Skip to main content

dsh-computer-use

26Stars3Forks2Issues1Watchers

Enables DeepSeek Harness Agent to read, write, and control other desktop applications on macOS through accessibility APIs without moving the system cursor or changing the foreground window.

Evidence5/5methodologySourceInstallMaintenanceDSH versionSecurity scan
Machine-auditedInstall commandRepo verifieddsh-plugin topicLicenseREADMEAI wiki
Language
TypeScript
License
MIT
Branch
main
accessibilityagent-skillsagent-toolsappkitcomputer-usedeepseekdeepseek-harnessdesktop-automation

Install

cmdweb profile
$ dsh plugin --profile web add @anionex/dsh-computer-use

Run the command above in your terminal to install this plugin via the dsh CLI. You can switch Profile in the top-right corner. New to dsh? Read the beginner tutorial

Install via your agent

Install the DeepSeek Harness plugin Anionex/dsh-computer-use for me: review the repository at https://github.com/Anionex/dsh-computer-use first, then run the install command and verify the plugin loads successfully.

Paste this instruction to the DSH Web GUI assistant — it will install and verify for you.

One-Line Pitch

Let DeepSeek Harness Agent operate other desktop apps on macOS like a local user who can see the screen: first read the Accessibility element tree, then click, type, scroll, or drag — all without stealing focus or moving your actual mouse cursor.

Core Capabilities

  • Enumerate current visible macOS apps showing process ID, Bundle ID, and frontmost status
  • Capture the target app's Accessibility element tree and current state, with optional screenshot
  • Initiate clicks, value setting, typing, key presses, scrolling, and dragging through Accessibility semantics (by role, value, executable actions)
  • For visual issues in screenshots, automatically hand off the artifacts to the vision-tools Skill for processing (OCR, positioning, cropping)
  • Grant "read-only" or "controllable" permissions per app dimension, with high-risk actions requiring a one-time confirmation token
  • Provide a /computer-use/settings page in the web client showing health status, permission state, and app authorizations

Technical Implementation

  • Language: TypeScript (host plugin) + Swift (native helper process) + a JSON configuration
  • Key Dependencies: @deepseek-ai/cordis, @deepseek-ai/dsh-tools, @deepseek-ai/schemastery, zod
  • Architecture Pattern: Cordis Service starts macOS Provider → During initialization, register computer-use Skill and a computer_use_activate bootstrap tool via installComputerUseConsumer; when Agent calls this tool to load the Skill in-session, exposure.ts exposes 11 computer_* tools to the model at the Agent granularity level
  • Entry Files: src/index.ts (exports ComputerUseBundle), native/macos/manifest.json (locks native Helper's SHA-256, architecture, and minimum macOS version)

Use Cases

Use when the Agent needs to operate a macOS native app that has no dedicated connector, CLI, or API — for example, filling out a form that can only be opened in a desktop app, extracting data from a GUI workflow, or completing a step in an app other than Safari that browser automation can't handle. Use browser automation for browser tasks, and API/CLI where those can solve the problem.

Prerequisites & Compatibility

DependencyMinimum VersionNotes
DeepSeek Harness0.1.0-rc.6All DSH peerDependencies require ^0.1.0-rc.6; @deepseek-ai/dsh-host-webserver is optional
Node.js^22.19.0 or >=24.0.0Only needed when building this repo from source; precompiled artifacts installed via dsh plugin manager don't enforce this
macOS14.0+Native Helper is an ad-hoc signed universal binary (arm64 + x86_64), SHA-256 locked in native/macos/manifest.json
macOS AccessibilityUser manual authorizationRequired for reading Accessibility tree and clicking; enable in System Settings → Privacy & Security → Accessibility
macOS Screen RecordingUser manual authorizationOnly needed when computer_observe screenshot is requested
Third-party vision capabilitiesdsh-vision-toolkit (optional)When screenshots need OCR, visual positioning, or pixel analysis, load the vision-tools Skill; this plugin passes the screenshot Artifact path to it

Installation

dsh plugin --profile web add github:Anionex/dsh-computer-use

This command only works for Web Profile; for Headless Profile, replace web with headless at the end and install separately. The official package on npm is @anionex/dsh-computer-use, installed via GitHub source using the command form in this marketplace.

Configuration Options

ConfigTypeDescriptionDefault
observationTtlMsInteger 0 or 1000~86400000Validity period for one observation result; 0 means never expires0
confirmationTtlMsInteger 1000~900000Validity period for one-time sensitive action confirmation token (ms)300000
actionTimeoutMsInteger 1000~120000Maximum wait time for a single native action (ms)15000
settleMsInteger 0~10000How long to wait for interface to stabilize after an action (ms)250
maxSettleMsInteger 100~60000Maximum wait time after an action completes (ms)5000
maxNodesInteger 10~5000Maximum number of Accessibility nodes returned per observation500
maxDepthInteger 1~64Maximum depth for traversing Accessibility tree in single observation14
maxTextBytesInteger 1024~1048576Maximum bytes for tree text64000
maxScreenshotBytesInteger 1024~268435456Maximum bytes for screenshot artifacts33554432 (32 MiB)
artifactRootStringScreenshot artifact directory; must be relative path under workspace, no .. allowed.dsh-computer-use/artifacts
helper.pathStringCustom external Helper executable path; empty uses default HelperNot set
helper.allowSourceBuildBooleanWhether to allow temporary source build when built-in Helper is missingfalse
interaction.focusPolicyStringWhether to allow bringing target app to foreground: preserve (default, don't steal focus) or activatepreserve
interaction.keyboardPolicyStringWhether to bring target app to foreground before keyboard input: preserve or activatepreserve (Bundle defaults to activate, overridden by cordis.patch.yml)
interaction.pointerInputPolicyStringWhether to allow mouse/scroll/drag targeting the target process: targeted (allow) or deny (forbid)targeted
interaction.cursorVisualizationStringWhether Agent's small cursor is visible: visible (show) or hidden (hide)visible
interaction.cursorMotionMsInteger 0~2000Animation duration for Agent's small cursor moving from point to point (ms)180
interaction.cursorAutoHideMsInteger 0~30000How long before Agent's small cursor auto-hides when idle; 0 means always show0
allowAllAppsBooleanWhether to grant read-only and control to all running apps at once; if enabled, ignores grants listfalse
grantsArrayGrant read-only or control by exact Bundle ID; control implies read; wildcards not supported[]

At Bundle startup, cordis.patch.yml sets focusPolicy to preserve and keyboardPolicy to activate, which differs from the bare Schema defaults above; override in Settings if changes are needed.

FAQ

Q: I installed it, but I can't see computer_click and other tools in the Agent. What should I do?

A: After installation, only computer_use_activate is available as a bootstrap tool. Have the Agent execute /computer-use in the current session to load the Skill, or directly invoke computer_use_activate. Once loaded, the 11 executable computer_* tools will appear in the tool list. Restarting dsh web host and creating a new Session is also a common cause.

Q: The content in screenshots is blurry, how do I let the Agent read the images?

A: This plugin doesn't perform OCR itself. When computer_observe returns a screenshot, it simultaneously passes the Artifact path to the current Agent; the Agent should load the vision-tools Skill, then pass this path to vision_glance, vision_ground, vision_detect, vision_crop, or vision_long_screenshot_ocr. Don't use tesseract, screencapture, or temporary Swift scripts as alternatives.

Q: Why did my "frontmost App" change after the Agent finished operating?

A: Under the default policy, semantic Accessibility actions and pointer input with target process don't steal focus. If you see the foreground switched away, it's likely focusPolicy: activate or keyboardPolicy: activate was enabled, or the target app caused side effects. Reverting the policy to preserve restores the default behavior.

Q: Some apps have Accessibility enabled but the Agent still fails. What's the issue?

A: This is by design — "fail closed." Custom canvas, games, apps with custom input handling, and future macOS versions may reject pointer or keyboard events delivered via SkyLight. Use semantic Accessibility (by role, value, advertised actions) where possible; coordinate clicking is a fallback, not the first choice.

Q: Can I grant "read-only" access to an app without granting "control"?

A: Yes. In Web Settings under "Application access," add an exact Bundle ID authorization, check read but leave control unchecked. control: true automatically includes read, but not vice versa.

Q: After removing the plugin, do screenshots and authorization records disappear together?

A: No. dsh plugin remove only unregisters the Skill, tools, process-level observations, and confirmation tokens. Screenshot files (under artifactRoot) and computer_use_state sidecar files are retained and require manual cleanup.

Difficulty Level

Advanced — requires granting Accessibility/Screen Recording permissions in macOS System Settings first, then configuring app authorization by Bundle ID in Web Settings. Users must also understand the "observe → lock target → input" protocol to create stable Agent workflows, so there's a learning curve for first-time users.

Known Issues & Limitations

  • macOS only; Windows UI Automation and Linux providers are not yet implemented
  • State is early at 0.1.0; model-facing (Skill copy, tool signatures) and provider behavior may change before stable release
  • Pointer delivery depends on dynamically resolved SkyLight SPI; if that SPI is unavailable on the current macOS, fallback to coordinate clicking fails closed rather than switching to global mouse
  • Click coordinates must fall within a visible window of the target app; the Helper automatically resolves the topmost matching window under the click point, but minimized, hidden, or windowless targets are rejected
  • Custom canvas, games, hardened input surfaces, and future macOS versions may reject target process-level pointer or keyboard events; semantic Accessibility is recommended whenever possible
  • focusPolicy: activate and keyboardPolicy: activate are breaking policies reserved for compatibility, to be used only when explicitly requested by the operator
  • The plugin only captures "on-demand" observations and doesn't maintain a real-time desktop stream; for continuous viewing, use screen recording or dedicated vision solutions
  • Continue using browser automation for browser tasks, as DOM/CDP state is narrower and more accurate
  • DSH's danger-full-access built-in authorization policy is approval/policy: never, which blocks unauthorized apps before the popup appears; in such cases the plugin reports COMPUTER_PERMISSION_REQUIRED, which is not treated as user rejection

Read the usage guide →

Install steps, key points, FAQ and compatibility for this plugin — auto-derived from indexed fields.

Listing badge

Listed on deepseek-plugin.org
[![Listed on deepseek-plugin.org](https://img.shields.io/badge/listed_on-deepseek--plugin.org-007EC6)](https://deepseek-plugin.org/plugins/Anionex/dsh-computer-use)

Paste this markdown into your GitHub README to link back to this listing. The badge only states the listing — not a security endorsement.

← Back to plugin directory