Pimp My IDE / garage dispatch
Back to garage
October 2, 2026 | agent harnesses / desktop / custody

Desktop is not a permission model.

DeepSeek Harness puts an open-source agent harness behind a desktop app and Web UI. The polished entry point makes the custody questions more urgent, not less.

Pin the profile, workspace, approval policy, and retained trace before a desktop agent receives a task.

The artifact exists.

DeepSeek released Harness as an MIT-licensed developer preview. It has a desktop download, a local Web UI, source code, and an npm package. The public guide says the agent can read and edit workspace files, run commands, delegate work, and keep a plan. The Web UI asks for approval when the active permission policy requires it.[1][2]

The package is usable. Pimp My IDE resolved version 0.2.0-rc.2 from npm and ran its launcher help in a disposable home directory. The command returned successfully and listed Web, terminal, headless, profile, patch, and plugin routes.[4]

The launcher exposes the real control point.

The repository describes each Harness profile as an ordered stack of plugin bundles and patches. The launcher can boot a named profile, add a patch, dump the composed configuration, or install a plugin into one profile. That structure matters more than the desktop chrome. The profile decides which code and tools enter the session.[3]

The workspace is a separate decision. The quickstart says a new Web UI has no selected workspace. The session composer remains unavailable until the operator adds and selects one. Keep that friction. A friendly desktop should not infer a broad writable root.

The desktop shortens the path to the agent. It must not shorten the path around review.

The safety notice sets the floor.

DeepSeek says the preview has not undergone a security audit and is not production-ready. Its safety notice says Harness can execute generated code, load third-party plugins, and access any network, process, credential, or file made available to it. It also says sandboxing and approval prompts reduce risk but do not guarantee isolation.[5]

That is the correct boundary. Start with least privilege. Use a disposable or dedicated environment. Keep backups. Review plugins and commands. Treat a successful launch as process evidence, not containment evidence.

Make each session declare its posture.

  1. Record the exact Harness and profile revision.
  2. Select one workspace with the smallest useful writable area.
  3. State which actions need approval before the prompt begins.
  4. Name the trace or receipt that must survive the session.
  5. Run one denied action and confirm the boundary holds.

The keyrack below builds a session plan. It does not configure Harness, run a task, or prove isolation.

Interactive makeover / harness custody keyrack

Choose the posture.

Traditional purpose replaced: one broad launch button. Better version: a native posture selector changes the visible execution route, while four independent checks build a copyable session plan.

Set the ignition

The posture states are a Pimp My IDE operating pattern. They are not DeepSeek product modes.

Requested session posture
Session plan sections
Requested route

Inspect

0 of 4 plan sections selected
ReadPrepareExecuteRepeat

Read before granting work.

Inspect the composed profile, workspace boundary, and current policy. No write or command result is claimed.

This component drafts a custody plan. It does not change a Harness profile, permission policy, workspace, plugin, scheduled task, or host boundary.

Session custody card

The all-selected state means the card structure is complete. Every value and runtime result still needs evidence.

Sources read

Source log and evidence boundary
  1. DeepSeek Harness product page, read October 2, 2026. This supplies the public-preview announcement, desktop route, open-source claim, plugin framing, scheduled-task example, trace viewer, and one-command Web UI route.
  2. DeepSeek Harness Web UI quickstart, read October 2, 2026. This supplies the model configuration, explicit workspace selection, task capabilities, and active permission-policy behavior.
  3. DeepSeek Harness repository and README, read October 2, 2026. This verifies the MIT-licensed source, npm and source launch paths, developer-preview warning, profile architecture, and repository layout.
  4. @deepseek-ai/dsh on npm, checked October 2, 2026. Pimp My IDE resolved version 0.2.0-rc.2 and ran npx --yes @deepseek-ai/dsh@0.2.0-rc.2 --help in a disposable home directory. It exited with status 0 and printed the launcher routes. No agent task or Web UI was started.
  5. DeepSeek Harness safety notice, read October 2, 2026. This supplies the no-security-audit boundary, host-access risks, sandbox limits, least-privilege advice, disposable-environment advice, backup advice, and plugin-review advice.
  6. Hacker News discussion for DeepSeek Harness Desktop, item ID verified through the Hacker News API and read October 2, 2026. This is the discovery and practitioner-discussion route, not technical authority.

Evidence boundary. Pimp My IDE verified the package launcher and read the public source, docs, and safety notice. We did not start the Web UI, download the desktop app, configure a model, run an agent task, test a sandbox, or audit the code. The four-posture keyrack is an editorial control pattern, not a DeepSeek feature map.