DeepSeek Harness
BetaDeepSeek's open-source, plugin-based harness for running AI coding agents locally
DeepSeek Harness is a free, MIT-licensed way to run a coding agent from a local web UI, reading and editing files and running commands with DeepSeek, Anthropic, OpenAI, Kimi, GLM or custom compatible models. Caution because DeepSeek's own safety notice calls it unaudited and not secure or production-ready, and a critical flaw, CVE-2026-82533, let a sandboxed agent switch off its own sandbox on unpatched installs. Right for experimenters in a disposable VM; wrong for machines holding credentials or production code.
An agent loop sends model requests and runs tool calls that read and edit workspace files and run commands in a sandbox.
Ist es das Richtige für dich?
Gut für
- Running a coding agent from a local browser UI: npx @deepseek-ai/dsh web starts it at http://127.0.0.1:3080, and the agent can read and edit workspace files, run commands, delegate work and keep a plan
- Choosing your model: besides a DeepSeek API key, built-in provider ids include anthropic, openai, moonshotai for Kimi and zai for GLM, and custom providers can speak openai-completions, openai-responses or anthropic-messages
- Developers who want to rework the agent itself, since everything is a plugin on the Cordis framework, including model adapters, tools, persistence, sandbox and approval policy
- Zero software cost under the MIT licence
Nicht geeignet für
- Production or sensitive machines: DeepSeek's SAFETY.md says it has not undergone a security audit, must not be treated as secure or production-ready, and recommends a disposable virtual machine, container or dedicated environment
- Stable integrations, since the README warns of compatibility-breaking changes in the developer preview
- Agents that read untrusted content on unpatched installs: under CVE-2026-82533, attacker-supplied text the agent read could get it to disable its own sandbox with one shell command, on shipped defaults and with no network exposure
- Trusting the CVE record's fix version on npm: The Hacker News reports 0.1.2-alpha.1 was fixed on GitHub only and never published to npm, so npm users need 0.1.2-alpha.2 or later
Unsere Erfahrung
Preise
Open Source- MIT licensed harness
- Requires a DeepSeek API key or another configured model provider
- Custom OpenAI- or Anthropic-compatible endpoints supported
Workflow-Rezepte
Try it in an isolated environment
Run the developer preview the way DeepSeek's safety notice recommends
- Start from a disposable virtual machine, container or dedicated environment with only the files the agent needs
- Install Node.js and run npx @deepseek-ai/dsh web
- Open http://127.0.0.1:3080 and enter a DeepSeek API key or configure another provider
- Choose the workspace directory where you started dsh
- Confirm the installed version is 0.1.2-alpha.2 or later before letting the agent read untrusted material
Noch keine Urteilsänderungen
Die Uhr läuft ab dem ersten Tag — Änderungen erscheinen hier, sobald sich unser Urteil weiterentwickelt.
Quellen
- DeepSeek Harness docs, architecture (official)Sept. 2026
- VulnCheck advisory, CVE-2026-82533Sept. 2026
- DeepSeek Harness GitHub repository (official; MIT, developer preview, safety notice intact; npm now lists 0.2.0-rc.2, fix version still covered)Okt. 2026
- OX Research: CVE-2026-82533, DeepSeek Harness sandbox escape (Sep 8, 2026)Okt. 2026
- DeepSeek Harness docs, model providers (official)Sept. 2026
- DeepSeek Harness docs, Web UI guide (official)Sept. 2026
- DeepSeek Harness SAFETY.md (official)Sept. 2026
- The Hacker News: DeepSeek Harness flaw let AI agents disable their own file sandbox (Sep 9, 2026)Okt. 2026
Prüfprotokoll
- Status— Keine Änderungen
Automatisierter Agent
- Profil— Keine Änderungen
Automatisierter Agent
Wollen Sie das in Ihrem Unternehmen laufen haben?
Wir haben dieses Tool getestet und bauen täglich mit Tools wie diesem. Sagen Sie uns den Ablauf, wir richten es ein, integrieren es und übergeben es funktionsfähig.
Das Gespräch läuft auf Gnosari, einem der Tools in diesem Verzeichnis. Ein echtes Gespräch, kein Verkaufsskript.