DeepSeek Harness Permissions & Sandbox Security
New sessions default to the workspace-write preset, but reads, network access and process visibility are not described as fully confined. The Python minimal example is more permissive and explicitly uses danger-full-access, so deployment surface matters. This page separates verified behavior from community reports and marks the release-candidate context so you can act without mistaking an observation for a permanent guarantee.
What is verified now
New sessions default to the workspace-write preset, but reads, network access and process visibility are not described as fully confined. The Python minimal example is more permissive and explicitly uses danger-full-access, so deployment surface matters.
Evidence basis: Official permission and Python danger-full-access docs. The status was checked on 14 August 2026; re-check the linked source after any dsh release.
Safe workflow
Use the smallest reversible workflow first. Do not add community plugins or paste credentials while validating the base behavior.
- Assume extensions and server commands can execute code.
- Review requested permissions, scripts, environment and network access.
- Use an isolated profile/workspace and preserve a rollback path.
Verify before moving on
A successful result should be observable: a version string, reachable local URL, valid provider response, loaded configuration, or disappearance of the exact error. If the result differs, stop and capture sanitized evidence rather than stacking unrelated fixes.
- Record the exact dsh, Node or Python version.
- State the operating system and installation method.
- Link the first-party source and include only sanitized logs.
First-party sources
Open the original source before acting on a changed version or unresolved community report.