Native per-workspace memory on the harness's own seams: facts and a bounded always-on profile on the storage-domain JSON unit, approval-gated writes with `(sessionId, seq)` citations, deterministic recall plus session-query FTS over past sessions — no external server, no custom SQLite.
Install
# from npm (prebuilt)
dsh plugin --profile web add dsh-native-memory
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:highland0971/dsh-native-memory
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
Native, per-workspace long-term memory for DeepSeek Harness (dsh): facts and profiles stored on the harness's own storage-domain, cross-session recall through session-query FTS, approval-gated writes, and cited provenance — no external server, no extra runtime dependency.
⚠️ Installing a plugin runs third-party code on your machine with your own permissions. Review the source (
src/) and the security model before installing.
Why this one
| dsh-hermes-memory | dsh-native-memory | |
|---|---|---|
| Storage | ~/.dsh/settings.yaml namespace |
dedicated storage-domain unit (~/.dsh/storages/dsh_memory.json) |
| Scope | user-global, all projects | per workspace (exact-cwd authorization) |
| Write safety | silent, model-only | human approval gate + session-log audit |
| Recall | everything always injected (hard caps) | bounded always-on profile plus on-demand recall + FTS over past sessions |
| Dependencies | vendored imports into the harness checkout | none beyond zod + the harness itself |
See docs/design.md for the full architecture and the competitive landscape analysis.
Install
dsh plugin --profile web add dsh-native-memory # npm after release
dsh plugin --profile web add /path/to/this/repo # from a checkout
Restart dsh web. The bundle enables session-query full-text search and adds
the memory tools to every session. Details and configuration:
docs/install.md.
Tools
| Tool | Kind | Gate |
|---|---|---|
memory_remember |
add/update a fact in this workspace (secrets rejected by default) | approval |
memory_edit |
replace a fact | approval |
memory_forget |
archive a fact (soft delete) | approval |
memory_recall |
deterministic three-tier keyword scan (tags > text > fuzzy; freshness/access tie-breaks) | none |
memory_search |
FTS over this workspace's past sessions (caller excluded) | none |
memory_expand |
expand a fact's citation to the original log excerpt | none |
memory_consolidate |
near-duplicate merge suggestions + cap budget | none |
memory_import |
import candidate facts from a past session's log | approval (per fact) |
memory_profile |
read the always-injected workspace profile | none |
memory_export |
write a git-friendly Markdown mirror (.dsh-memory/memory.md, masked, idempotent) |
none |
Every fact records its origin (sessionId, seq) — memory stays
reconstructable from the lossless session log.
Writes reject secret-shaped text (tokens / keys / passwords) by default;
secretPolicy: "mask" | "off" in the bundle patch relaxes that. The
credential-assignment detector can flag benign token: … values of ≥16
characters. Prompt injection and tool output always mask secrets.
A read-only browser page (settings → 记忆) lists every workspace's facts with
secrets masked; deletions are copied as a memory_forget instruction and land
in the chat through the approval gate.
Opt-in session-end proposals (proposeOnSessionEnd: true): one cheap LLM call
distills a finished session into candidate facts shown in the next sessions;
they become facts only through the approval-gated memory_remember.
A compaction drift guard (compactionGuard: true, on by default) surfaces
literal anchors a compaction summary dropped, as data to verify in the next
sessions — deterministic, no LLM.
Development
pnpm install
pnpm build && pnpm typecheck && pnpm test
New contributors start at docs/handoff.md and docs/contributing.md. Chinese docs: README.zh.md.
License
Links
More in this category
vectorize-io/hindsight#coding-agents★ 41184
Hindsight, agent memory that learns: long-term project memory with auto recall and retain, knowledge pages, deep reflection, and per-repo memory banks.
volcengine/OpenViking#examples/dsh-memory-plugin★ 38914
OpenViking memory and context bundle for DeepSeek Harness: pre-step auto-recall and profile injection, session capture, `viking://` URI guarding, and recall/write memory tools backed by an OpenViking server.
agentscope-ai/ReMe#dsh★ 3530
Connects DeepSeek Harness to ReMe's local-first, self-evolving personal knowledge base: automatically captures completed main-agent conversations as user-owned Markdown memory, searches conversations and source material through reme_search with BM25, optional embeddings, and wikilink expansion, and schedules daily memory consolidation.
zilliztech/memsearch#MemSearch★ 2679
Shared Markdown memory for DSH and other coding agents, with automatic capture, pre-step context injection, searchable recall, and memory-to-skill self-evolution through a review panel.
vshulcz/deja-vu#extensions/dsh★ 1081
Reads the session files thirty-three other coding agents on this machine already wrote — Claude Code, Codex, Cursor, VS Code Copilot Chat, opencode, OpenClaw, Hermes, Kimi, Cline, Zed and more — including sessions from before it was installed: six tools (deja_recall, deja_session, deja_blame, deja_fix, deja_how, deja_remember), a /deja command, and optional automatic recall added to the runtime context. Local BM25 index, no LLM, no embeddings, no network (dsh plugin --profile web add dsh-deja).
adoresever/graph-memory★ 631
Traceable, searchable cross-session memory for DeepSeek Harness — conversation knowledge as typed graph nodes (TASK/SKILL/EVENT) and typed edges.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.