跳到主要内容
← Harness 图谱

Deep Agents

LangChain
Python 开源 MIT 通用harness 长任务 子代理 verified lifecycle: active 核验 2026-09-30

「batteries-included agent harness」 —— 官方自述:开箱即跑、面向长任务多步流程、

适合与不适合

适合:要开箱即用、默认调优好、面向长任务多步流程的通用 Agent;不想自己拼 filesystem/记忆/子代理;已在 LangChain 生态里。

固定坐标系

8 个维度,与同赛道其他对象逐项可比。

模型与开放条件
官方自述 model-agnostic,README 列为四条原则之一: 「Model-agnostic — works with any LLM that supports tool calling: frontier, open-weight, or local」。 FAQ 进一步说明:任何支持 tool calling 的模型都行,包括 frontier API(OpenAI/Anthropic/Google)、 provider 托管的开源权重(Baseten/Fireworks),以及通过 Ollama / vLLM / llama.cpp 自托管的模型。 接入方式是任一 LangChain chat model。换 provider 不需要改 agent 代码。
运行位置
你自己运营进程 —— 它是库不是服务。README 明确 built on LangGraph (streaming, persistence, checkpointing),配 LangSmith 做 tracing/evaluation/deployment。 agent loop 的责任分布:模型决策与工具调用在 LangGraph runtime 上, Deep Agents 预置了规划、上下文管理、子代理委派。
本地文件
Filesystem 能力是核心卖点:read / write / edit / search, 且后端可插拔(pluggable local, sandboxed, or remote backends)。 重要边界:官方安全声明原文说「Enforce boundaries at the tool/sandbox level, not by expecting the model to self-police」—— 即官方明确不提供一层权限护栏, 边界要靠你自己在 tool/sandbox 层实现。多 agent 并发时的文件冲突处理本次未核验。
关机后的任务
自托管 = 关了就停,没有托管执行选项(README 无相关承诺)。 但断点续跑有官方支撑:built on LangGraph 的 persistence + checkpointing, 加上 persistent memory(pluggable state and store backends for cross-session recall)。 官方另有 LangSmith 提供 deployment。
工具与扩展
工具链是「batteries-included」定位:Sub-agents(隔离子上下文的委派)、Filesystem、Shell access (run commands in your sandbox of choice)、Skills(按需加载的可复用行为)、 Tools(自带函数或任意 MCP server)。 MCP 支持明确:官方列「bring your own functions or any MCP server」。 human-in-the-loop:可 approve / edit / reject 工具调用,发生在执行前。
上下文与记忆
本赛道「状态 ≠ 上下文」分野的教科书案例: Context management = summarize long threads and offload tool outputs to disk(卸载,不是丢); Persistent memory = pluggable state and store backends,支持跨会话召回。 官方描述 defaults are tuned for long-horizon, multi-step work。 两种做法并存:压缩历史 + 把大工具输出落盘 + 跨会话记忆。
权限与限制
官方明确不设防模型越界,Security 章节原文: 「Deep Agents follows a "trust the LLM" model. The agent can do anything its tools allow. Enforce boundaries at the tool/sandbox level, not by expecting the model to self-police.」 翻译:采用「信任 LLM」模型,Agent 能做任何它的工具允许的事; 边界要在工具/沙箱层强制,不要指望模型自我约束。 唯一的内建人工干预点是 human-in-the-loop 的工具调用审批(approve/edit/reject)。 这意味着:装了 Deep Agents 之后,权限模型是你的责任。
适合什么任务
适合:要一个开箱即用、默认调优好、面向长任务多步流程的通用 Agent; 不想自己拼 filesystem / 记忆 / 子代理;已经在 LangChain 生态里。 不适合:需要细粒度权限护栏(官方明说不提供,必须自建沙箱); 要严格控制 agent loop 形状(该用 LangGraph 自定义图); 想要轻量 harness(该用 LangChain create_agent)。

头号误解

  • 把 Deep Agents / LangChain / LangGraph 当成同一个东西 —— 官方自己明确是三层,职责不同(见 layer_position)
  • 以为 "trust the LLM" 是产品特性而不是风险声明 —— 官方原文是让你在工具/沙箱层自行设边界
  • 以为开源就零成本 —— 模型推理 + LangSmith(官方推荐的 tracing/eval)都要付费
  • 以为最新版是 0.7.0 —— 竞品站的快照记的是 0.7.0,实际已 0.7.20(核验 2026-09-30)

价格

月度入口库本身免费(MIT)
额度说明框架免费 ≠ 运行免费。 README 原文推荐搭配 LangSmith 做 tracing / evaluation / monitoring, LangSmith 是商业产品。另:模型推理费用自理,官方举例用 model="openai:gpt-6-astra"。 README 的 Quickstart 示例里没提 Deep Agents 自身有托管服务。

不同币种不做折算。优惠、地区、税费与登录后报价可能变化,购买前请到官方页面确认。

未知项清单

  • LangSmith 定价(README 推荐搭配,但商业条款未核验)

证据来源

判断可回到以下一手源复核。本站核验日 2026-09-30,内容更新日 2026-09-30。

类型名称链接
repoLangChain · Deep Agents 仓库https://github.com/langchain-ai/deepagents
docsDeep Agents 官方文档(overview)https://docs.langchain.com/oss/python/deepagents/overview
docsDeep Agents · Going to productionhttps://docs.langchain.com/oss/python/deepagents/going-to-production
docsDeep Agents · Security policy(trust the LLM 声明原文)https://github.com/langchain-ai/deepagents?tab=security-ov-file
docsLangChain 生态关系说明(三层如何配合)https://docs.langchain.com/oss/python/concepts/products
changelogDeep Agents Releases(0.7.20 @ 2026-09-29)https://github.com/langchain-ai/deepagents/releases

实测记录

本站尚未完成实测。测试协议见 tasks/_protocol.md。

本页由 ai-coding-agent-atlas 数据层生成(CC BY 4.0)。 方法论与坐标系定义见仓库内 METHODOLOGY.md。