Penglai 0.6.1

Make room for the work that matters.

Penglai installs official DeepSeek Harness on a personal computer. You bring a model key, choose a Workspace, and finish setup only after the first real reply. Office and Memory start on. The rest waits until you ask.

Apple Silicon Windows x64 UOS 20 LoongArch MIT

Penglai first-run welcome: language, appearance, and a seven-step guide
Installed 0.5.5 first-run welcome, kept as a UI reference. This is not a 0.6.1 screenshot.

Edit the file in front of you

Office can inspect, create, preview, export, and save DOCX, XLSX, PPTX, and PDF. A write waits for a confirmation bound to that action.

Remember this project only

Project memory stays in the current Workspace. Personal memory is a separate choice you confirm. Storage stays on this computer.

Message when you need it

Weixin, Feishu, and six other channels can join the same official Session. Optional macOS iMessage is private text and default off. WhatsApp is not a product surface.

Speak only if you install it

Speech recognition and voice generation stay off until you download their models. Ordinary chat still works without them.

The core does not change

DeepSeek Harness still owns the conversation.

Official DeepSeek Harness is the only agent core. It owns models, tools, approvals, Workspace, Session, Turn, and the conversation interface. Penglai owns the installer, first-run, process supervision, updates, uninstall, local paths, and a reviewed plugin set. There is no second Penglai agent and no replacement chat page. Fresh setup lists official deepseek-flash (DeepSeek-V41-Flash) with text and image input. A model you already chose stays in official settings.

Penglai 0.6.1 · DSH 0.1.5-rc.1 · tag dsh-v0.1.5-rc.1 · commit 183f08e9c6dde7e36cd2318eaee70b0da08fb35e · 279 packages

Penglai Plugin Center inside official DSH settings, showing Office, Memory, messaging, and voice
Installed 0.5.5 Plugin Center, running in official DSH settings. UI state is never proof that a plugin is installed or healthy. Not a 0.6.1 screenshot.

Penglai Office · on by default

Files enter a Workspace. Writes wait.

Office inspects, creates, previews, and exports DOCX, XLSX, PPTX, and PDF. Writes and exports wait for a confirmation bound to that action. You can also attach files in chat; the assistant reads them with tools. Whether a picture is understood as an image depends on the model you selected. The official generic sidebar is a plain-text preview, not a formatted Office viewer.

  • DOCX, XLSX, PPTX, and PDF share one Office path.
  • Attach a file in chat when you want the assistant to read it with tools.
  • Save, export, and return wait for that action's confirmation.
Penglai Office settings: create, inspect, and planned edits for a DOCX file

Penglai Memory · on by default

This Workspace can remember. The next one cannot.

Project memory stays in the current Workspace. Another Workspace does not see it. Personal memory is a separate choice you confirm. Memory uses your selected model provider to decide which project facts to keep. Storage stays on this computer.

  • You can turn memory off, or review candidates first.
  • Authorised folders are indexed without changing the originals.
  • Memory starts on, with the Mnemon 0.2.8 engine packed.
Penglai Memory settings: Workspace scope, graph, correction, and migration

Waiting until you ask

Optional tools stay out of the way.

Opt in

Messaging

Weixin, Feishu, DingTalk, WeCom, QQ, Slack, Telegram, and Discord enter one @penglai/im control plane, using each platform's QR, device-registration, or official-token flow. WeChat and Feishu can send files into the bound conversation. If that conversation is missing, the channel keeps a durable error with /projects and /new. Optional macOS iMessage is private text, default off, and needs Full Disk Access plus Messages automation. It is unsupported on Windows and UOS. Native live use is not claimed (LIVE_NOT_RUN). WhatsApp is not bundled.

Opt in

Local voice

SenseVoice handles speech recognition. MOSS-TTS handles voice generation on Mac and Windows. Plugin code ships in the app. Large SenseVoice weights explain themselves before downloading. MOSS-TTS is not available and not enableable on LoongArch. Conversation Read speaks the original reply rather than translating it.

Opt in

Companion

It contacts you only after you turn it on, and stays within quiet hours, a daily cap, and one chosen messaging route. Fresh installations keep it off.

Independent updates

Plugin Center

The catalog comes from immutable GitHub Releases. The current live catalog is plugin-catalog-v1.000006: no extra downloads, with the historic office-reader revocation kept. A reviewed plugin compatible with DSH 0.1.5-rc.1 can join later without a new desktop release. Signatures, hashes, permissions, and rollback protect distribution. Plugins still share the local DSH process.

First launch

Seven steps, complete only after a real reply.

Choose language and appearance, read the local-data boundary, pick a provider and model from the official catalog, test your own API key, choose a real Workspace, then send the first message. Fresh setup includes official deepseek-flash. Folder browse stays in the Penglai window; you can cancel or retry. You can go back and resume after restart. A failed API key is never recorded as success. The app data directory and the install directory cannot be Workspaces.

  • Use the matching installer. Do not mix Apple Silicon, Windows, or UOS packages.
  • Upgrade with the same-platform installer as a manual overlay. Updates are never silent.
  • Default uninstall keeps user data. External Workspaces and the Penglai/0.5 generation remain.
Penglai first-run privacy step, explaining local YAML credentials and what is not logged

Boundaries, in plain language

No Penglai account. Model calls still leave the computer.

Where data goes There is no Penglai account, Penglai-operated telemetry backend, or cloud memory sync. Official DSH bundles a dormant DeepSeek OTLP endpoint; Penglai hard-disables it. Model calls still send the context needed for that task to the provider you selected.

What needs a confirmation Office save, export, and return, personal Memory, plugin install, and outbound messaging use a confirmation bound to that action. Diagnostics must not contain credentials, chat bodies, QR codes, or private absolute paths.

Signatures are not an OS endorsement macOS packages are ad-hoc signed and not notarized. Windows has no Authenticode. Gatekeeper or SmartScreen may warn. Penglai Ed25519 signatures protect updater and plugin bytes; they are not Apple or Microsoft publisher identity.

UOS is a packaged target, not a finished native claim UnionTech UOS 20 LoongArch is packaged as Penglai_0.6.1_uos_loong64.deb. Native install, startup, and function on that host remain Owner post-publication testing (OWNER_POST_RELEASE). Mac and Windows embed Node 22.23.2 and Electron 43.6.0 (Chromium 150). UOS uses Loongson Node 22.16.0 and Electron 31.7.7 (Chromium 126). That runtime is unmaintained. Memory stays on, with the packed Mnemon engine. MOSS-TTS cannot be enabled on LoongArch. Native Windows checks used the hosted runner's existing security configuration; default Defender-on Windows was not verified. This page does not claim a three-target native GUI PASS.

Penglai 0.6.1

Choose the installer that matches the machine.

If GitHub is slow from mainland China, download the same installers from the Beijing mirror. Verify each file against the GitHub SHA256SUMS; in-app updates still use GitHub.

The immutable GitHub Release is the authoritative public download source: v0.6.1. All three installers come from source 7ad7c29ecda5d9e867fdde0fe3fefd5c42d3ab1b. Check the file against SHA256SUMS on that page. The release is three installers and ten assets. The signed updater covers Apple Silicon and Windows x64. Intel Mac is not a 0.6.1 installer. Linux amd64 and Windows ARM are not targets. Updates are never silent. Published 0.5.10, 0.5.11, 0.5.12, and 0.6.0 remain immutable.

Why Penglai

I spent more than ten years around networking, security, and operations, but I was not a software developer. Penglai began with one stubborn idea: ordinary people should be able to reach a real assistant from the computer they already have.

Computers travelled from command lines to windows and then into everyone's pocket. Agents should make the same trip. If I can send a message, I should be able to reach my own assistant. If it acts for me, I should be able to see what it was allowed to do, what actually happened, and what it cost.

Penglai has been rebuilt more than once. The important decision in 0.5 was to stop building another agent and stand on DeepSeek Harness instead. 0.6.1 keeps that decision and puts the same product on three computers, including UnionTech UOS 20 LoongArch. Older generations remain in Git history; their runtimes are not mixed into this core.

Kevin Chen / 陈克文

FAQ

Short answers before you install.

Is Penglai another agent?

No. Official DeepSeek Harness is the only core. Penglai owns install, lifecycle, and first-party plugins. There is no second chat page.

Which version should I download?

This page describes Penglai 0.6.1. Download the matching installer from the immutable v0.6.1 GitHub Release. Intel Mac is not a 0.6.1 installer. Published 0.5.10, 0.5.11, 0.5.12, and 0.6.0 remain historical and immutable.

Why does Gatekeeper warn?

macOS packages are ad-hoc signed and not notarized; Windows has no Authenticode. That is a stated limitation, not an OS endorsement. Do not turn off system security to install.

Are Office and Memory on by default?

Yes. You can attach files in chat for the assistant to read with tools. Office inspects, creates, previews, and exports documents, with confirmation on writes. Messaging, speech, and Companion stay off until you enable them.

Does Penglai support iMessage?

Only as optional macOS private text, default off. Grant Full Disk Access and Messages automation first, then enable and bind the exact peer. It is unsupported on Windows and UOS. Native live use is not claimed.

What if the API key fails?

The wizard supports Back, retry, and resume after restart. A failed credential test is never recorded as success.

Does uninstall delete my files?

Default uninstall removes the application and cache while preserving user data. Complete delete uses a separate category plan and must not recursively wipe a Workspace or home directory.

Product contract Architecture Plugin Center 0.6.1 acceptance delta