet confirmed.
Safety and the permission model
dsh asks before operations that need approval under the active permission policy, and profiles can be layered with your own patches. The project is explicit about the ceiling, though: SAFETY.md says sandboxing, approval prompts and permission controls reduce risk without guaranteeing isolation, that even correctly enforced restrictions cannot protect resources the harness is allowed to reach, and that dsh must not be the sole security control for untrusted workloads. Its own guidance is to run with least privilege, prefer a disposable VM or container, keep backups, and review plugins and proposed commands before allowing them. A dsh plugin is code the harness loads and runs with your privileges — our safety guide covers how to check one before you install it.
Documentation and contributor experience
This is where the project punches above its age. There is a published documentation site, per-subsystem READMEs across the monorepo, a development guide that fixes the Node floor and the pinned toolchain, a Python SDK, an AGENTS.md for coding agents working in the repository, and a documented architecture layer for Cordis. The CLI README even documents the composed config tree's layer precedence and ships helpers to inspect it without booting. The honest criticism is volume rather than absence: the surface is large enough that reading it takes real time, which is the same trade-off the plugin model makes.
Where dsh is strong
- Extensibility without a ceiling. Replacing the agent loop is a supported move, not a fork.
- One install, several runtimes. web, headless, SDK and ACP are profiles of the same tree.
- A fast, broad ecosystem. 15,845 repositories carry the plugin topic within roughly six weeks of launch.
- Documented safety limits. The project states what its controls do not guarantee, which is more useful than a security page that only lists features.
Where it falls short
- Developer preview is not marketing. Compatibility-breaking changes are announced in advance; pin what you depend on.
- Repo-level quality is unevidenced. A large share of plugin repositories are tiny, so finding the good ones is hard — a directory problem more than a harness problem, but a real one for users.
- No security audit, by its own admission. For production or untrusted workloads that is disqualifying until it changes.
- Profiles are a learning curve. Legible once learned, but the first hour holds more concepts than a harness with a fixed core.
Who should use it, and who should wait
- Use it if you want an agent harness you can reshape, and you are comfortable maintaining a plugin stack.
- Use it to run the same agent interactively, headlessly and over ACP without installing it twice.
- Wait if you need a security-audited or compatibility-stable agent platform today.
- Wait if you want a fully curated experience out of the box; start from reviewed plugins and expect to check what you install.
What we could not verify
We did not measure model quality, latency, token cost or agent reliability, and we do not rank dsh against Claude Code, Codex or OpenCode on experience we have not gathered — which is why our Claude Code and Codex comparison and our OpenCode comparison stick to documented architecture. Install commands are verified per plugin and published on each plugin's page; plugin quality beyond an install check is a separate, ongoing review. Any third-party claim that dsh is production-ready should be read against the project's own safety notice above.
Sources
- DeepSeek Harness README — developer-preview status, npm and source run paths, plugin topic, MIT licence, Cordis architecture (fetched 2026-09-22)
- DeepSeek Harness SAFETY.md — unaudited status, sandbox limitations, responsible-use guidance (fetched 2026-09-22)
- DeepSeek Harness CLI README — entry modes, profile layout and layers, reserved desktop profile (fetched 2026-09-22)
- DeepSeek Harness Web UI guide — model setup, workspace selection, first task (fetched 2026-09-22)
- DeepSeek Harness development guide — Node 22.19+/24+/26, [email protected], Git 2.26+, typecheck contract (fetched 2026-09-22)
- GitHub API — repository stars, forks, creation date, topic and repository-name search counts (fetched 2026-09-22)
- dshpacks directory data — plugin, category, review and install-command counts (plugins.json + enrichment.json), measured at build time
Where to go next
- Best DeepSeek Harness plugins — ranked picks by category
- How to install DSH plugins — step-by-step guide
- Are DSH plugins safe? — what to check before installing
- DSH plugin FAQ — 20 questions answered
- DSH vs Claude Code vs Codex — harness comparison
- Pi vs DSH vs Claude Code — the context-management debate
- dsh Packs — curated bundles of reviewed plugins
- The plugin directory — every reviewed plugin, searchable
- DSH ecosystem report — the numbers behind the directory
- DeepSeek Harness tutorial — get dsh running, step by step
- DeepSeek Harness vs OpenCode — how the two open agent harnesses differ