Announced 29 Sept 2026 · Sources checked
What shipped in the v0.2 desktop candidates?
GitHub release dsh-v0.2.0-rc.1, published 28 September 2026, is labeled the first release candidate in the 0.2.0 series. Its English notes cover desktop update prompts, plugin-management UI work, Creator-mode guidance, and Windows sandbox permission diagnosis among other fixes.
Tag dsh-v0.2.0-rc.2 followed on 29 September. Its headline English feature is bundling the dsh command with macOS and Windows Desktop for plugin management without a separate Node or pnpm install, via a “Manage dsh command” menu-bar item.
That packaging story sits beside other local agent runtimes. For protocol context, see Model Context Protocol explained and the broader primer AI agents explained.
The product page we opened on 10 October still markets Harness as public-preview open source with composable plugins, Creator mode, scheduled tasks, and file/code previews. It lists download links for https://download.deepseek.com/desktop/dsh-latest-macos-arm64.dmg and https://download.deepseek.com/desktop/dsh-latest-windows-x64.exe.
Between the August 13 repository creation date recorded on GitHub and these late-September candidates, Harness moved from an npx-first developer preview to a downloadable desktop distribution. The product page’s “Ready to use. Right now.” framing is marketing language on a page that still links to a developer-preview codebase; keep those two tones separate when you brief stakeholders.

How do you run it, and what does SAFETY.md warn?
The repository README, checked 10 October, still documents npx @deepseek-ai/dsh web for a local Web UI on http://127.0.0.1:3080, plus a from-source pnpm path. Desktop installers are the v0.2 distribution change; the web path remains.
SAFETY.md states Harness is experimental developer-preview software that has not undergone a security audit, can execute model-generated code and commands, load third-party plugins, and access network, processes, credentials, and files. It tells users to prefer disposable VMs or containers and least privilege.
Those warnings matter more as local agents gain tool rights. For an infrastructure-side control story, compare NVIDIA OpenShell for agent runtime controls.
We did not download the .dmg or .exe, complete account login, enable Creator mode, or install a third-party plugin.
The README’s citation block still presents DeepSeek Harness as a GitHub-published MIT project rather than a peer-reviewed system paper. Cordis arXiv 2608.25512 is the composability reference the README cites; it does not substitute for Harness release notes when you need to know what broke between alphas.

What is “everything is a plugin” claiming?
DeepSeek’s README ties the harness to Cordis and points to arXiv 2608.25512, A Programming Paradigm for Spatiotemporal Composability. That paper is a design reference for the plugin runtime; it is not a Harness product changelog.
The product page’s marketing copy says plugins can extend tools, skills, and the interface, including creating plugins through chat in Creator mode. Those are DeepSeek’s statements on pages we opened, not measured plugin quality.
Official plugin topics and Discord links appear in the README; community packaging does not replace reading SAFETY.md before granting filesystem access.
Creator mode, as shown on the product page, is a chat path that writes and installs a plugin bundle. That is a powerful convenience and a supply-chain surface at once: a model-written plugin inherits the same host access the harness already has. DeepSeek’s own safety text is the reason to review generated plugin code before trust.
What limits should teams treat as open?
All v0.2 tags we opened are marked pre-release on GitHub. Compatibility-breaking changes are explicitly promised in the README’s developer-preview banner.
Linux is covered by the web/npx and from-source paths in the README; the product-page desktop download links we saw were macOS arm64 and Windows x64 only. Do not invent an official Linux .deb from that page.
Model routing, account requirements, and third-party provider keys are product/configuration details that change with releases. rc.2 notes mention updating the third-party model catalog via pi-ai 0.87.1 and that some older model IDs were removed.
A later pre-release, dsh-v0.2.1-alpha.2 dated 9 October, adds experimental plugins such as reasoning translation and Git worktrees. That is a follow-on alpha, not the v0.2 desktop candidate pair this article centers.
Star counts on GitHub change quickly and are not a quality or security metric. We note the repository’s popularity only as discovery context; nothing in this article depends on a star total.
What should a reader try before trusting it on a real workspace?
If you evaluate it, start in a disposable VM with a throwaway workspace folder, read SAFETY.md, and refuse broad home-directory access on first run.
Prefer a single official plugin or a trivial Creator-mode toy before granting shell delete/move tools. Keep backups of anything the agent can reach.
Compare against other desktop agents you already use on the same brief. We are not ranking Harness against Claude Desktop, Codex, or Cursor.
What did we not test?
We did not install macOS or Windows builds, run npx @deepseek-ai/dsh web, authorize DeepSeek account login, create a plugin, or schedule a task. This article reports the product page, README, SAFETY.md, and the 28–29 September v0.2 release notes only.
Common questions
Is Harness v0.2 a stable GA release?
No. The README still says developer preview with breaking changes expected, and the v0.2.0-rc tags are marked pre-release on GitHub.
Do you need Node.js for the desktop app?
rc.2 says the desktop build can bundle and install the dsh command from the menu bar without a separate Node or pnpm install. The web path still documents Node via npx.
Did AiLookout run Harness on a real machine?
No. We reviewed primary pages and release notes; we did not execute the agent.
What to remember
If you want a local DeepSeek-linked agent UI, v0.2’s dated change is desktop packaging on 28–29 September—still preview software that can run commands. Read SAFETY.md and isolate the workspace before any real files.
Sources & further reading
How this story was made
Written by Kristian Kostov with AI assistance and checked against the linked sources. Company performance claims are attributed to the company. Analysis reflects AiLookout’s interpretation; we have not independently tested the products discussed. Cover photography is illustrative and does not depict the specific announcement or product.
Our editorial standards





