Everything is a plugin, including the components that enforce the limits
The architecture is explicit that models, tools, skills, sessions, sandboxes, storage, loops, scheduling and the UI all sit behind plugin boundaries. The approval path is one of those layers. Read at a pinned commit, it composes as a waterfall, which means a plugin can be placed ahead of the component that would have refused. This is the question this publication wrote into the source contract at intake, answered by the code rather than by the landing page, and answered in the direction that costs an operator something.
What this changes for operators
- If you write a dsh plugin, understand that your plugin is not governed by the approval gate in the way a tool is governed by a permission system. It sits in the same layer the gate does.
- Ask of any plugin-everything architecture: which component is not replaceable? If the answer is none, then the enforcement story is a convention rather than a boundary.
- This is developer preview and the whole project ships to a prerelease. Nothing here is an upgrade instruction; it is a design question to settle before this reaches a stable channel.
Signal metadata
Source findings
- 2026-08-17-deepseek-harness-everything-is-a-plugin-including-the-components-that-enforce-the-limits 2026-08-17-deepseek-harness-everything-is-a-plugin-including-the-components-that-enforce-the-limits
Run: 2026-08-17-weekly-digest-2026-08-10_2026-08-17-frontier-v0
Schema: bitter.frontier_signals.v0 / ID: 2026-08-17-deepseek-the-gate-is-a-plugin
Research evidence and publication history are open in the repository.