UHP and DeepSeek Harness
DeepSeek Harness is an upstream developer-preview agent harness with native ACP, MCP client/resource support and rich subagent composition. HarnessRouter separately integrates it as a UHP backend and still pins dsh 0.1.2rc1, while the latest observed upstream prerelease is dsh-v0.2.1-alpha.1. The older 0.1.6-alpha.1 analysis is retained as a dated source snapshot.
Page reviewed 4 Oct 2026 Source and review policy
Evaluate the preview without upgrading the adapter by implication
Section titled “Evaluate the preview without upgrading the adapter by implication”The upstream release list checked 4 October shows dsh-v0.2.1-alpha.1, published 3 October. The project README still calls DeepSeek Harness a developer preview and warns of breaking compatibility. HarnessRouter v0.29.0 separately installs Python SDK/runtime packages at 0.1.2rc1.
Choose one test target: the current native preview or the released UHP adapter. Record both the runtime and its distribution family; the repository’s dsh-v... tag and the Python adapter package pin use different naming conventions. In particular, the newest release’s experimental Claude Code Mods compatibility layer is not a promise of complete plugin compatibility and is not evidence that the older adapter exposes it.
| Failure | Check first |
|---|---|
| Backend absent after CE starts | Installation logs and the dsh-ready version/import check |
| Native plugin fails after an upgrade | Preview release’s breaking API/export changes |
| Text works but MCP integration fails | Adapter transport bridge, configured server and actual pinned runtime |
| A Web URL works locally but fails remotely | Bind/public URL/authentication and reverse-proxy path configuration |
HarnessRouter’s entrypoint rebuilds its DSH virtual environment when the recorded pin differs and writes the readiness marker only after SDK/runtime imports resolve. That check establishes an installation seam, not an authenticated successful task.
Start with one task and required tool path before moving a version override into production. For the external contract, use HarnessRouter setup and UHP errors; for native automation, use DeepSeek’s versioned documentation. The historical ACP/MCP notes below retain their September scope.
Release check — 4 October 2026
Section titled “Release check — 4 October 2026”The latest prerelease observed in the upstream GitHub release API is dsh-v0.2.1-alpha.1, published 2026-10-03. GitHub marks this release as a prerelease. The 0.1.6-alpha.1 material below is a historical review, not the latest prerelease. No stable-release or new conformance claim follows from observing this tag.
HarnessRouter integration, checked 4 October 2026: the v0.29.0 entrypoint retains the default pin DeepSeek Harness 0.1.2rc1. This is source-verified adapter configuration, not a fresh runtime or provider test. HarnessRouter now has 20 released backends; the earlier counts and measurements below retain their dated scope.
Evidence scope: the integration details, commands, measurements and development-head references below preserve the 15 Sep 2026 source snapshot. They are not presented as a fresh test of this newer release. For the current UHP protocol, HarnessRouter release and suite coordinates, use the release tracker and conformance guide. Adapter support does not establish upstream-native UHP adoption.
Source snapshot — 15 Sep 2026
Section titled “Source snapshot — 15 Sep 2026”DeepSeek Harness (dsh) is an open-source agent harness developed by DeepSeek AI. Upstream remains in developer preview, with compatibility-breaking changes explicitly expected.
The latest observed upstream prerelease is v0.1.6-alpha.1, published 15 September 2026 at 04:57:57 UTC; tag commit 0a15e36e7f82b6ed45af6fa9759f29b40dcd965d. Checked upstream master is 0d1f50007f9bca3f52b06e1c3074fa14d5fb0720. HarnessRouter’s current released dsh adapter remains deliberately on a different coordinate: 0.1.2rc1, introduced in HarnessRouter v0.15.6 and still pinned in checked current source. The upstream latest release and the adapter version actually measured by HarnessRouter must not be conflated.
| Coordinate | Verified state |
|---|---|
| DeepSeek Harness upstream latest prerelease | v0.1.6-alpha.1 · 15 Sep 2026 · tag 0a15e36e; checked master 0d1f5000 |
| HarnessRouter latest release | v0.17.2 · tag target fa9ca27d; runtime-relevant post-release main cutoff d24b6659 through PR #185; later checked branch head 821a95d8 is README-only PR #186 |
| HarnessRouter dsh adapter pin | 0.1.2rc1 through PR #135; unchanged in checked current source |
| Native DeepSeek protocol surface | ACP v1 automation server verified; first-party MCP client now uses official SDK v2 and exposes tools/resources; native UHP remains not established |
| HarnessRouter UHP evidence through dsh | Historical 52/52 Full result at HarnessRouter v0.8.0; later runtime/matrix evidence is separate from UHP conformance |
| Current MCP evidence through HarnessRouter | PR #135 records dsh MCP-server driving; PRs #180/#182 complete plugin-provided stdio launcher delivery; PR #185 bridges plugin SSE to local stdio for clients including dsh that lack native SSE in the pinned surface |
| Upstream Web security boundary | VulnCheck assigns CVE-2026-82533 / CVSS 9.4 to DeepSeek Harness before 0.1.2-alpha.1; first-party patch 3e24087b authenticates the browser Host API and release v0.1.2-alpha.1 requires a one-time launch token for network Web access |
v0.1.6-alpha.1: MCP SDK v2, resources and automation surfaces
Section titled “v0.1.6-alpha.1: MCP SDK v2, resources and automation surfaces”DeepSeek published v0.1.6-alpha.1 on 15 September. Unlike the preceding v0.1.5-rc.2 UI-focused release, this alpha contains several integration-facing changes that materially affect harness embedders and automation clients.
- MCP moves to the official SDK v2. DeepSeek documents protocol negotiation, paginated tool lists and support for MCP servers that expose no tools.
- MCP resources become first-class upstream behavior. DSH can discover and read resources and use URI templates; configuring an MCP server in a built-in Profile enables shared resource tools.
- Headless gains a cleaner automation seam. It can read tasks from standard input, resume with
--session-id, and emit run events as newline-delimited JSON with--json. - Browser Use and Computer Use are added as experimental capability families. Browser Use can run through Playwright MCP, Chrome DevTools MCP or Stagehand; Computer Use can run through Cua Driver MCP or the native driver.
- The official DeepSeek adapter now defaults to the Messages protocol and can reuse uploaded images through the Files API. Custom API addresses remain preserved; users who explicitly configured the old official root URL are instructed to remove that override or change it to
https://api.deepseek.com/anthropic. - Plugin/runtime lifecycle contracts change.
agent/session-startis replaced by async-serialagent/created, and the first model request waits for initialization. Optional plugin startup failures no longer take down otherwise usable plugins, while required-plugin failures still exit. - Node PTC now runs in a dedicated process under session file policy and resource limits, with an empty
process.env; integrations relying on the old inherited execution environment must adapt. - Sandbox and shell preparation become cancellable asynchronous operations.
SandboxProvider.confineandShellExecutor.startare async and preparation time counts toward timeout. - The synchronous Session history readers are now formally deprecated in the release line.
snapshotEvents,eventAtandownEventsshould not be the basis for new integrations.
These are DeepSeek Harness developer-preview runtime/API behaviors. They do not change UHP 2026-09-12, do not create a new MCP wire specification, do not establish native UHP adoption by DeepSeek Harness, and do not upgrade HarnessRouter’s separately pinned 0.1.2rc1 dsh adapter.
v0.1.5-rc.2: prior release-candidate UI refinements
Section titled “v0.1.5-rc.2: prior release-candidate UI refinements”DeepSeek published v0.1.5-rc.2 on 10 September as the second release candidate in the 0.1.5 line. Its release notes are deliberately narrow: both likes and dislikes require dialog confirmation before feedback is recorded, failed submissions retain entered feedback and show a notice, and delivered-file card layout, conversation spacing and code-file icons are refined.
Those changes improve the Web client experience but do not establish new UHP, ACP or MCP wire behavior, and they did not change HarnessRouter’s pinned dsh 0.1.2rc1 adapter. The durable integration-facing changes summarized below remain the rc.1 baseline inherited by the newer alpha line.
Synchronous historical event readers are deprecated
Section titled “Synchronous historical event readers are deprecated”The deprecation first tracked on master at commit 42b50bd3 is now also documented in the v0.1.6-alpha.1 release line. New production code should avoid Session.eventAt(), Session.snapshotEvents() and Session.ownEvents(). The stated direction is to reconstruct durable domain state into projections during resume, maintain those projections incrementally, and use explicit asynchronous pagination/progressive loading when historical event content is actually requested. Existing callers may defer migration and the current Session implementation still retains the complete event sequence in memory.
This is an upstream API-use/storage-direction decision rather than a protocol change. It matters to embedders because new integrations should avoid depending on synchronous random access to complete Session history.
v0.1.5-rc.1: consolidated 0.1.5 candidate and DeepSeek V4.1 Flash default
Section titled “v0.1.5-rc.1: consolidated 0.1.5 candidate and DeepSeek V4.1 Flash default”DeepSeek published v0.1.5-rc.1 on 10 September as the first release candidate for the 0.1.5 line, summarizing the major user- and developer-facing changes since v0.1.2-rc.1. It superseded the earlier v0.1.5-alpha.1 and v0.1.5-alpha.2 coordinates tracked here without changing the project’s developer-preview warning.
Material integration-facing changes in the candidate include:
- The official DeepSeek adapter adds
DeepSeek-V41-Flash(deepseek-flash) and makes it the default for new sessions, while an explicitly configured model still wins. The release describes text, image and in-history system-prompt update support for that model. - Continuable subagents gain queue/edit/delete, per-message or all-message steer, and stop controls. Agent Team
send_messageis aligned to steer semantics while preserving sender attribution and order across cross-agent and cold-recovery delivery. - Session format V3 and lifecycle changes are now part of the RC baseline. Session persistence is held by a lifecycle-owned
SessionHandle,agentLoop.create()becomes async, and a session lock limits a session to one process owner at a time. - SDK, Headless and ACP default to read/write/edit file tools, while Web
minimaland Pythonsdk-minimalremain persistent-shell-only unlessstr_replace_editoris explicitly enabled. - All outbound network requests honor
HTTP_PROXY,HTTPS_PROXY,ALL_PROXYandNO_PROXYfrom the launch environment. - MCP tool discovery rejects repeated pagination cursors instead of hanging startup or synchronization, retaining the last valid tool set.
- Filtered subagent prompts are aligned with effective tool access, custom-provider Base URLs are validated/normalized before discovery or creation, and project-root permission/I/O failures are surfaced rather than silently loading instructions from an ancestor project.
- Arbitrary file uploads and richer file delivery/preview are consolidated into the RC, including background upload progress/cancellation and Markdown/code/HTML/PDF/image viewing.
- User-paused goals immediately stop the active model round and cannot be resumed by the model. Resumption requires user action.
These are upstream DeepSeek Harness developer-preview semantics. They are not changes to UHP 2026-09-12, do not turn an MCP client guard into a new MCP protocol rule, and are not silently attributed to HarnessRouter’s older 0.1.2rc1 adapter pin.
Security boundary: CVE-2026-82533 and the browser Host API
Section titled “Security boundary: CVE-2026-82533 and the browser Host API”VulnCheck’s 8 September advisory assigns CVE-2026-82533, CWE-807 and CVSS v4 9.4 to DeepSeek Harness before 0.1.2-alpha.1. The advisory describes an authentication bypass in the local HTTP control-plane API: trusting a client-supplied Host value could let a malicious browser origin reach privileged agent methods, including unconfined command execution and stored-conversation access, without a credential.
DeepSeek’s first-party patch 3e24087bfaeabe40b58ba2f7b936895b8f93fe27 is titled fix(web): authenticate the browser Host API. Its trust-boundary work keeps the Web API on loopback by default, rejects the CLI’s old 0.0.0.0 exposure path, applies Host/Origin request fencing and adds separate browser token authentication. DeepSeek’s later v0.1.2-alpha.1 release notes explicitly state that network Web access requires the one-time token in the launch URL and reiterate that DeepSeek Harness has not been security-audited and that sandboxing, approvals and permissions do not guarantee isolation. Current v0.1.6-alpha.1 is newer than that remediated application release.
v0.1.5-alpha.1: Session V3 and plugin/runtime boundary changes
Section titled “v0.1.5-alpha.1: Session V3 and plugin/runtime boundary changes”The preceding 8 September upstream prerelease introduced several durable integration changes:
- Dynamic system-prompt updates without invalidating KV cache when the configured model explicitly declares support for the capability.
- Session format V3. Supported historical sessions are upgraded into new log files while originals are preserved; system prompts become part of message history; legacy PTC events and
codepreset references migrate. Custom log readers must adapt, and upgraded sessions are not downgrade-readable by older formats. - Agent plugin API change.
ctx.agentis removed; callers pass the Agent explicitly. Continuable subagent ownership is corrected so those children are not mistaken for root conversations by root-only scheduling. - Inbox API change.
Inboxbecomes a type-only interface rather than a constructable exported runtime class; plugins access pending messages throughagent.inbox, whilehasPendingandclaimare no longer public API. - Queue/steer consistency. The Send button and Enter honor the same busy-session behavior, with queue/steer intent made explicit.
- User ownership of paused goals. The model cannot resume a goal paused by the user; resuming requires user action.
- Project-root failure safety. Permission/I/O failures while finding the project root are reported instead of silently loading instructions from an ancestor project.
- Subagent runtime refresh. Optional Codex and Claude Code subagent plugins move to Codex
0.153.4and Claude Code2.1.263; explicit model configuration remains unchanged.
These are upstream DeepSeek Harness runtime/API semantics. They are not part of UHP 2026-09-12, and they are not silently attributed to HarnessRouter’s older 0.1.2rc1 adapter pin.
HarnessRouter dsh integration: pin remains 0.1.2rc1
Section titled “HarnessRouter dsh integration: pin remains 0.1.2rc1”PR #135 upgraded HarnessRouter’s dsh adapter from 0.1.0rc7 to 0.1.2rc1 because the older pin did not contain the MCP client needed to drive configured servers. HarnessRouter builds the dsh sdk profile with one dsh-mcp-client row per configured MCP server.
The PR records a real TokenRouter-backed dsh turn calling mcp__deepwiki__read_wiki_structure, then a second process resuming the same session and recalling the earlier codeword. It also records a sandbox recycle followed by successful recall, and a bash tool call crossing the relay. Existing dsh virtual environments are version-marked so an old persistent volume rebuilds when the adapter pin changes.
HarnessRouter sets DSH_PERMISSION_MODE=danger-full-access for this integration after measuring that dsh’s SDK sandbox mode could not operate in the container without bubblewrap/Landlock support. That is a HarnessRouter deployment choice and security boundary, not a UHP requirement.
PR #138 exercises the dsh pin in HarnessRouter’s custom-harness dimension. The dimension declares a real MCP server, requires the second turn to call it and judges the stored tool call rather than relying on remote prose. Candidate dsh matrix coverage reported in the PR includes Vercel 189/189, TokenRouter 169/169, Anthropic 40/40, OpenAI 44/44, Azure OpenAI E2 44/44 and Google 55/55 under that run’s conditions. OpenRouter was initially partial because the shared account was empty.
PR #140, merged to HarnessRouter main on 10 September 2026, closes that evidence gap. After the OpenRouter account was topped up, the dsh OpenRouter column was rerun in full on HarnessRouter 0.15.7: 38 model pairs and 189/189 scenario runs passed, with no retests and no substitution. The previously quota-blocked rows, including gpt-5.5 and gpt-6-astra, are therefore no longer failures in that matrix. This is point-in-time provider/runtime evidence, not UHP conformance and not a blanket claim that every future OpenRouter model works through dsh.
HarnessRouter has since advanced to stable v0.17.2. Its dsh package pin remains 0.1.2rc1 in checked current source. Post-release PR #180 removes the false assumption that dsh cannot accept plugin-provided stdio MCP servers and writes the native command-based configuration shape; PR #182 fixes the residual URL-only hosted job filter so that command-based server reaches the compose patch. PR #185 then adapts plugin-provided SSE through a local stdio bridge for dsh, Codex and Goose rather than claiming those pinned clients gained native SSE. Those changes improve the HarnessRouter adapter/runtime boundary without changing the upstream dsh pin.
Native ACP remains a separate protocol boundary
Section titled “Native ACP remains a separate protocol boundary”DeepSeek Harness first-party package documentation describes an ACP v1 automation server over JSON-RPC/stdio. One ACP connection can carry several independent sessions, with session lifecycle, prompt/cancel, semantic assistant/thought/tool/context updates, permission requests and standard MCP-server attachment over stdio or Streamable HTTP. DeepSeek Harness also has an out-of-process ACP subagent client.
Cross-harness subagent composition
Section titled “Cross-harness subagent composition”DeepSeek Harness exposes a concrete subagent capability family. Current documented child paths include:
| Child path | Role |
|---|---|
| In-process spawn | Fresh child inside dsh |
| In-process fork | Child initialized from completed parent history |
subagent-acp | Out-of-process child over ACP |
subagent-codex | Real Codex app-server child |
subagent-claude-code | Claude Code child through the official Claude Agent SDK |
subagent-dsh-sdk | Out-of-process dsh child through the TypeScript SDK |
Continuable children can exchange follow-up messages with the parent, and later prereleases tightened sender attribution, ordering and steering semantics. This is harness composition, not UHP protocol adoption by the child runtimes.
Historical UHP conformance evidence through dsh
Section titled “Historical UHP conformance evidence through dsh”HarnessRouter v0.8.0, published 20 August 2026, added DeepSeek Harness as a backend and published a Full 52/52 UHP run through that integration. That remains valid point-in-time evidence for the 52-check suite then in force.
Current UHP conformance contains 74 checks under package 2026.9.12, and HarnessRouter separately records a current 74/74 Full reference result. The historical dsh 52/52 record is not silently upgraded to 74/74. Likewise, PR #138, PR #140 and the later plugin-MCP transport fixes are runtime evidence, not a DeepSeek-specific current UHP conformance rerun.
Evidence boundaries
Section titled “Evidence boundaries”- Upstream DeepSeek Harness latest:
v0.1.6-alpha.1/ tag0a15e36e; checkedmaster0d1f5000. - HarnessRouter latest release:
v0.17.2/ tag targetfa9ca27d; runtime-relevant post-release cutoffd24b6659through PR #185. A later checked branch head821a95d8is README-only PR #186. - HarnessRouter dsh adapter actually measured from
v0.15.6and still pinned in checked current source:0.1.2rc1. - Native DeepSeek ACP: verified upstream.
- Native DeepSeek UHP: not established.
- Historical UHP conformance through HarnessRouter dsh: 52/52 at the
v0.8.0point in time. - Current HarnessRouter dsh MCP/provider evidence: PR #135 / PR #138 / PR #140 plus PRs #180/#182/#185, implementation-level only; PR #140’s OpenRouter rerun is 189/189 across 38 model pairs with no retests or substitution.
- CVE-2026-82533: advisory affects the upstream application before
0.1.2-alpha.1; do not infer status of HarnessRouter’s separately named Python SDK pin without package-specific evidence.
Because DeepSeek Harness is in developer preview, session formats, plugin APIs, event shapes and child-provider interfaces can continue to change. Pin exact versions when building integrations.
Related pages
Section titled “Related pages”Read HarnessRouter Community Edition, harness composition, UHP vs ACP, UHP vs MCP, conformance, release tracker, adoption and ecosystem.
Primary sources
Section titled “Primary sources”- DeepSeek Harness
v0.1.6-alpha.1 - DeepSeek Harness
v0.1.6-alpha.1tag0a15e36e - DeepSeek Harness checked
master0d1f5000 - DeepSeek Harness
v0.1.5-rc.2 - DeepSeek Harness synchronous-history-reader deprecation
42b50bd3 - DeepSeek Harness
v0.1.5-rc.1 - DeepSeek Harness
v0.1.5-alpha.1 - DeepSeek Harness
v0.1.2-alpha.1 - DeepSeek browser Host API authentication patch
3e24087b - VulnCheck CVE-2026-82533 advisory
- DeepSeek Harness ACP package
- DeepSeek Harness subagent capability family
- HarnessRouter
v0.17.2 - HarnessRouter current runtime cutoff
d24b6659 - PR #185 — bridge SSE to stdio for clients without native SSE
- PR #182 — retain dsh stdio MCP servers in the hosted job
- PR #180 — Pi/dsh stdio plugin admission and writer support
- PR #140 — full dsh OpenRouter matrix rerun
- PR #138 — custom-harness MCP-server verification
- PR #135 — dsh
0.1.2rc1MCP driving - HarnessRouter
v0.8.0 - HarnessRouter
v0.8.0conformance commit