초대하고 적립

초대 보상 안내

초대 링크를 공유하세요. 친구가 링크로 가입하고 충전하면 이후 충전마다 표시된 보상을 받을 수 있습니다.

DeepSeek Harness: 시작, mode, plugin 경계

안전한 DeepSeek Harness 첫 run: isolation, mode, Trajectory, plugin audit, 적용 경계입니다.

목차

DeepSeek Harness: 시작, mode, plugin 경계

DeepSeek는 Harness를 Developer Preview라고 합니다. 첫 goal은 production rollout이 아니라 isolated folder에서 관찰 가능한 read-only run입니다. custom endpoint 전에 schema, Base URL, auth를 확인하세요. BetterToken API Docs는 자신의 Key를 설명하지만 모든 plugin compatibility를 보장하지 않습니다.

격리된 시작

npx @deepseek-ai/dsh web

secret이나 uncommitted work가 없는 empty folder/clean clone을 씁니다. Standard에서 entry point만 찾게 하고 actual files와 비교합니다.

mode 선택

mode용도첫 check
Standardfull agenttools/actions
PTC읽을 수 있는 orchestrationgenerated TypeScript
Minimaldiagnostic baselineextra 없는 동작
Creationcustom presetplugins/dependencies

PTC는 better result를 약속하지 않으며 Minimal은 baseline, Creation은 설정 이해 뒤에 사용합니다.

Trajectory 검토

append-only event stream에서 실제 files, tools, outputs, context sources를 봅니다. path/output이 다르면 prompt를 바꾸기 전에 access나 context를 고칩니다.

plugin audit

plugin마다 부족 capability, 닿는 data/service/permission, regression signal, rollback을 적습니다. community bundle 전 source와 dependencies를 읽고 preview에서는 run마다 component 하나만 바꿉니다.

permission과 secret

test folder가 shell을 자동으로 안전하게 만들지 않습니다. minimal permission만 주고 deploy를 막으며 API Key, cookie, .env를 preset, prompt, Trajectory에 넣지 않습니다.

적용 또는 보류

model과 tool layer를 분리하거나 reproducible preset을 만들 때 적합합니다. disposable environment, diff review, log process가 없으면 real data 사용은 보류합니다.

CTA와 sources

허용된 API test는 BetterToken API Docs로 자신의 Key만 설정하고 작은 read-only task부터 시작하세요.

Developer Preview를 이해하고 첫 실행 범위를 정하기

공식 저장소는 MIT 라이선스이며 Cordis로 plugin을 로드, 제거하고 의존성을 관리합니다. Harness가 단독으로 agent 능력을 제공하는 것은 아닙니다. model, tool, session, sandbox, storage, agent loop, UI가 교체 가능한 plugin으로 구성됩니다. 따라서 model만 바꾸어 비교할 수 있지만, plugin 하나를 추가하면 agent가 접근할 data, permission, 외부 service도 달라질 수 있습니다.

Developer Preview는 운영 조건입니다. DeepSeek는 호환성을 깨는 변경이 있을 수 있다고 알립니다. 오래된 글의 option이나 preset을 안정된 계약으로 취급하지 말고, real data를 쓰기 전에 공식 quickstart와 현재 README를 다시 확인하세요.

첫 시작, provider 설정, 성공 확인

현재 문서가 요구하는 Node.js를 설치한 뒤 공식 Web UI command를 실행합니다.

npx @deepseek-ai/dsh web

browser를 자동으로 열지 않고 server만 시작하려면 —no-open을 사용합니다. secret, cookie, .env, uncommitted work가 없는 empty folder나 clean clone을 만들고 Standard를 고릅니다. 첫 task는 entry point 찾기나 project 구조 설명처럼 write 없는 작은 작업이어야 합니다. 결과를 실제 file과 session event에 대조한 다음에만 제한된 edit와 diff review를 허용합니다. test folder는 shell을 자동으로 안전하게 만드는 기능이 아니라 설정 오류의 영향 범위를 줄이는 방법입니다.

custom API endpoint를 연결한다면 plugin 설치 전에 provider별 protocol, Base URL, authentication, model을 확인합니다. BetterToken은 custom Base URL을 허용하는 tool에 OpenAI-compatible 및 Anthropic-compatible interface를 제공하지만, 모든 Harness plugin 호환성을 보장하지는 않습니다. BetterToken API Docs에서 자신의 Key와 provider schema를 확인하고, 최초 request는 read-only task로 제한하세요.

네 가지 mode를 고르는 기준

mode용도먼저 검토할 증거
Standardfile edit, shell, search, skill, plan, goal, subagent, workflow를 포함한 coding agent실제로 열린 tool과 실행된 action
PTCCode Mode SDK로 여러 tool call을 TypeScript program으로 조합generated TypeScript, input, 각 tool 경계
Minimalpersistent bash와 str_replace_editor만 있는 baseline추가 orchestration을 뺀 뒤의 차이
Creationruntime inspection, memory의 Cordis plugin 실험, preset 생성preset이 추가한 plugin, dependency, permission

첫 실제 작업은 Standard가 적합합니다. PTC는 orchestration을 읽고 재현해야 할 때 쓰며 더 좋은 결과나 안전을 약속하지 않습니다. Minimal은 일상용 경량 mode가 아니라 skill, search, UI의 영향을 보는 기준입니다. Creation은 현재 configuration을 이해한 뒤 custom preset을 설계할 때 사용합니다.

Trajectory와 plugin audit의 실제 사용법

Trajectory는 system prompt, model에 보인 context, tool call과 result, subagent schedule, context injection을 append-only event stream으로 남깁니다. 첫 task 뒤에는 agent가 실제로 본 file과 command output, 예상하지 못한 context/tool call, permission·tool·instruction·context 중 어떤 이유로 멈췄는지, 성공 경로를 빈 conversation 없이 재현할 수 있는지를 확인합니다.

configuration을 만드는 위치만 찾게 하고 write를 금지한 뒤, path, command, output을 Trajectory와 repository에서 비교해 보세요. 다르면 prompt를 다시 쓰기 전에 access와 context부터 고칩니다. Trajectory는 audit trail이지 API Key, 비밀 prompt, production log를 두는 장소가 아닙니다.

plugin마다 필요한 capability, 닿을 수 있는 file/data/service/permission, regression signal, 이전 preset으로의 rollback을 기록합니다. dsh-plugin topic의 community bundle도 install 전에 source와 dependency를 읽습니다. Preview에서는 run마다 component 하나만 바꾸고, 작은 task라고 deploy, migration, secret manager, 광범위 write access를 허용하지 않습니다.

검증, 문제 분류, 도입 판단

최소 검증은 task 이해, log action과 실제 file의 일치, 사람의 diff 또는 output review입니다. 그 다음에는 discardable branch write, tool 추가, plugin 테스트를 한 번에 하나씩 진행합니다.

  • file이 틀리거나 없으면 working directory, read permission, 전달한 context를 확인합니다.
  • command output이 설명과 다르면 Trajectory event, tool version, 실제 output을 봅니다.
  • provider가 응답하지 않으면 protocol, Base URL, authentication, model을 해당 Docs에서 재확인합니다. 한 error만으로 plugin 비호환을 결론내리지 않습니다.
  • plugin이 access surface를 과도하게 넓히면 끄고 이전 preset으로 돌아가 다시 실행합니다.

model과 tool layer를 분리해 조사하거나, 여러 단계 workflow를 event로 debug하거나, 재현 가능한 preset이 필요하면 Harness를 시험할 가치가 있습니다. disposable environment, diff review, log 검토 절차가 없으면 real data 도입은 보류하세요. 허용된 API test에서는 자신의 BetterToken Key와 API Docs를 사용해 짧은 read-only task부터 시작하고 Docs URL에는 UTM을 붙이지 마세요.

LLM 워크플로를 최적화할 준비가 되셨나요?

하나의 API로 모델을 연결하고 키와 AI 비용을 관리하세요.

무료로 시작하기