Build2 publishers2 min readPublished Updated
DeepSeek packages its unaudited Harness agent runtime as a Windows and macOS desktop app
DeepSeek released its open-source Harness agent runtime as a Windows and macOS desktop app on September 30, so users no longer need a command line to run it. The agent edits local files and runs commands, so what each user exposes to it decides what it can touch and which provider sees it.
The Engineer · Build desk

What happened
- Harness is an agent runtime that connects a language model to tools acting on files, code and other systems.
- Official DeepSeek models need an account, while custom models run on an API the user obtains and, per DeepSeek's privacy policy, send inputs directly to that provider.
- For official-model sessions, DeepSeek says it collects logs that can include user inputs, uploaded content, model outputs, tool calls and plugin configuration.
- The project's safety notice says the preview has not had a security audit and that mistakes, malicious input or untrusted plugins can damage files or disclose data.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- exposure People who would never have set up Node.js can now give an unaudited agent reach into their files, credentials and network from a double-click.
- decision Choosing an official DeepSeek account or a custom API key now decides which company's data policy covers every file the agent reads.
- cost Any team that allows Harness on work machines takes on plugin vetting and command review itself, because DeepSeek's notice leaves that safeguard to the user.
The key word in DeepSeek's terms of use is "available". According to the terms, the services can run model-generated code and commands, load third-party plugins, and access files, credentials, processes and networks made available to them [13]. Harness does not set its own limit in that sentence. The user sets it, by deciding what the account running the app can reach.
That decision also shapes what gets logged. A chat model's input is what the user typed. An agent's input includes the documents it opened and the commands it ran. I'd assume any file Harness reads on DeepSeek's own models can be logged, since DeepSeek's list for official-model sessions includes authorized content and tool calls [12].
Before the desktop build, DeepSeek's documented web interface required installing Node.js and running a command, so every user had at least opened a terminal [8]. Installing Node.js was never a security control, but it did a fair impression of one. The desktop downloads cover Windows and Apple-silicon Macs on macOS 13 or later [3].
The design pulls in two directions. DeepSeek pitches Harness for work that goes on without the user: running scripts, analyzing spreadsheets, processing files in the background [5]. The safety notice asks users to grant only the permissions a task needs and to review plugins and proposed commands [15]. Following that advice literally means watching the agent the whole time. On a laptop that holds client files and cloud credentials, I would run it under a separate OS account with one project folder exposed, and keep background tasks off until the preview label comes off.
Some of the engineering deserves credit. Cordis, the plugin layer, lets users install or write extensions for tools, skills and interface features [6]. The runtime is MIT-licensed and still a developer preview, according to its GitHub repository [7]. Because the code is open, anyone can read what a tool call actually does before deciding to trust it. The safety documentation states the failure modes in plain words, and that is to DeepSeek's credit [14].
Runtimewire frames the release as DeepSeek extending its open-source work from models into the agent software that uses them [17]. The record so far fits that, within limits the publication itself sets out. The release does not show how many people will use the app, whether they will keep it pointed at DeepSeek's models, or how much work they will trust it to do unattended [16].
What to watch
- Whether DeepSeek publishes a security audit or moves Harness out of developer preview.
- Whether DeepSeek adds signing or review for third-party Cordis plugins as the extension catalogue grows.
- Whether DeepSeek narrows the official-model session log list or adds a mode that keeps file contents out of it.