Harness · spec sheet
DeepSeek Harness
- Category
- Coding agent
- Interface
- Terminal (TypeScript)
- License
- MIT
- Languages
- TypeScript — everything is a plugin, including the agent loop
- Models
- Any (multi-provider); can drive Claude Code or Codex as sub-agents
- Isolation
- Ships an OS-level sandbox, a credentials file and an append-only session log
- Best for
- Assembling a harness from parts, or putting one harness in front of several others
Everything is a plugin — including the agent loop. A parts bin powerful enough to run Claude Code or Codex as a sub-agent; developer preview since 13 Aug 2026.
What it is
DeepSeek's open-source coding harness, published as a developer preview on 13 Aug 2026. It collected roughly 95,000 GitHub stars in its first two days, which tells you about attention rather than quality — it is the number worth noting and then setting aside.
What makes it interesting is the architecture. Most harnesses have a core loop with extension points bolted around the edges: you can add tools, maybe swap a provider, but the loop itself is the product. Here the loop is a plugin like anything else. So are the tools, the providers, the renderers, the permission checks. The shipped harness is one particular assembly of parts, and nothing stops you building a different one.
How the loop works
The default assembly behaves like the terminal agents you already know: read the repository, propose edits, run commands, iterate. The difference shows up when you want something else. Replacing the planning step, changing how tool results are summarised, or inserting a review pass between proposal and execution are all plugin work rather than fork work.
The most striking consequence is sub-agents. Because an external process can be wrapped as a plugin, DeepSeek Harness can drive Claude Code or Codex as sub-agents — one harness sitting in front of several others, dispatching work and collecting results. That is a genuinely different shape from the single-loop norm, and it is the reason to look at this rather than at a more settled tool.
Isolation and permissions
Better provisioned than most open-source harnesses out of the box. There is an OS-level sandbox, a separate credentials file so provider keys are not scattered through config, and an append-only session log — which matters more than it sounds, because an audit trail you cannot quietly rewrite is the thing you actually want after an agent run goes sideways.
One caveat follows directly from the architecture: if the permission layer is a plugin, a plugin can replace it. The security posture is whatever your assembly happens to be, not a fixed property of the tool.
Who it is for
Two groups. People who want to build a harness to their own taste and would rather start from a parts bin than fork someone else's loop. And people orchestrating several agents, who need something that can hold other harnesses underneath it.
If you want a tool that works well on defaults and stays where you left it, this is not that tool yet.
Limits
It is a developer preview and it is moving fast. Nothing about it is stable: plugin interfaces, configuration format and defaults are all subject to change without much ceremony. The star count means a lot of people are watching, not that a lot of people are running it in anger. As of Sep 2026 we would treat it as something to experiment with rather than something to build a team workflow on.
Alternatives on this board
- OpenCode — provider-agnostic and far more settled, if you want the flexibility without the churn.
- Claude Code — the opinionated default, and one of the harnesses this can run underneath it.
- Prime Agent — the other August 2026 arrival with a strong architectural argument.
Sources
- DeepSeek on GitHub — repository and preview release notes
- deepseek.com
Hand-maintained editorial spec, not vendor copy — the read on each tool is judgement. Last checked 26 Sep 2026 · back to harnesses.