The artifact exists.
DeepSeek released Harness as an MIT-licensed developer preview. It has a desktop download, a local Web UI, source code, and an npm package. The public guide says the agent can read and edit workspace files, run commands, delegate work, and keep a plan. The Web UI asks for approval when the active permission policy requires it.[1][2]
The package is usable. Pimp My IDE resolved version 0.2.0-rc.2 from npm and ran its launcher help in a disposable home directory. The command returned successfully and listed Web, terminal, headless, profile, patch, and plugin routes.[4]
The launcher exposes the real control point.
The repository describes each Harness profile as an ordered stack of plugin bundles and patches. The launcher can boot a named profile, add a patch, dump the composed configuration, or install a plugin into one profile. That structure matters more than the desktop chrome. The profile decides which code and tools enter the session.[3]
The workspace is a separate decision. The quickstart says a new Web UI has no selected workspace. The session composer remains unavailable until the operator adds and selects one. Keep that friction. A friendly desktop should not infer a broad writable root.
The desktop shortens the path to the agent. It must not shorten the path around review.
The safety notice sets the floor.
DeepSeek says the preview has not undergone a security audit and is not production-ready. Its safety notice says Harness can execute generated code, load third-party plugins, and access any network, process, credential, or file made available to it. It also says sandboxing and approval prompts reduce risk but do not guarantee isolation.[5]
That is the correct boundary. Start with least privilege. Use a disposable or dedicated environment. Keep backups. Review plugins and commands. Treat a successful launch as process evidence, not containment evidence.
Make each session declare its posture.
- Record the exact Harness and profile revision.
- Select one workspace with the smallest useful writable area.
- State which actions need approval before the prompt begins.
- Name the trace or receipt that must survive the session.
- Run one denied action and confirm the boundary holds.
The keyrack below builds a session plan. It does not configure Harness, run a task, or prove isolation.