Edit the file in front of you
Office can inspect, create, preview, export, and save DOCX, XLSX, PPTX, and PDF. A write waits for a confirmation bound to that action.
Penglai 0.6.1
Penglai installs official DeepSeek Harness on a personal computer. You bring a model key, choose a Workspace, and finish setup only after the first real reply. Office and Memory start on. The rest waits until you ask.
Office can inspect, create, preview, export, and save DOCX, XLSX, PPTX, and PDF. A write waits for a confirmation bound to that action.
Project memory stays in the current Workspace. Personal memory is a separate choice you confirm. Storage stays on this computer.
Weixin, Feishu, and six other channels can join the same official Session. Optional macOS iMessage is private text and default off. WhatsApp is not a product surface.
Speech recognition and voice generation stay off until you download their models. Ordinary chat still works without them.
The core does not change
Official DeepSeek Harness is the only agent core. It owns models, tools, approvals, Workspace, Session, Turn, and the conversation interface. Penglai owns the installer, first-run, process supervision, updates, uninstall, local paths, and a reviewed plugin set. There is no second Penglai agent and no replacement chat page. Fresh setup lists official deepseek-flash (DeepSeek-V41-Flash) with text and image input. A model you already chose stays in official settings.
Penglai 0.6.1 · DSH 0.1.5-rc.1 · tag dsh-v0.1.5-rc.1 · commit 183f08e9c6dde7e36cd2318eaee70b0da08fb35e · 279 packages
Penglai Office · on by default
Office inspects, creates, previews, and exports DOCX, XLSX, PPTX, and PDF. Writes and exports wait for a confirmation bound to that action. You can also attach files in chat; the assistant reads them with tools. Whether a picture is understood as an image depends on the model you selected. The official generic sidebar is a plain-text preview, not a formatted Office viewer.
Penglai Memory · on by default
Project memory stays in the current Workspace. Another Workspace does not see it. Personal memory is a separate choice you confirm. Memory uses your selected model provider to decide which project facts to keep. Storage stays on this computer.
Waiting until you ask
Weixin, Feishu, DingTalk, WeCom, QQ, Slack, Telegram, and Discord enter one @penglai/im control plane, using each platform's QR, device-registration, or official-token flow. WeChat and Feishu can send files into the bound conversation. If that conversation is missing, the channel keeps a durable error with /projects and /new. Optional macOS iMessage is private text, default off, and needs Full Disk Access plus Messages automation. It is unsupported on Windows and UOS. Native live use is not claimed (LIVE_NOT_RUN). WhatsApp is not bundled.
SenseVoice handles speech recognition. MOSS-TTS handles voice generation on Mac and Windows. Plugin code ships in the app. Large SenseVoice weights explain themselves before downloading. MOSS-TTS is not available and not enableable on LoongArch. Conversation Read speaks the original reply rather than translating it.
It contacts you only after you turn it on, and stays within quiet hours, a daily cap, and one chosen messaging route. Fresh installations keep it off.
The catalog comes from immutable GitHub Releases. The current live catalog is plugin-catalog-v1.000006: no extra downloads, with the historic office-reader revocation kept. A reviewed plugin compatible with DSH 0.1.5-rc.1 can join later without a new desktop release. Signatures, hashes, permissions, and rollback protect distribution. Plugins still share the local DSH process.
First launch
Choose language and appearance, read the local-data boundary, pick a provider and model from the official catalog, test your own API key, choose a real Workspace, then send the first message. Fresh setup includes official deepseek-flash. Folder browse stays in the Penglai window; you can cancel or retry. You can go back and resume after restart. A failed API key is never recorded as success. The app data directory and the install directory cannot be Workspaces.
Penglai/0.5 generation remain.
Boundaries, in plain language
Where data goes There is no Penglai account, Penglai-operated telemetry backend, or cloud memory sync. Official DSH bundles a dormant DeepSeek OTLP endpoint; Penglai hard-disables it. Model calls still send the context needed for that task to the provider you selected.
What needs a confirmation Office save, export, and return, personal Memory, plugin install, and outbound messaging use a confirmation bound to that action. Diagnostics must not contain credentials, chat bodies, QR codes, or private absolute paths.
Signatures are not an OS endorsement macOS packages are ad-hoc signed and not notarized. Windows has no Authenticode. Gatekeeper or SmartScreen may warn. Penglai Ed25519 signatures protect updater and plugin bytes; they are not Apple or Microsoft publisher identity.
UOS is a packaged target, not a finished native claim UnionTech UOS 20 LoongArch is packaged as Penglai_0.6.1_uos_loong64.deb. Native install, startup, and function on that host remain Owner post-publication testing (OWNER_POST_RELEASE). Mac and Windows embed Node 22.23.2 and Electron 43.6.0 (Chromium 150). UOS uses Loongson Node 22.16.0 and Electron 31.7.7 (Chromium 126). That runtime is unmaintained. Memory stays on, with the packed Mnemon engine. MOSS-TTS cannot be enabled on LoongArch. Native Windows checks used the hosted runner's existing security configuration; default Defender-on Windows was not verified. This page does not claim a three-target native GUI PASS.
Penglai 0.6.1
91393e2e760871694e836c2582b903f6fee509e9fa11391724567e472f9946e9
Windows · x64
GitHub · 354.1 MiB · 64-bit installer
Penglai_0.6.1_windows_x64_setup.exe
d4fb670edea847024abcb2a1ac760cc2f7c5814d0c60f77f80ec647c59f51791
UOS 20 · LoongArch
GitHub · 279.5 MiB · UOS 20 Professional 1070, old-world. Native function is Owner post-publication.
Penglai_0.6.1_uos_loong64.deb
cd38c06e37151f226e7f9eb2519dba0800fc9ed7f4449d2b7edd5a282efb5934
If GitHub is slow from mainland China, download the same installers from the Beijing mirror. Verify each file against the GitHub SHA256SUMS; in-app updates still use GitHub.
91393e2e760871694e836c2582b903f6fee509e9fa11391724567e472f9946e9
China mirror · Windows x64
Beijing HTTPS · 354.1 MiB
Penglai_0.6.1_windows_x64_setup.exe
d4fb670edea847024abcb2a1ac760cc2f7c5814d0c60f77f80ec647c59f51791
China mirror · UOS LoongArch
Beijing HTTPS · 279.5 MiB
Penglai_0.6.1_uos_loong64.deb
cd38c06e37151f226e7f9eb2519dba0800fc9ed7f4449d2b7edd5a282efb5934
The immutable GitHub Release is the authoritative public download source: v0.6.1. All three installers come from source 7ad7c29ecda5d9e867fdde0fe3fefd5c42d3ab1b. Check the file against SHA256SUMS on that page. The release is three installers and ten assets. The signed updater covers Apple Silicon and Windows x64. Intel Mac is not a 0.6.1 installer. Linux amd64 and Windows ARM are not targets. Updates are never silent. Published 0.5.10, 0.5.11, 0.5.12, and 0.6.0 remain immutable.
Why Penglai
I spent more than ten years around networking, security, and operations, but I was not a software developer. Penglai began with one stubborn idea: ordinary people should be able to reach a real assistant from the computer they already have.
Computers travelled from command lines to windows and then into everyone's pocket. Agents should make the same trip. If I can send a message, I should be able to reach my own assistant. If it acts for me, I should be able to see what it was allowed to do, what actually happened, and what it cost.
Penglai has been rebuilt more than once. The important decision in 0.5 was to stop building another agent and stand on DeepSeek Harness instead. 0.6.1 keeps that decision and puts the same product on three computers, including UnionTech UOS 20 LoongArch. Older generations remain in Git history; their runtimes are not mixed into this core.
Kevin Chen / 陈克文
FAQ
No. Official DeepSeek Harness is the only core. Penglai owns install, lifecycle, and first-party plugins. There is no second chat page.
This page describes Penglai 0.6.1. Download the matching installer from the immutable v0.6.1 GitHub Release. Intel Mac is not a 0.6.1 installer. Published 0.5.10, 0.5.11, 0.5.12, and 0.6.0 remain historical and immutable.
macOS packages are ad-hoc signed and not notarized; Windows has no Authenticode. That is a stated limitation, not an OS endorsement. Do not turn off system security to install.
Yes. You can attach files in chat for the assistant to read with tools. Office inspects, creates, previews, and exports documents, with confirmation on writes. Messaging, speech, and Companion stay off until you enable them.
Only as optional macOS private text, default off. Grant Full Disk Access and Messages automation first, then enable and bind the exact peer. It is unsupported on Windows and UOS. Native live use is not claimed.
The wizard supports Back, retry, and resume after restart. A failed credential test is never recorded as success.
Default uninstall removes the application and cache while preserving user data. Complete delete uses a separate category plan and must not recursively wipe a Workspace or home directory.
Product contract Architecture Plugin Center 0.6.1 acceptance delta