Security notes

Know which layer you are trusting.

This page documents the desktop shell's boundaries. DeepSeek Harness has its own permissions, credentials and sandbox behavior; consult the upstream project for those controls.

Local service exposure

The desktop app always starts DSH itself on a loopback address. Phone remote is off by default; when the Owner explicitly enables it, the desktop shell opens a self-signed HTTPS proxy on the LAN. Devices must complete one-time QR Pairing and use a revocable Device credential. Paired Devices can be revoked individually, and sensitive settings/credential methods remain behind a separate Host-side grant.

What the desktop shell can access

The Go host starts a local process, opens the embedded Web UI, reads startup output and writes its own log. Project files, tools, model credentials, sessions and plugins are managed by the upstream Harness runtime rather than reimplemented by this shell.

Data locations

DataOwner / location
Desktop startup log~/.dsh-desktop/logs/dsh.log
Harness profiles and sessionsManaged by DSH; configurable through DSH_HOME
npm download cacheApplication-specific cache used for the pinned DSH package

Current signing status

macOS packages are signed with a Developer ID certificate and notarized by Apple since v0.1.9; Windows executables are not code-signed. SmartScreen may still warn on Windows. Download only from the project's GitHub Releases page and inspect the public source if this trust level is not acceptable.

Network access

The shell needs npm network access on first launch or when its package cache is empty. Model provider traffic is initiated by DeepSeek Harness according to the providers configured by the user.

Reporting a vulnerability

Do not publish sensitive exploit details in a public issue. Until a dedicated private reporting channel is configured, open a minimal GitHub issue asking the maintainer for a private contact path.

Non-affiliation

This is an unofficial community project. It is not developed, endorsed or supported by DeepSeek AI.