Introduction¶
One of the core ideas of DeepSeek Harness (DSH) is that “everything is a plugin,” allowing developers to enrich agent capabilities through extensions. When an agent needs to interact with a user’s local desktop, calling system interfaces directly can be risky and difficult to audit. aibo204/dsh-plugin-computer-use is a DSH plugin that integrates the native MCP runtime of Open Computer Use, giving agents secure, approval-gated desktop control capabilities and local audit archives.
Plugin Overview¶
This plugin aims to address permission management and security auditing issues when agents perform “Computer Use” in local environments. It is not a default DSH Host capability, but a plugin mounted on an Agent Preset. Each mounted instance corresponds to a native MCP process, an accessibility element snapshot namespace, and an action-based policy. The plugin maintainer is community-based, the project is released under the MIT license, and it has no official affiliation with DeepSeek.
Core Features¶
The plugin provides a set of MCP-based desktop manipulation tools. Models can invoke these tools through the mcp__computer_use__ namespace:
- App management:
list_appslists installed and running apps;get_app_statecaptures app windows, the accessibility tree, and element indexes. - Interaction operations:
clickclicks an element or coordinate;perform_secondary_actiontriggers an action declared by accessibility;scrollscrolls an element or app;dragdrags between screenshot coordinates;type_texttypes literal text;press_keysends a key or key combination;set_valuesets an accessibility control value. - Security and audit: supports on-demand approval and generates local audit archives.
Installation and Enablement¶
Installing this plugin requires first installing the Profile Bundle, then adding a plugin line to the authored Agent Preset.
- Install the plugin
Run the following command to add the plugin to the specified Profile (for example,web):
dsh plugin --profile web add github:aibo204/dsh-plugin-computer-use#v0.2.1
- Handle pnpm dependencies
DSH uses pnpm, and each Profile must make an explicit decision about dependency install scripts. During the initial installation, DSH may add anopen-computer-useplaceholder to the configuration file. To prevent a build script from interrupting the installation, it is recommended to explicitly disable its build in$DSH_HOME/profiles/web/pnpm-workspace.yaml:
allowBuilds:
open-computer-use: false
Save the file, then run the installation command again.
- Configure the Agent Preset
Add the plugin configuration line in the authored Agent Preset YAML file. A typical configuration example is:
- id: computer-use
name: '@aibo204/dsh-plugin-computer-use'
config:
accessPolicy: per-call
automaticScreenshots: before-and-after
- System permission configuration
The plugin relies on a native runtime, and different operating systems have different permission requirements:- macOS 14+: Before first use, run the following command to check and grant permissions:
npx open-computer-use@0.3.1 doctor
The system will prompt you to grant Accessibility and Screen Recording permissions.
* **Linux**: A logged-in desktop environment is required, with support for AT-SPI2/D-Bus accessibility services.
* **Windows**: A logged-in interactive desktop is required, with UI Automation access enabled.
After installation, restart the Profile and start a new Session using that Preset.
Typical Usage¶
- Use dsh-mcp-client: When invoking tools, using
dsh-mcp-clientpreserves the server’s full canonical JSON response, which is important for debugging and auditing. - Audit retention:
dsh-mcp-clientensures that screenshots become persistent model images only whenctx.attachmentsis mounted and the call route declares image input. Otherwise, the result includes explicit image diagnostic information. - Element index updates: After performing control operations (such as
clickortype_text), the app’s cached element mapping becomes invalid. Subsequent actions must be based on the latestget_app_stateresult; otherwise, the indexes may be invalid.
Notes and Limitations¶
- Plugin type: This is an Agent Preset plugin, not a Host capability. Mounting it under the Host root is not supported.
- App list format: The
allowedAppsanddeniedAppssettings use exact strings (for example, bundle IDcom.apple.finder); entries fail if they are empty, contain spaces, duplicate each other, or overlap. - Approval policy:
accessPolicycontrols the approval flow.per-callis the default and prompts for approval before each call;allowauthorizes calls directly (use with caution in deployment). - High-risk confirmation:
highRiskConfirmationis enabled by default and requires secondary confirmation for operations such as sending, deleting, purchasing, and uploading. - License: The plugin is released under the MIT license and does not represent official DeepSeek endorsement.
Summary¶
aibo204/dsh-plugin-computer-use provides DeepSeek Harness with a standardized set of desktop manipulation interfaces and a security audit mechanism. By configuring accessPolicy and automaticScreenshots, developers can keep agent-desktop interactions controllable while recording detailed operational traces.