I Used DeepSeek Harness and ZCode on Real AI Projects — One Broke Me, One Shipped
A developer’s comparison of stability, cache costs, data security, and the moment I stopped debugging plugins and started finishing work.

dsh and ZCode: a practical comparison
In August 2026, two tools appeared on developers' screens at almost the same time. On August 11, ZCode announced that its user count had passed 1 million. Three days later, DeepSeek open-sourced DeepSeek Harness late at night. Its command-line entry point was called dsh. On GitHub, dsh's star count passed 50,000 within twelve hours. In forums, people posted screenshots, wrote long posts, and installed both tools on the same machine, switching back and forth.
A developer sat in front of a monitor. He installed dsh first. In the terminal he typed dsh --profile tui. A line appeared: Error: duplicate prefix route /sidebar/api. He blinked, then opened GitHub Issues. Someone had already reported it. dsh-web-ui-all 0.2.0 included a loading entry for dsh-better-sidebar. The profile also declared a plugin with the same name. Both instances registered /sidebar/api, and the backend exited on startup. The interface went white, and the browser showed ERR_FAILED.
He followed the thread's advice and manually removed the conflicting package from the bundles array. The error disappeared. He went back to writing code. The next day, he installed a new plugin from the plugin market. dsh's reconcilePlugins logic silently wrote the package back into the bundles array. package.json was rewritten as a whole. The terminal went white again. He assumed the new plugin was broken. He uninstalled it, reinstalled it, and changed versions. He kept at it until two in the morning, when he found that dsh itself had put the conflicting package back.
This was not the only report. In dsh's GitHub Issues, someone posted a session file after a crash. A crash left behind an orphan tool call id, a call that would never have a result. After that, every round of dialogue failed during model serialization: An assistant message with 'tool_calls' must be followed by tool messages responding to each 'tool_call_id'. That session was dead. In the community, dsh-fix and dsh-doctor appeared. One repaired configuration damage. The other disabled plugins that crashed on startup and isolated broken session files. The framework needed outside repair tools to run. That fact says enough.
On ZCode's side, he opened the desktop client, logged in, and dragged the project folder in. In Goal mode he typed: "Keep first-screen load time under 2 seconds and make sure all existing tests pass." ZCode began breaking down tasks, changing code, running commands, and executing tests. If the target was not met, it went another round. He closed his laptop and went out to eat. On his phone he opened Feishu, and Remote Control showed progress. The code and commands were still running in the original desktop environment. The project was not synced to the phone. He replied "continue," then locked the screen.
How they are built
dsh's design is described in DeepSeek's documentation: Agent = Model + Harness. The model handles reasoning. The Harness handles file reading and writing, command execution, tool calls, and context management. dsh turns every part of that layer into a plugin. Model adapters are plugins. Tool registration is a plugin. The Agent main loop is a plugin. The sandbox is a plugin. Approval policies are plugins. The UI is a plugin. The foundation is the Cordis meta-framework, which the documentation describes as "spatiotemporal composability."
This design gives you a system you assemble yourself. You can use the 100-plus official plugins to quickly build a coding Agent, or replace any link with a plugin you write. The freedom is high. The cost is that a basic feature, such as @ file references, needs a plugin. Third-party plugin quality varies. One plugin error can crash the whole application.
ZCode takes another approach. From code parsed out of the Electron asar, ZCode is built on the Vercel AI SDK. It mainly uses the AI SDK's data and tool protocols, its provider accumulation, and the classic streamText and generateText. One detail: it did not use the newer Agent class in the AI SDK. It chose streamText to build the main loop. The Agent class wraps too many details, which makes fine-grained changes inside the loop difficult. This restrained design choice gives ZCode a stability advantage over building from scratch. It works out of the box.
Stability
dsh's stability problems are common in Issues. Beyond the plugin double-loading mentioned earlier, there are harder cases. A user manually deleted the conflicting package, and the error disappeared for a while. But the next time he installed or updated any plugin from the market, dsh's reconcilePlugins logic silently wrote the package back into the bundles array. package.json was rewritten as a whole, with no warning. dsh crashed again. The user assumed the newly installed plugin was at fault and went through repeated troubleshooting.
Crashes also leave aftereffects. After one crash, a session may retain an orphan tool call id. After that, every round of dialogue fails during model serialization. The session is basically dead. The community produced dsh-fix and dsh-doctor for this. A framework that needs a doctor and a repairman to run normally says something by itself.
ZCode's stability comes from building on the Vercel AI SDK. Rather than building every layer itself, it avoids many low-level risks. A user scale of one million is itself a stability test. Zhipu's official tests on Z.ai Code Bench show that GLM-5.2 with ZCode has an overall task pass rate 2.39% higher than with Claude Code.
Of course, ZCode is not perfect. Reports on macOS Apple Silicon described ZCode 3.1.6 as unusable through all entry points. The desktop client showed EPIPE and a blank renderer. The CLI lacked @zcode/tui. Login reported "OAuth response is not valid JSON." At a scale of one million users, such problems are isolated cases, not the systemic risk dsh has.
Cost
Both tools claim high cache hit rates. The value is different.
ZCode's official data shows that GLM's cache hit rate in ZCode stays above 98%, and effective token volume rises by about 30%. In a comparison, ZCode's 98.10% is higher than Pi's 95.95%, Claude Code's 95.30%, OpenCode's 95.17%, and Cursor's 95.02%. The key is stability. That number holds across usage scenarios.
dsh's cache hit rate can also reach 99% or even 100% in daily use. But some users found that after session recovery, the cache hit rate can fall to 0-3%. If you close a session and resume it later, token costs can rise without warning. For developers doing AI projects, that unpredictability is more dangerous than a slightly lower but stable rate. You do not know what your API bill will be at the end of the month.
Data security
If dsh's stability problem is a technical problem, ZCode's data security problem is a matter of principle.
In September 2026, the developer community reported that after a user logs in, ZCode snapshots the entire workspace in the background. The snapshot includes the full .git history, LFS files, and reflog. It encrypts the snapshot and sends it directly to Alibaba Cloud OSS. ZCode's UI settings have two related switches, but neither can stop the upload itself. The "experience optimization" switch only controls whether data is used to train models. The "repository snapshot index" switch only decides whether the cloud builds an index. Neither can turn off the silent packaged upload. A user traced ZCode's version evolution and found a step-by-step design. Version 3.5.3 first shipped a "local rollback checkpoint" feature to get users used to the concept. Version 3.10.0 put the upload feature under the same vocabulary. By versions 3.11.0/3.11.1, full collection took shape.
This is serious for enterprise users. ZCode has no SSO, no organization-level audit, and no data boundary. Code repositories, terminal output, and Git history all pass through Z.ai's orchestration layer. BYOK only swaps the model for inference. It does not change who sees your code.
dsh has an advantage here. It runs locally, and model routing, file access, and persistence all stay local. Your code does not leave your machine. The cost is that you have to weigh dsh's instability against ZCode's data collection.
Plugin community and usability
dsh's plugin community grew quickly within a few weeks. GitHub reached 149,000 stars and 15,000 forks, with more than 5,100 plugins and 3,500 authors. One developer rebuilt the installer with Tauri and compressed it to 100 MB. Another used Python + pywebview to get it down to 18 MB. DeepSeek officially released Skills its engineering team uses daily, including code review by repository standards, catching over-engineering and dead code, and more.
The plugin system also has usability problems. One user review said: "Not very friendly to non-developers." Another said: "Ugly interface, cannot read images, no IDE form, no TUI." On Chinese Windows, reading UTF-8 files with PowerShell under system code page 936 produces garbled text, while every file dsh writes is UTF-8. The CLI help says dsh --profile tui, but the distribution has no tui profile template at all.
ZCode's experience is more complete. Its major upgrade in August 2026 brought four features: Goal, Subagents, Remote Control, and idle-time tasks. Goal mode is the important one. You set a clear objective, and ZCode automatically breaks down tasks, changes code, runs commands, executes tests, and judges from the results whether the objective is complete. If it falls short, it goes another round. Remote Control lets you check progress and enter commands from a phone through WeChat or Feishu. Code and commands still run in the original desktop environment. The project is not synced to the phone. That remote check is something dsh lacks right now.
Conclusion
Back to that developer. He closed dsh's terminal, opened ZCode, and dragged the project folder in. The PR due tomorrow was still there. He needed something that could do the work. ZCode offers stability proven by a million users, a stable cache hit rate above 98%, an out-of-the-box Goal mode, and remote control. But he needs to assess data security risk. Sensitive code, proprietary business logic, and enterprise projects should not be uploaded to the cloud. A practical approach: use ZCode for non-sensitive personal projects or learning tasks, and for enterprise projects look for alternatives that support private deployment.
If he is curious about Agent architecture and wants to explore how an Agent can reorganize the boundaries of its own capabilities while running, dsh is a good research platform. But remember three rules: lock the version and do not update casually, use it in an isolated environment, and never use it for a project you depend on and need to deliver stably.
Users will not pay for the agent layer itself. They will pay for model and token costs. Today, as model capabilities become more similar, the value of an agent layer is not in how fancy the interface looks. It is in who keeps the risk more controllable. By that standard, ZCode's advantage in stability and governance is clear, provided you accept the data collection. dsh's "everything is a plugin" is full of possibility, but at this stage it is more a research testbed that needs maintenance than a production tool.
He locked the screen. The pothos on the desk needed water.
About the Creator
Jin
Writer of reamstories
https://reamstories.com/jin
Enjoyed the story? Support the Creator.
Subscribe for free to receive all their stories in your feed. You could also become a paid subscriber, letting them know you appreciate their work.
Comments
There are no comments for this story
Be the first to respond and start the conversation.