DeepSeek Harness (dsh) is an open-source agent harness published by DeepSeek under the MIT license (GitHub repository github.com/deepseek-ai/deepseek-harness created 13 Aug 2026, about 241,000 stars, checked 30 Sep 2026). It is built on a plugin architecture in which tools, skills and interface parts are plugins, and it runs as a local web UI, a desktop app, a CLI, or through Python and TypeScript SDKs. You bring a model: the quickstart uses `npx @deepseek-ai/dsh web` and a DeepSeek API key, and the docs describe other providers and compatible endpoints. It is unrelated to Harness.io, the CI/CD platform listed at aicoolies.com/tools/harness. Stars are a popularity signal, not proof of quality or adoption.
Every release so far is marked pre-release (latest: dsh-v0.2.0-rc.2, 29 Sep 2026), and the README warns of compatibility-breaking changes. The project's SAFETY.md says it "has not undergone a security audit and must not be treated as secure or production-ready", that it can execute model-generated code and commands and load third-party plugins, and it recommends a disposable virtual machine or container. In the `master` branch as of 30 Sep 2026, uploading the session log (messages, tool calls and results) with requests to the official DeepSeek API is enabled by default; it can be turned off under Settings > General in the web UI or with `session-log-deepseek.enabled: false` in a profile patch. According to the repository's package notes, a separate OpenTelemetry export happens only after explicit user feedback and can be disabled with `DSH_TELEMETRY_DISABLED`.
Evidence: documented, not tested. This page is based on the repository (README, SAFETY.md, package READMEs and source on `master`), release notes, package registry metadata and DeepSeek's product page, all read on 30 Sep 2026. aicoolies has not run the software or observed its network traffic. It suits developers who want to experiment with a free, plugin-based agent harness and can run preview software in an isolated environment; anyone who needs stable releases or a completed security review should wait.