Preface

DeepSeek Harness (DSH) is a system with a plugin-based core architecture. When building complex agent workflows, developers often need to integrate external services or tools. OrgX provides MCP tools and work ledger access capabilities, and useorgx/orgx-deepseek-harness-plugin is the plugin used to integrate OrgX into DSH.

Plugin Positioning

This is a developer preview plugin designed to add OrgX MCP tools to DeepSeek Harness profiles and provide an OrgX gateway peer that runs within the workspace.

  • Name: @useorgx/deepseek-harness-plugin
  • Owner: useorgx
  • License: MIT
  • Core value: OrgX MCP tools, Work Ledger access, and a Sovereign Execution peer for DeepSeek Harness.

Core Features

This plugin mainly performs the following tasks:

  1. Integrate OrgX tools: Add OrgX MCP tools to the DeepSeek Harness configuration.
  2. Run Gateway Peer: Run an OrgX gateway peer bound to the workspace using Harness headless mode.
  3. Mount client: Mount a dsh-mcp-client instance named orgx to communicate with OrgX services.

Installation and Enablement

It is recommended to use the OrgX-provided wizard for installation and configuration.

  1. Run the OrgX wizard to initialize setup:
    npx @useorgx/wizard@latest setup
  1. Trigger a DeepSeek task via the wizard to refresh the OAuth Token and ensure credentials are ready before DSH starts:
    npx @useorgx/wizard@latest deepseek "List the OrgX tools available in this workspace."

For advanced users, the plugin package can also be installed directly. The DeepSeek Harness version must be pinned to 0.1.0-rc.6, and the Node.js version must be ^22.19.0 or >=24.0.0.

dsh plugin --profile headless add @useorgx/deepseek-harness-plugin@0.1.0

Typical Usage

After installation, you can invoke OrgX tools or check the configuration in the DSH headless profile:

dsh --profile headless "List the OrgX tools available in this workspace."

Check the currently mounted configuration:

dsh --profile headless --dump-config

Notes and Risks

Because this is a developer preview release, note the following specific limitations and risks when using it:

  1. State validation: Successful installation of the plugin package does not imply that OrgX authentication succeeded, gateway admission succeeded, or the deployment is ready. If the MCP connection or initial tool synchronization fails, the DSH bundle will not start.
  2. Missing capabilities: The current version does not support accessing MCP Resources and Prompts through this client. In addition, non-text MCP blocks undergo lossy projection on the model side, even if local execution results preserve the JSON block.
  3. Host access permissions: The peer sets its execution directory inside ORGX_WORKSPACE_ROOT. This establishes a path and mutation boundary, not host isolation. DSH workspace-write permission does not restrict file reads, process visibility, or network access for the same user.
    • To use this capability, set the environment variable ORGX_DEEPSEEK_HOST_ACCESS_ACK=1 and configure it manually after accepting the associated risks.
  4. Credential scope: The API key must be authorized for gateway:drive and plugin:heartbeat.
  5. Auth mechanism: The OAuth Token must be a client-managed OrgX OAuth 2.1 access token. Gateway keys starting with oxk_ are not applicable to managed MCP.

Summary

This plugin provides a pathway for DeepSeek Harness to integrate with the OrgX ecosystem, allowing OrgX MCP tooling and work ledgers to be used directly within Harness. Given its developer preview status and its particular design around host access permissions, developers should carefully evaluate permission boundaries and missing features before use.