Post-compaction premise-drift guard: injects a one-shot notice when a compaction summary drops a critical literal anchor.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:ICCuse/dsh-premise-guard
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
中文 | English
Post-compaction premise-drift guard. After a compaction/summary event, it extracts distinctive literal anchors (file paths, quoted literals, key=value pairs, error codes) from the shadowed span's text, checks whether the committed summary still contains them, and — when a critical anchor vanished — injects a one-shot notice into the next step telling the model what it may have lost and how to recover it from the append-only log.
Why
Recall-oriented designs (recallable-compaction, session-query tools) make shadowed content reachable when suspected. Nothing says "you just dropped a key fact". This guard turns the compaction summary into a checked handoff: the model learns the moment a path, value, or error string it was relying on is no longer in the summarized context.
How it works
| Hook | Role |
|---|---|
session/event (compaction/summary) |
Re-derives the shadowed span's text from shadowedSeqs (the log keeps every byte), extracts anchors, and compares against event.data.summary. |
agent/pre-step |
Injects one notice (plugin source) naming up to maxAnchors vanished anchors and the shadowed seq range, once per alarm; a new user prompt skips delivery. |
Anchor extraction is deterministic and pure — no LLM calls, no new storage.
Config
| Field | Default | Meaning |
|---|---|---|
maxAnchors |
5 |
Vanished anchors named in one notice. |
minAnchorLength |
6 |
Anchors shorter than this are never critical. |
maxNoticeChars |
400 |
Notice text cap. |
All three must be integers >= 1; misconfiguration throws at plugin load.
Install
Not on npm yet - install from this repository:
npm install github:ICCuse/dsh-premise-guard
# or: pnpm add github:ICCuse/dsh-premise-guard
Then mount the bundle (declared in package.json 'dsh.bundle'):
- id: dsh-premise-guard
name: 'dsh-premise-guard'
Or, once published, 'dsh plugin --profile web add dsh-premise-guard'.
Links
More in this category
volcengine/OpenViking#examples/dsh-memory-plugin★ 38815
OpenViking memory and context bundle for DeepSeek Harness: pre-step auto-recall and profile injection, session capture, `viking://` URI guarding, and recall/write memory tools backed by an OpenViking server.
vectorize-io/hindsight#coding-agents★ 37670
Hindsight, agent memory that learns: long-term project memory with auto recall and retain, knowledge pages, deep reflection, and per-repo memory banks.
agentscope-ai/ReMe#dsh★ 3526
Connects DeepSeek Harness to ReMe's local-first, self-evolving personal knowledge base: automatically captures completed main-agent conversations as user-owned Markdown memory, searches conversations and source material through reme_search with BM25, optional embeddings, and wikilink expansion, and schedules daily memory consolidation.
zilliztech/memsearch#MemSearch★ 2670
Shared Markdown memory for DSH and other coding agents, with automatic capture, pre-step context injection, searchable recall, and memory-to-skill self-evolution through a review panel.
vshulcz/deja-vu#extensions/dsh★ 1074
Reads the session files thirty-three other coding agents on this machine already wrote — Claude Code, Codex, Cursor, VS Code Copilot Chat, opencode, OpenClaw, Hermes, Kimi, Cline, Zed and more — including sessions from before it was installed: six tools (deja_recall, deja_session, deja_blame, deja_fix, deja_how, deja_remember), a /deja command, and optional automatic recall added to the runtime context. Local BM25 index, no LLM, no embeddings, no network (dsh plugin --profile web add dsh-deja).
adoresever/graph-memory★ 630
Traceable, searchable cross-session memory for DeepSeek Harness — conversation knowledge as typed graph nodes (TASK/SKILL/EVENT) and typed edges.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.