DeepSeek Harness Review: The Harness and the Plugins

Published Sep 22, 2026 · dshpacks Research · ~10 min read

DeepSeek Harness (dsh) went from its 13 August 2026 launch to a plugin ecosystem large enough that curation is now the hardest part of using it. This review covers what dsh is, how much friction the install and plugin model really carry, what the measured ecosystem looks like, and where it falls short — including what we could not verify.

How we reviewed this

Most harness reviews test the software hands-on. We run a plugin directory, so ours works differently — and we would rather say so than imply otherwise.

What DeepSeek Harness is

dsh is an open-source agent harness published by DeepSeek AI under the MIT licence and built on Cordis, a plugin framework. Its README describes the architecture in four words — everything is a plugin — and that is literal: the Web UI, the tools, the memory backends and the model providers all arrive as plugins rather than as built-ins. Adoption has been fast: the repository reported 233,376 stars and 28,027 forks on 2026-09-22, roughly six weeks after it was created on 13 August 2026.

Two warnings come from the project itself, not from us. It is in developer preview, and the README states in capitals that there will be compatibility-breaking changes. SAFETY.md adds that it has not undergone a security audit and must not be treated as secure or production-ready.

Installing it

The npm path is unusually short for a project this size. With Node.js installed:

npx @deepseek-ai/dsh web

That serves the Web UI on http://127.0.0.1:3080 and opens a browser locally; --no-open suppresses the browser. Launched over SSH it only prints the host URL, because the client or editor owns the forwarded address. Model setup is one entry in Settings → Models that takes effect without a restart, and the step that stops newcomers is choosing a workspace — the session composer stays disabled until you add one. Our step-by-step tutorial walks the whole first run.

Source builds are a different job, because this is a large TypeScript monorepo: Node.js 22.19+ or 24+ (CI also covers 26), Corepack-enabled pnpm with the repo pinning [email protected], and Git 2.26 or newer — then pnpm install, pnpm run build and pnpm dsh web. The development guide treats setup as complete only when pnpm run typecheck exits clean.

Verdict on install: the npm path is about as easy as an agent harness gets. The source path is a real contributor setup, and the documentation does not pretend otherwise.

The plugin model: profiles, bundles and patches

The extension unit is a profile: an ordered stack of plugin bundles plus your own patch layer, stored under $DSH_HOME/profiles/<name>. Adding a capability is one command that forwards to pnpm inside the profile directory:

dsh plugin --profile web add <package-name>

Five profiles ship and initialize themselves on first use — web, headless, sdk, sdk-minimal and acp — while the name desktop is reserved for the Electron host. One install therefore runs interactively, as a one-shot headless job, as an SDK server or as an ACP endpoint.

The power and the cost are the same fact. Because the agent loop itself is composed from plugins, a dsh plugin can replace almost anything — which also means the whole stack becomes something you maintain. This is a harness where "it works on my profile" is a real category of bug.

The plugin ecosystem, measured

GitHub reported 15,845 repositories carrying the dsh-plugin topic on 2026-09-22, and 3,082 with "dsh-plugin" in the repository name. That is raw supply, counted before anyone checks whether a repository installs, runs or is even maintained. Curation is the scarce resource, which is the problem this directory exists to solve.

Our own measured state at build time: 2,961 English-visible plugins across 27 categories, of which 1,651 carry a completed review. Of the reviewed plugins, 1,583 publish a verified install command, 1,349 use the harness-managed dsh plugin form and 1,188 name the web profile; the rest install a documented other way, such as a global npm install or a build from source.

What the numbers do not flatter

Safety and the permission model

dsh asks before operations that need approval under the active permission policy, and profiles can be layered with your own patches. The project is explicit about the ceiling, though: SAFETY.md says sandboxing, approval prompts and permission controls reduce risk without guaranteeing isolation, that even correctly enforced restrictions cannot protect resources the harness is allowed to reach, and that dsh must not be the sole security control for untrusted workloads. Its own guidance is to run with least privilege, prefer a disposable VM or container, keep backups, and review plugins and proposed commands before allowing them. A dsh plugin is code the harness loads and runs with your privileges — our safety guide covers how to check one before you install it.

Documentation and contributor experience

This is where the project punches above its age. There is a published documentation site, per-subsystem READMEs across the monorepo, a development guide that fixes the Node floor and the pinned toolchain, a Python SDK, an AGENTS.md for coding agents working in the repository, and a documented architecture layer for Cordis. The CLI README even documents the composed config tree's layer precedence and ships helpers to inspect it without booting. The honest criticism is volume rather than absence: the surface is large enough that reading it takes real time, which is the same trade-off the plugin model makes.

Where dsh is strong

Where it falls short

Who should use it, and who should wait

What we could not verify

We did not measure model quality, latency, token cost or agent reliability, and we do not rank dsh against Claude Code, Codex or OpenCode on experience we have not gathered — which is why our Claude Code and Codex comparison and our OpenCode comparison stick to documented architecture. Install commands are verified per plugin and published on each plugin's page; plugin quality beyond an install check is a separate, ongoing review. Any third-party claim that dsh is production-ready should be read against the project's own safety notice above.

Sources

Where to go next

deepseek harness reviewdsh reviewdeepseek harness github

Browse the directory by category