DeepSeek Harness vs Claude Code vs Codex

Three agent harnesses, three different bets. Claude Code is a finished first-party product wrapped around Claude models. Codex is an open CLI plus a cloud agent from OpenAI. DeepSeek Harness (DSH) is an open core that expects everything else to arrive as a plugin. This comparison is built from each product's own documentation — and, for DSH, from the plugins this directory actually catalogues.

Published 2026-09-18 · dshpacks Research

The short version

All three put a model in a loop with tools and a filesystem. The differences that matter are where the boundary of the product sits, and who is expected to cross it.

Where the product boundary sits

Claude Code and Codex are products with an edge. The vendor decides what is inside the box — the surfaces, the permission model, the instructions file, the distribution — and you configure it. Both publish an extension surface for the parts you are allowed to change: Claude Code publishes a plugin specification, and Codex documents custom instructions, skills and hooks.

DSH draws that boundary in a different place. The harness core is small and the rest is expected to be a plugin, which is why this directory exists at all: the interesting parts of a DSH setup — the interface, the memory backend, the notifications, the provider bridges — arrive as third-party packages rather than as configuration. That is a real advantage if you want to reshape the harness, and a real cost if what you wanted was a finished product.

How you extend it

Claude Code: plugins that bundle four kinds of extension

Anthropic's plugin guide describes a plugin as a self-contained directory with skills, agents, hooks, MCP servers, or a .claude-plugin/plugin.json manifest, and distinguishes it from standalone .claude/ configuration: standalone is for personal workflows, plugins are for sharing with a team or the community, versioned and reusable across projects, with namespaced commands. Distribution happens through plugin marketplaces. MCP — the open standard for connecting AI tools to external data sources — is part of the same extension story, so a Claude Code setup can also pull in external tools that were never written for it.

Codex: instructions, skills, hooks, and an admin switch

The Codex CLI repository keeps custom instructions in AGENTS.md and documents skills as a first-class concept. Configuration lives in config.toml, and enterprise control is explicit: an administrator can set allow_managed_hooks_only = true in requirements.toml to ignore user, project and session hook configuration while still allowing managed hooks. OpenAI's Codex documentation also describes a plugin surface — the Codex Security plugin, installed and enabled inside the Codex surface of the desktop app.

DSH: the plugin layer is the product

Measured across the 1,633 reviewed plugins in this directory, 1,331 publish the harness-managed form dsh plugin --profile <profile> add <package>, and 1,170 of those target the web profile. The rest are npm lines, source checkouts, Python packages or release downloads. Nothing here is a marketplace curated by the vendor: plugins are independent repositories, installed into a profile you choose, and the review burden lands on you. We wrote a separate guide on exactly that — are DSH plugins safe?

Installing each one

These are the install lines each vendor publishes for the tool itself, quoted as documented (not paraphrased):

Project instructions live in a file

Claude Code reads a CLAUDE.md markdown file from your project root at the start of every session, and Anthropic documents how those files, settings and MCP servers carry across surfaces. Codex uses AGENTS.md for custom instructions. It is the same idea in both cases: project context is a file in the repository, reviewable in a pull request, not a setting hidden in a UI.

DSH has no equivalent file in this directory's data — our pages catalog plugins, not harness configuration, so we will not invent a convention here. What the data does show is where that responsibility goes instead: 44 plugins are filed under Memory alone in this directory, alongside a separate Memory Enhancement category, because persistence is a plugin choice rather than harness configuration.

Permissions: what the agent may do without asking

Claude Code's documented model is permission-based. In Manual mode it starts read-only and asks before editing files or running Bash commands that modify your system, while running a built-in set of read-only commands such as ls, cat and git status without asking. In auto mode a separate classifier model reviews actions instead of you and blocks the ones it judges unsafe; your own ask and deny rules still apply, and an organisation can turn auto mode off entirely.

Codex documents sandboxing and approvals as its security model, with lifecycle hooks that an administrator can restrict. Its own docs index links a dedicated sandbox and approvals page; OpenAI has since reorganised that documentation under its ChatGPT Learn site, so read the current page rather than a stale link.

DSH's position is different by design: a plugin is code the harness loads and runs with your session's reach, and the harness does not curate it. That is the tradeoff of an everything-is-a-plugin core, and it is why the review question is the one we spend the most space on.

Openness and lock-in

Codex CLI is the most conventional answer: a public repository under Apache-2.0, distributed by installer, npm, Homebrew and release binaries. Claude Code is distributed as a product rather than a public source tree — what Anthropic publishes is the documentation, the plugin specification and the permission model, and the tool's own docs are the source of record. DSH is open at the core with a community plugin ecosystem on top, which means the harness is inspectable but the ecosystem's quality is uneven: across the 2,961 plugins listed here, the median repository has only a handful of stars and most are small, young projects. Openness moves the trust decision to you rather than removing it.

Which one fits which workflow

Those are design tradeoffs, not test results. We have not benchmarked the three against each other, we publish no speed, cost or quality scores, and this page makes no claim about which is better at any task. Anyone who gives you a ranking without showing their harness, model version and task set is guessing.

Where DSH stands today

The honest snapshot from this directory's data: 2,961 English-visible plugins, 1,633 reviewed, 27 categories, 1,331 of the reviewed entries installing through the harness's own dsh plugin form. That is a young ecosystem — wide rather than deep, with most projects maintained by one person. If you are choosing DSH, choose it for the shape of the thing: a harness you can rebuild. Then pick plugins the boring way, by reading the install line and the repository, which is exactly what our safety guide walks through.

How we sourced this

Every Claude Code and Codex statement above comes from that vendor's own documentation, fetched on 2026-09-18 and listed in full below; nothing about either product is written from memory, and where their docs were silent this page says so. Every DSH number is computed at build time from data/plugins.json and data/enrichment.json, so it tracks the directory instead of drifting from it. Product documentation changes: if you are reading this months later, check the sources before relying on a detail.

Sources

All fetched 2026-09-18. Listed as plain references — this page does not link out.

Where to go next

Related: dsh Packs · Submit a plugin for review

Where to go next

deepseek harness vs claude codedsh vs codexopen source agent harness

Browse the directory by category