Native, foreground-safe macOS computer use for DeepSeek Harness — fresh Accessibility observations, target-process input, scoped leases, and one-use confirmation for sensitive actions.
DSH integration
Native runtime
Author-claimed
Safety audit
Unaudited
Last verified
2026-09-03
License
MIT
01What can it help you accomplish?
Let an Agent inspect and control macOS applications with fresh Accessibility observations
Bounded Accessibility tree, indexed elements, exact app/process/window metadata, permission state, and an optional screenshot Artifact
Agents and developers running DeepSeek Harness (dsh) on macOS who need reliable native GUI automation
Route keyboard and pointer input to a target process without stealing focus or moving the system cursor
Target-process-bound keyboard/pointer events plus a separate non-activating Agent cursor; pid/window targeted, never global HID
Operators who need foreground-safe computer use while the user keeps working in the current app
Gate high-impact actions behind one-use confirmation tied to exact state
A short-lived, one-use confirmation token bound to the exact app, process, observation, target handle, and action
Security-conscious users who require explicit approval before sensitive macOS input
02How to install into DeepSeek Harness
Prerequisites
- macOS 14 or newer
- DeepSeek Harness with a Web or Headless Profile and the Skill Tool mounted
- macOS Accessibility permission for observation and native actions
- macOS Screen Recording permission only when a screenshot is requested
- Node.js ^22.19.0 or >=24.0.0 when building this repository from source
Installation steps
- 01
Install the published npm package into a Web profile: `dsh plugin --profile web add @anionex/dsh-computer-use`
$ dsh plugin --profile web add @anionex/dsh-computer-use
- 02
Install into a Headless profile: `dsh plugin --profile headless add @anionex/dsh-computer-use`
$ dsh plugin --profile headless add @anionex/dsh-computer-use
- 03
Restart a running `dsh web` host, start a new Session, then load the Skill with `/computer-use`
$ dsh web
Verify the integration
- Confirm the bundle is registered: `dsh --profile web --dump-config | grep computer-use`
- Restart the host and start a new Session so the Bundle and Skill catalog reload
Rollback
- Remove from the Web profile: `dsh plugin --profile web remove @anionex/dsh-computer-use`
- Remove from the Headless profile: `dsh plugin --profile headless remove @anionex/dsh-computer-use`
03DSH integration and capability boundaries
Native macOS action layer (DSH Bundle) mounted via `dsh plugin add`; exposes Computer Use Tools after loading the `/computer-use` Skill
Observe
target application bundle id and pid→fresh full/diff Accessibility observation and optional screenshot Artifact
Click
exact element index or opaque targetHandle (with optional safe rebinding)→target-process coordinate click after semantic AXPress preference
may activate the target app before keyboard input when keyboardPolicy: activateType text
Unicode text and target process→inserted text via Accessibility, with process-targeted keyboard fallback
process-targeted keyboard fallback may activate the target app firstConfirm
one exact sensitive action→a one-use token bound to the exact app, process, observation, target handle, and action
Scope application access
Agent, Session, turn, and exact bundle id→separated read and control leases; high-impact actions require one-use confirmation
04Who is it for? When not to use it?
Good for
- Agents and developers running DeepSeek Harness (dsh) on macOS who need reliable native GUI automation
- Operators who need foreground-safe computer use while the user keeps working in the current app
- Security-conscious users who require explicit approval before sensitive macOS input
Not for
- The current provider is macOS-only (macOS 14+); Windows UI Automation and Linux providers are not implemented, so non-macOS hosts register no Computer Use Tools.
- The plugin needs macOS Accessibility and Screen Recording UI permissions (not filesystem permissions); normal use stays under DSH workspace-write and screenshots remain in the Session workspace.
- The clicked point must fall inside an on-screen window of the selected app; minimized, hidden, or windowless targets fail closed rather than switching to global input.
05Compatibility, maintenance and safety notes
- The current provider is macOS-only (macOS 14+); Windows UI Automation and Linux providers are not implemented, so non-macOS hosts register no Computer Use Tools.
- The plugin needs macOS Accessibility and Screen Recording UI permissions (not filesystem permissions); normal use stays under DSH workspace-write and screenshots remain in the Session workspace.
- The clicked point must fall inside an on-screen window of the selected app; minimized, hidden, or windowless targets fail closed rather than switching to global input.
- No Tool accepts AppleScript, JXA, shell, Swift, Objective-C, native selectors, arbitrary Accessibility constants, or source code; the model cannot override host policies through Tool arguments.
MIT · actively maintained (latest release v0.3.1, 2026-09-02)
06Frequently asked questions
How do I install DSH Computer Use for DeepSeek Harness?
Add the published npm package `@anionex/dsh-computer-use` to a Web or Headless profile with `dsh plugin --profile web add @anionex/dsh-computer-use`, then load the Skill with `/computer-use` in a new Session.
Does it move my real cursor or steal focus?
No — the default route has no cursor-warp path and uses a target-process SkyLight route, not global pointer injection; the Agent cursor is a separate non-activating overlay that never replaces the macOS system cursor.
Which platforms are supported?
The current provider is macOS-only (macOS 14+); Windows UI Automation and Linux providers are not implemented. On non-macOS hosts the plugin degrades gracefully and does not register Computer Use Tools.
How are sensitive actions guarded?
High-impact actions require a short-lived, one-use `computer_confirm` token bound to the exact app, process, observation, target handle, and action; grants never bypass it.
How is my data kept safe?
The plugin needs macOS Accessibility and Screen Recording (UI) permissions, not filesystem permissions; observations use scoped read/control leases and secure text values are emitted as `[secure]`.
07Related DSH workflows
open-design
by nexu-io
🎨 Best DeepSeek Harness Design Plugin. The open-source Claude Design alternative. 🖥️ Local-first desktop app. 🖼️ Your coding agent becomes the design engine: prototypes, landing pages, dashboards, slides, images & video — real files, HTML/PDF/PPTX/MP4 export. 🤖 Claude Code / Codex / Cursor / DeepSeek Harness / OpenCode & 20+ CLIs via BYOK.
dsh-desktop
by anywhere-labs
Modern desktop client for the DeepSeek Harness (dsh) plugin ecosystem. Everything is a plugin — even the desktop shell itself.
picgo
by molunerfinn
:rocket: The Ultimate Image Uploader for Efficient Creators. Supports Obsidian, Typora, VS Code etc. and 60+ image hosting services (S3, GitHub, Cloudflare R2, Imgur, Aliyun OSS...). Paste, upload, done.
dsh-desktop
by dataelement
Modern desktop client for the DeepSeek Harness (dsh) plugin ecosystem.
08Data and sources
**Native macOS control for DeepSeek Harness that keeps your real cursor and foreground application alone by default
DSH Computer Use gives an Agent fresh Accessibility observations, exact process/window targeting, stale-state rejection,…
Semantic Accessibility comes first; mouse, drag, wheel, and keyboard fallback are routed to the selected process instead…
This page is generated from the project’s public documentation, repository metadata and a structured parse of DSH Plugins; last verified on 2026-09-03. Found an error? Submit a correction.
Best DeepSeek Harness Plugins
Twelve plugins worth installing first — picked from the whole catalog, across every category.
