Skip to content

DeepSeek Harness Capability Map ​

The reference inventory behind the exploration lesson plan. Every row is a capability that ships in the repository checkout, named by the package or seam that provides it. The Lesson column points at the guided lesson that puts that capability under your hands.

Reading that column. A link means the lesson teaches or exercises the capability. An em dash (—) means it ships in the harness but no lesson here covers it — this is a path through the harness, not a survey of it, and saying so is more useful than a link that does not deliver.

Sources: the plugin model, the architecture doc's "where new behavior goes" table (docs/architecture.md), the tool schema catalog (docs/tool-catalog.md), and the shipped bundle patches (packages/bundle/base/cordis.patch.yml, packages/bundle/web-app/cordis.patch.yml).

1. Plugin core — the defining capability ​

CapabilityProvided byLesson
Everything-is-a-plugin composition into one shared contextCordis coreL1
Two plugin shapes exercised: function, Service subclass (the object form is documented upstream, not taught here)CordisL1, L3
Fiber lifecycle PENDING → LOADING → ACTIVE → UNLOADING → DISPOSED, plus FAILEDCordis registryL1
Reversible effects — registrations unwind on unloadctx.on, ctx.plugin, ctx.effectL1, L2, L3
Dependency injection and load ordering via injectCordis servicesL3
Typed events in five dispatch modes: emit, parallel, serial, bail, waterfallCordis events—
Config validation before apply runs (Schemastery)Cordis configL2
Service isolation — two groups seeing different instances of one service nameCordis isolate realmsL3
!!js load-time config and disabled expressionsLoaderL2
Profiles, bundles, patches; ordered composition at bootdsh-base, dsh-web-app, dsh-headless, dsh-sdk-appL1, L2
Live config inspection — dsh --dump-config, --dump-config-schemaapps/cliL1, L2
Hot module reload of changed plugins@deepseek-ai/dsh-hmrL3
Read-only live loader-tree projection@deepseek-ai/dsh-host-plugin-inventoryL3
Runtime define/run of Cordis packages, host and browser halvesextensions/{tool-cordis,cordis-host-runner,cordis-client-runner,ui-cordis}—

2. Extension seams — where new behavior attaches ​

Seamctx key / eventLesson
Model providerregister adapter on ctx.llm— (see cookbook)
Model-facing capabilityctx.tools.register(...)L2
Per-session capability setagent preset (a service row there needs an isolate realm)L9
Shell execution backendctx.shell (bash-local, bash-sandbox, pwsh-*)— (swap providers, not author)
Persistent terminal backendctx.terminals + dsh-tool-terminal—
Human command (no model turn)ctx.commandsL5
Background workctx.jobs.start(...) + job_* tools—
External webhook → new Sessionctx.webhookRuntime + a provider adapterL9
Filesystem provider or policyctx.fs provider, fs/* eventsL4
Process confinementctx.sandbox backendL4
Interception of requests, tools, turnsagent/*, tools/* eventsL4, L5
Monotonic tool guards — a denial no later listener can reversectx.tools.guard()L4
Model-facing context injectionagent.inject()L5
Durable session statectx.sessionProjections.register(…) folding a known first-party eventL6
Stored-event vocabulary validation — a log containing an unknown event type is refused unless the event is marked ignorablevalidateStoredEvents, KNOWN_SESSION_EVENT_TYPESL6, L7
Skill discoveryskill-filesystem (customSkillDirs) + the skill toolL5
UI / editor integrationctx.agents, session/event, ConversationNodeDefinition—
Session title generationctx.sessionTitle provider—

3. Agent runtime ​

CapabilityProvided by
Agent loop, turn/step admission, steering and follow-upsdsh-agent, dsh-agent-loop
System-prompt assembly (tool schemas join it automatically)dsh-system-prompt
Plan mode with an approval gatedsh-plan-mode
Same-session objectives across rounds (create_goal/get_goal/update_goal)dsh-goal, dsh-goal-round-driver
Todo checklist statedsh-tool-todo
Conversation compaction, image offload, tool-result pruningcompaction-*
Token metering and cost accountingdsh-token-meter
Timeout policy, repeat-tool reminderguard/timeout-policy, guard/repeat-tool-reminder
Output spill and truncation policiesspill-local, spill-policy

4. Tool surface ​

GroupTools
Filesystemread, write, edit, read_image, str_replace_editor
Shellbash, pwsh (one-shot; *_run_in_background), persistent PTY variants
Discoveryglob, grep (packaged ripgrep via ctx.subprocess)
Terminal controlterminal_open/read/send/signal/list/close
Webweb_search, web_fetch (providers: deepseek, exa, perplexity, http)
Code as glue (PTC)run_code in mode: ptc / both — programs call visible tools as await tools.<name>(args)
Language intelligencelsp (provider behind ctx.lsp, e.g. lsp-stdio)
MCPMCP client plus list_mcp_resources, read_mcp_resource, list_mcp_resource_templates
Human interactionask_user_question, approval prompts, exit_plan_mode
Deliverablespresent, workspace-changes diffing, office-to-pdf
Introspectioncordis_inspect_list, cordis_inspect_query, plugin_manager, load_workspace_dependencies
Session historysession_search, session_trace, session_event_read/search/trace

5. Delegation and orchestration ​

CapabilityProvided byLesson
Delegate one focused task to an isolated contextsubagent tool + subagent-spawn-in-processL8
Fork the current conversation into a childsubagent_fork + subagent-fork-in-processL8
Continuable children: message, interrupt, listsend_message, interrupt_agent, list_agentsL8
Scripted fan-out with phases, pipelines, barriers, schema-validated resultsworkflow tool + ctx.workflowEngineL8
Fresh child per round on one immutable objectiveralph tool—
Alternative delegation backends (ACP, Claude Code, Codex, dsh-sdk)subagent-* providersL8
Roster + task board + mailbox coordinationexperimental agent-team (ctx.agentTeams)L8

6. Context engineering ​

CapabilityProvided byLesson
AGENTS.md / CLAUDE.md auto-loading with directory precedencedsh-agent-instructionsL5
Skills (filesystem, office, badges) loaded on demandskill*, tool-skillL5
File and session references with @path semanticsfile-reference*, session-reference—
Ambient time and tmux contexttime-context, tmux-context—
Credential redaction in contextdsh-credentialsL4

7. Sessions, state, and persistence ​

CapabilityProvided byLesson
Durable session log as the source of truthdsh-session, session-formatL6
JSONL persistence with versioned migrationssession-persistence-jsonl, session-format-vN-to-vN+1—
Incremental projections and cached client viewssession-projection, session-projection-cacheL6
SQLite session query and exportsession-query-sqlite, session-log-export—
Fork and resume at a turn boundaryctx.agents.create({ seed, inheritedEventCount, meta }) / ctx.agents.resumeL6, L8
Checkpointing policysession-checkpoint-policy—

8. Web GUI and client ​

CapabilityProvided by
Session/conversation surfaces and streaming renderclient/ui-*, web-runtime
Approval prompts and permission presetsui-approval, permission-presets
Right sidebar: files, terminal, browser, document previewui-sidebar-*
Plugin manager and plugin inventory UIui-plugin-manager, ui-settings-plugin-inventory
Settings cards contributed per pluginui-settings-*, settings-controller
File upload, directory picker, open-in-appfile-upload, directory-picker*, open-in-app
Deliverable cards, workspace diffs, goal and jobs panelsui-deliverables, workspace-changes, ui-goal, ui-jobs
Theming, i18n, shortcuts, client HMRui-theme, locale, ui-shortcuts, client-hmr

9. Integration and automation ​

CapabilityProvided byLesson
TypeScript SDK (spawns a runtime, drives turns)packages/sdk/clientL9
Python SDK over the same protocolpython/L9
Newline-delimited JSON-RPC wire protocolsdk/protocol, sdk/serverL9
Agent Client Protocol server for programmatic clientspackages/acp—
One-shot headless executiondsh-headless bundleL9
Scheduled wakes (interval, absolute, daily/weekly, cron)dsh-schedule + schedule_* toolsL9
Webhook-triggered sessions, including GitHub eventswebhook, webhook-githubL9
Hook protocol adapters for Claude Code and Codexhooks-*, hook-protocolL9
Remote execution over SSHssh, fs-ssh, subprocess-ssh, sandbox-ssh—
HTTP API gateway with controllerspackages/api/*—
Browser automation and computer usebrowser-use*, computer-use* (experimental)—
Speech-to-text and voice inputexperimental/speech-to-text*—

10. Model providers ​

CapabilityProvided by
DeepSeek API key and account-backed routesllm-deepseek, llm-deepseek-api-key, llm-deepseek-account
Third-party providers (e.g. OpenRouter) with per-model reasoning controlllm-pi-ai
Retry and fallback policyllm-retry
Sandboxed execution backendssandbox-local, e2b, sandbox-windows-acl

See OpenRouter integration & reasoning error hardening for the verified provider-configuration recipe.

11. Observability and operations ​

CapabilityProvided byLesson
OpenTelemetry traces and metricsotel, session-telemetry-otelL7
Token/cost accounting per sessiontoken-meter, session-statsL7
Trajectory replay from the durable logsession-projection, session-queryL7
Runtime invariant checkingruntime-diagnostics/invariantsL7

Deploy-time hardening guidance is not published by DSH as documentation; it lives in the package READMEs for the container, session-store, and telemetry packages, plus your own operational judgment. Treat every row above as a capability to harden rather than a deployment recipe.

Independent, unofficial teaching resource. DeepSeek Harness is by DeepSeek AI, MIT licensed.