DeepSeek Harness 插件

PerryLink/dsh-memento

Star 数 ★ 122 下载量(近 30 天) 4,569 分类 记忆 收录于 2026-08-14 npm dsh-memento

有界、分层、带审批门、可审计的跨会话记忆:`ctx.memory` 服务 + 零依赖 SQLite 存储 + `memory` 工具与冻结快照注入,并预演 dsh-memory-protocol v1——适配器注册表与可分发的一致性套件。

安装

# npm 包(预构建)

dsh plugin --profile web add dsh-memento

# GitHub 源码(首次需按提示配置 allowBuilds 构建授权后重试)

dsh plugin --profile web add github:PerryLink/dsh-memento

装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络,工具审批管不到它。GitHub 来源的插件还会在安装时执行构建脚本——pnpm 默认拦截,所以安装可能停在 ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED 或 ERR_PNPM_IGNORED_BUILDS;dsh 会打印出需要添加的确切键名,把它加进该 profile 的 pnpm-workspace.yaml 的 allowBuilds 下,重跑一次即可装上。放行构建本身就是一次信任判断:请只安装可信来源,并尽量锁定 commit(github:owner/repo#sha)。

README

dsh-memento

  • 1024 商店渠道:先 npm i -g dsh1024,再 dsh1024 plugin --profile web add dsh-memento(计入 deepseek1024.com 安装排行)。

给 DeepSeek Harness 补上有界、分层、带审批门、可审计的跨会话记忆。

一个类型安全的 ctx.memory 接缝、模型绕不过去的写入审批门,以及可重建的审计链——来自审批对加插件自有审计表,并把会话日志侧的缺口说出来。

dsh-doctor DSH Market

English · 简体中文 · Español · Português · हिन्दी


⭐ 如果它帮到了你

这个插件是 DSH 插件家族的一员(40+ 个,全部 Apache-2.0)。如果你在用,给个 star —— 它不会解锁任何功能,但会让下一个人在搜索里更容易找到它。

English: part of a 40+ plugin family for DeepSeek Harness. If it is useful, a star helps the next person find it — nothing is gated behind it.

Compatibility

Surface Status
Harness DeepSeek Harness dsh-v0.1.7-rc.2(2026-09-22 适配):0.1.7 线把整条设置注册面(installSettingsSection / SettingsProvider.installSection / SettingsNamespace / SettingsScope)换成 live config 表单——表单的 namespace 就是 profile entry id(memento),可编辑字段就是标了 .volatile() 的那些,被接受的编辑提交进运行中的插件而不是重挂它。浏览器半经 ctx.configForms.get(entryId) 读同一份表单(ctx.settingsScope 服务已删)。两侧都保留了 installSection / settingsScope 分支,peer 区间仍声明支持 0.1.2-rc.1、0.1.5-alpha.1、0.1.6-0 三条线;新增的 >=0.1.7-0 <0.2.0 这一段是修 bug——旧范围按 semver 预发布规则把目标宿主本身排除在外。仍无插件事件注册面——KNOWN_SESSION_EVENT_TYPES 不含 memory/*,且 Session.append 第三参只承载 surface 类型的 SurfaceIntent,故审计门保持自适应、行为不变(会在进程内告警一次,并在 /memory audit 输出里明示缺口)。类型证据来自三个面:本机 checkout 的已构建类型、node_modules 里钉住的已发布线、以及 DOM 库下的浏览器半侧。
Node `^22.19.0
Platforms Windows / macOS / Linux(纯 host;无原生代码、无网络)
Model 任意

What you get

dsh-memento 是能力接缝,不是又一个仓库:一个类型安全的 ctx.memory 服务、一个本地 SQLite 提供方(node:sqlite,WAL,0600,位于 $DSH_HOME/dsh-memento/memory.db),以及它的消费方——memory 工具与注入系统提示的冻结快照。

  • 审批门不可绕过。 每条写路径(add / replace / remove / seed)都被强制经过服务内部的审批 waterfall,而非工具层。writePolicy: ask | auto | off 是模型看不见的配置;replace / remove / consolidate 的审批载荷携带将被改动条目的全文,被拒的写同样落一条 *-denied 审计行。
  • 模型可见 ⟺ 已记录。 注入的快照逐字进入 system/message;每次写都能从 approval/asked + approval/decided + 插件自有审计表重建。
  • 有界且诚实。 每轨每层硬字符预算(默认 user 2000 / agent 4000)。写满返回结构化错误(用量 + 上限)——绝不截断、绝不自动压缩。
  • 审计缺口可见。 /memory audit 列出插件审计表,并在会话日志侧未落盘时附一行说明:本宿主不认识 memory/* 会话事件类型,而 append 未知类型会让该会话无法再加载,因此写入的审计由 approval/asked + approval/decided 与插件审计表承担。该提示随门自适应——宿主收录这些类型后自行消失。

两条轨道 × 两个层级 × 按 agent 隔离:user 轨(关于用户的事实)与 agent 轨(环境事实与约定),各自再分为 user-global 与 workspace 层,并按 agentPreset 隔离。快照在会话首次组装提示时冻结一次,会话中途不再变化。

Quick start

# 1. install the bundle into your profile
dsh plugin --profile web add "github:PerryLink/dsh-memento#main"

# or from npm (published releases)
dsh plugin --profile web add dsh-memento

# 2. restart and verify the row
dsh --profile web --dump-config | grep -A3 'id: memento'

Install & uninstall

  • git channel(最新 main):dsh plugin --profile web add git+https://github.com/PerryLink/dsh-memento.git。
  • npm channel(发布版本):dsh plugin --profile web add dsh-memento。
  • tarball channel:在本仓库执行 npm pack,然后 dsh plugin --profile web add ./dsh-memento-<version>.tgz。
  • uninstall:dsh plugin --profile web remove dsh-memento(记忆库与会话日志保留)。

Configuration

所有可调项均为 Schemastery Config 字段(可在 cordis.yml 中修改)。非法值在加载期响亮失败。在 memento 行下覆盖。

设置面板。 0.1.7 线上插件自己的 Config 就是它的设置页:表单的 namespace 是 profile entry id(memento,即本 bundle 那一行的 id:),可编辑字段恰好是插件标了 .volatile() 的那些(下表除 enabled 外的每个键),被接受的编辑合并进 profile 的插件行并提交进运行中的插件——无需改文件、无需重启。几乎全部即时生效(写策略、语言、预算、各上限、提案、面板;dbPath / auditRetentionDays 经重开 store 生效;retrieval.vector 经重装检索器生效);插件在加载期注册的面(snapshotOrder、工具描述文案)在重载后跟随,页面为这些字段标了记号。数值下限同时写在 schema 里,越界编辑在写入路径即被拒绝,不会留下一个用不了的配置。旧线(0.1.2-rc.1、0.1.5-alpha.1、0.1.6-0)上同一张卡片编辑 dsh-memento 设置 namespace,行为与从前一致;设置服务完全缺失时一切回退组合配置。悬浮窗按钮可在同一页面隐藏(panel.enabled)。

Key Default Meaning
enabled true 总开关;false 移除服务、工具、快照、命令、面板与 answerer(设置页不可编辑——禁用的插件没有设置项)
panel.enabled true 显示 Web 面板悬浮按钮;在设置页保存 false 后立即隐藏 🧠 入口,无需刷新(设置页本身不受影响)
dbPath '' → $DSH_HOME/dsh-memento/memory.db 绝对路径,或相对 $DSH_HOME(Windows 上回退到 ~/.dsh)
budgets.user.userGlobal 2000 user 轨 user-global 层的硬字符预算
budgets.user.workspace 2000 user 轨 workspace 层的硬字符预算
budgets.agent.userGlobal 4000 agent 轨 user-global 层的硬字符预算
budgets.agent.workspace 4000 agent 轨 workspace 层的硬字符预算
writePolicy 'ask' 默认写策略:ask / auto / off(模型不可见)
writePolicies {} 按轨/作用域或按来源的覆盖(如 user/workspace、source:claude)
language 'en' 模型可见文本与命令输出语言:en / zh
snapshotOrder -50 快照段顺序(在 harness 身份之后、persona 之前)
maxEntriesPerQuery 20 每次查询默认结果上限(硬上限 1000)
commandListLimit 50 每次 /memory list / query 渲染的条目数
commandAuditLimit 10 每次 /memory audit 渲染的审计行数
recall.historyLimitDefault 8 memory_recall 默认扫描的会话数
recall.snippetCap 5 memory_recall 每个会话的片段数
recall.snippetChars 300 memory_recall 片段字符数
recall.windowDays 30 memory_recall 近期窗口天数
retrieval.vector false 语义召回开关:true 且探测到嵌入 provider 时 memory_recall 走向量召回(伪嵌入),否则优雅降级回 substring
panelEntriesLimit 200 Web 面板条目分页大小
panelAuditLimit 20 Web 面板默认审计行数
auditRetentionDays 0 审计保留天数(0 = 永久保留)
proposals.enabled true 每次成功压缩后自动捕获一条记忆提案
proposals.maxChars 2000 提案字符上限
proposals.maxPending 8 待处理提案上限

Tools & surfaces

Surface Kind Notes
memory tool 带 Save/Skip 指引的 add/replace/remove/consolidate/query;写入走审批门
memory_recall tool 有界的记忆匹配 + 近期会话历史匹配
/memory command list · query · add · remove · consolidate · proposals · budgets · audit · export · import <path> · adapters
web panel client drawer 只读:浏览条目、搜索、预算条、审计尾部;悬浮入口按钮可隐藏(panel.enabled)
settings section DSH 设置侧栏 → dsh-memento 免改文件编辑除 enabled 外的全部配置字段(0.1.7 线上 namespace = memento profile entry,之前是 dsh-memento 设置 namespace);即时/重载生效时机在页面内标注

MCP server

dsh-memento 附带一个只读 stdio MCP 服务器(dsh-memento-mcp),让外部 MCP 客户端(Claude、Codex 等)无需 harness 即可检索记忆库。它通过 newline-delimited JSON(NDJSON)承载 JSON-RPC 2.0——每行一个 JSON 对象,不支持 Content-Length 分帧。

只读。 数据库以 node:sqlite 的 readOnly: true 打开(不跑迁移、不写 WAL、不 bump recall-count);库文件不存在时返回空结果而非崩溃。

工具 用途
memory_search {query, limit?} → 排序后的条目(经检索 Provider seam 的大小写不敏感子串检索)
memory_stats {} → {total, namespaces} 条目总数 + 按轨道/作用域概览

直接运行:

node bin/mcp-server.mjs
# 或 npm 安装后:npx dsh-memento-mcp

数据库路径取自 $DSH_MEMENTO_DB_PATH(绝对路径,或相对 $DSH_HOME);默认为 $DSH_HOME/dsh-memento/memory.db。

Claude Desktop(claude_desktop_config.json)配置示例:

{
  "mcpServers": {
    "dsh-memento": {
      "command": "npx",
      "args": ["-y", "dsh-memento-mcp"],
      "env": {
        "DSH_MEMENTO_DB_PATH": "/home/you/.dsh/dsh-memento/memory.db"
      }
    }
  }
}

服务器只读:无网络、无写入、无审批门——仅检索与统计。

How it's different

Plugin 是什么 dsh-memento 的差异
dsh-memory-evolve 记忆仓库 / 进化循环 类型化服务接缝、审批门与会话日志审计;无仓库野心
dsh-mnemon 记忆存储助手 协议 + 门 + 审计,而非又一个 store
dsh-kb-sieve 知识库筛选 无检索工程:小语料子串搜索,经 session_search/sessionQuery 跨会话召回
dsh-tdai-memory 任务驱动记忆工具 预算按 track×layer 且在服务内强制执行,而非尽力而为
claude-bridge Claude Code 桥接 DSH 原生;未来的 seed(source:'claude') 路径让桥接写入同一 store
dsh-external/Recall 外部 agent 记忆 本地优先、零网络、走 DSH 自有审批接缝
Official MCP memory examples DSH 宣称的"memory = 外部 MCP"立场 原生第一方补充:同目标、无外部服务器;两者共存

名称是 dsh-memento(已发布到 npm 与 GitHub)。不是 dsh-recall(易与 dsh-external/Recall 混淆),也不是已删除的旧名 dsh-memory。

dsh-memory-protocol v1

dsh-memento 是 DSH 记忆协议的社区预演——官方 ctx.memory 接缝的一个候选形态。该协议把本插件的接缝规范化为跨插件契约:

  • Entry spec — 两条轨道 × 两个层级 × 按 agent 隔离,外加短 tags(≤16 × ≤32 字符)与每次 replace 递增的每条目 version。

  • Write semantics — 幂等的唯一子串条件写;批准即所见载荷(replace / remove / consolidate 携带将被改动的全文)。

  • Audit contract — 每次写都能从 approval/asked + approval/decided + 提供方账本重建。

  • Budget model — BUDGET_EXCEEDED / AMBIGUOUS_MATCH 语义。

  • Schema versioning — 带响亮版本检查的迁移规则。

  • Spec — docs/protocol-v1.md(中文: protocol-v1.zh.md);规范性 JSON Schema 见 docs/schemas/dsh-memory-protocol-v1.schema.json。

Adapter registry — ctx.memoryAdapters(register / list / adapt / export)让第三方记忆插件通过注册纯数据转换器接入协议(可逆 register();导入走审批门 seed,导出只读)。接入指南:docs/adapters-guide.md(中文: adapters-guide.zh.md)。

Built-in adapter External format Notes
mem0 mem0 fact collections({facts: [{memory, metadata?}]}) metadata.category / metadata.tags 成为 tags;原始 messages 数组被拒绝——适配器只转换、绝不抽取
hermes-memory-md Hermes memory.md(## section + 列表项) 章节名成为 tags;非列表散文响亮失败
claude-code-memory-md CLAUDE.md 风格 markdown(标题、列表、段落) 列表项与段落成为条目;章节名成为 tags

Conformance suite — test/protocol-conformance/:可分发用例集,任何声明兼容的提供方都能跑(node test/protocol-conformance/run.mjs --provider ./your-factory.mjs);本仓库 CI 以自有提供方为黄金参考运行它(npm run test:conformance)。

Permissions & data

  • Permissions:workshop 清单声明 harness:tool、filesystem:read、filesystem:write,以及 network:none / subprocess:none / shell:none / python:none / credentials:none。写审批走官方审批接缝。
  • Data:本地 SQLite 数据库(0600),零网络、零凭据。
  • Session log:审计完整性来自审批对(approval/asked + approval/decided)加插件自有审计表;会话日志侧的缺口由 /memory audit 明示,宿主收录 memory/* 后自动消失。

Security boundaries

  • 仅公开服务。 只消费 tools、systemPrompt 与审批接缝;不改 engine / agent-loop / apiproxy / 官方 UI。
  • 零网络、零凭据。 本地数据库,POSIX 文件权限 0600。
  • 失败要大声。 库损坏、schema 过新或非法配置在加载期抛错;写满与子串歧义返回结构化错误。
  • 一进程一库。 多个会话共享 SQLite 库;共享同一 $DSH_HOME 的两个进程写同一文件(SQLite 锁下后写覆盖)。

Known limitations

  • 会话事件已声明、尚未发出(rc.2)。 memory/added|updated|removed|recalled|snapshot 已合并声明,但 rc.2 没有仓库外事件类型的注册面;一旦 harness 构建收录这些类型即自动开启发出。
  • ask 策略需要 answerer。 未组合 UI/ACP answerer 时,写入失败关闭。
  • 无 FTS5 索引。 子串搜索走大小写不敏感的 instr(对 CJK 正确)。

What we learned from the terminal memories

dsh-memento 不是 Claude Code、Codex 或 Hermes 的移植——但其设计刻意吸收了它们各自做对的部分,并拒绝有害的部分:

Terminal memory 做对了什么 dsh-memento 采纳了什么
Claude Code — CLAUDE.md 分层纯文本记忆文件(用户级 → 项目级),人类可读、可编辑,自动合并进每个会话 纯文本条目;user-global / workspace 层按会话合并;可浏览、export、审计的 store——透明即特性
Codex — AGENTS.md 按目录作用域自动发现并注入的指令,零模型摩擦 按会话 cwd 隔离的 workspace 层(Windows 大小写不敏感);会话开始时自动注入冻结快照
Hermes — memory.md 主动记忆保存,以及"只在工具层强制门可被后期工具注入绕过"的安全教训 带 Save/Skip 指引的 memory 工具 + 审批门控的自动捕获提案;门位于 ctx.memory 写方法内部,而非工具层

来源:Claude Code memory · Codex AGENTS.md · Hermes memory · Hermes #48181。

刻意拒绝的部分:隐藏地自动摘要进模型私有状态(此处压缩摘要成为等待人类 approve/dismiss 的待处理提案)、仓库/向量库野心,以及任何缺少人类可见审批或审计链的写入。也采纳了:Hermes 记载的"两个进程共享一个主目录写同一记忆文件"的告诫——见 Security boundaries。

Development

npm install              # node ^22.19 || >=24
npm test                 # node --test: 187 tests
npm run lint             # oxlint
npm run test:conformance # dsh-memory-protocol v1 conformance suite
npm run typecheck        # 宿主面 × 本机 D:\deepseek-harness checkout(无 checkout 时打印「不可验证」并 exit 0)
npm run typecheck:ci     # 宿主面 × node_modules 里钉住的已发布线
npm run check:client     # 浏览器半侧(DOM 库)类型门
npm run check:coverage   # line-coverage gate
npm run check:readmes    # five-language README consistency gate
npm run verify:self-contained # reject out-of-repo dependency specs
npm run verify:artifacts # artifact presence + syntax + import

lib/ 零 DSH 依赖(仅 node: 内置模块);DSH 导入只出现在 index.mjs。

Topics

dsh, dsh-plugin, deepseek-harness, memory, agent-memory, approval, audit, sqlite, cordis, llm

Contributors

  • @Niuniu-Sir — issue #1 中的启动崩溃报告,催生了 0.3.1 引入的 ~/.dsh 回退。

PerryLink DSH Plugin Family

This project is one of the 45 DeepSeek Harness plugins maintained by PerryLink. If this one helps you, the others likely will too:

Plugin One-liner
dsh-auto-review Second-model auto-review on the approval chain, fail-closed by default
dsh-autotier Automatic strong/cheap model-tier routing with deterministic risk guards and a /tier command
dsh-background-agents Durable background child agents with a Web UI sidebar, messaging and interrupt
dsh-budget Cost governance for DeepSeek Harness: budgets, carbon, and latency in one panel.
dsh-catalog DSH Desktop Market standard catalog source for the PerryLink family
dsh-cert-mcp Read-only MCP server exposing the certification registry: grades, snapshots and five-dimension evidence
dsh-checkpoint-rewind Claude Code /rewind-equivalent: snapshots, session forks, one-shot restore
dsh-claude-move Migrate Claude Code sessions, memory, skills and CLAUDE.md into DSH
dsh-click Cross-platform native desktop control for DeepSeek Harness — Windows first.
dsh-composer-history Terminal-style input history for the web composer: arrows, Ctrl+R search
dsh-data-quality Dataset quality checks and citation cross-checks (the optional numeric bridge consumed here)
dsh-defend Prompt-injection, jailbreak, and secret-leak defense for DeepSeek Harness.
dsh-doublecheck Engineering-discipline guard: requirements grill, test gates, adversary review
dsh-draw Unified static-image generation routing for DeepSeek Harness.
dsh-fast Read-only performance diagnostics for DeepSeek Harness.
dsh-fund-research Deterministic research reports for Chinese public mutual funds
dsh-github GitHub PR/issues integration for DSH, every write gated by approval
dsh-industry-research Industry research orchestration that seals its deliverables through this plugin's ctx.researchReport.assemble
dsh-laya Laya typed decisions (noul/choice/score) as a first-class Cordis service and model-visible tools
dsh-library Local document knowledge base for DeepSeek Harness.
dsh-local-ai Local-model (Ollama) integration for DeepSeek Harness.
dsh-lsp-actions LSP diagnostics, formatting, completion, code actions and rename over language servers
dsh-mask PII masking middleware: anonymize at the model boundary, restore at the display layer
dsh-mcp-panel Read-only MCP runtime panel: /mcp command + Settings tab with status, tools and errors
dsh-memento Approval-gated cross-session memory: ctx.memory seam + SQLite + memory tool
dsh-observe OpenTelemetry and Langfuse observability exporter for DeepSeek Harness.
dsh-output-styles Claude Code outputStyles-equivalent runtime style switching
dsh-permission-rules Claude Code-style declarative allow/deny/ask permission rules with audit
dsh-plugin-certification Community certification registry with repro-checkable grades and badges
dsh-plugin-doctor Zero-dependency static + sandbox smoke detector for DSH plugins
dsh-plugin-guide Plugin-development knowledge base as an on-demand agent skill
dsh-plugin-kit Shared zero-runtime-dependency toolkit for the PerryLink DSH plugins
dsh-plugin-upgrade One-package, one-corridor-index plugin upgrade skill: routes a repository to the matching closed corridor card
dsh-plugin-upgrade-015 Merged 0.1.3-alpha.1 → 0.1.5-rc.1 upgrade corridor card plus a zero-dependency seam scanner
dsh-reach Multi-channel approval/question bridge: WeChat/Telegram/Feishu, session console
dsh-research-report Verifiable research-report engine: content-addressed evidence ledger and sealed versions
dsh-score Multi-dimensional quality scoring for DeepSeek Harness plugins.
dsh-session-pin Pin sessions in the Web sidebar with durable ordering
dsh-session-sync Cross-device session sync for DeepSeek Harness — a dedicated git mirror of your session store.
dsh-skill-pack-security Security-audit skill pack: secret scan, dependency and supply-chain review
dsh-talk Voice-first session loop for DeepSeek Harness: talk to it, hear it answer.
dsh-team-rooms Cross-session team rooms: shared message bus, task board and timeline
dsh-test-drive Isolated install-and-smoke test drives for DeepSeek Harness plugins.
dsh-ticktick TickTick/Dida365 task bridge: session-header panel + 11 tools
dsh-translate Vendor parameter translation and deterministic JSON repair for DeepSeek Harness.

License

Apache License 2.0 © 2026 dsh-memento contributors

从 DSH Desktop 市场安装

所有 PerryLink 插件均可在 DSH Desktop 内置市场中浏览:市场 → 来源 → 添加来源 → 粘贴 https://perrylink-dsh-catalog.perrylink.workers.dev/catalog-source.json → 选中。安装仍需通过市场的 npm 身份校验与你的确认。

内容来自项目 README(GitHub)↗

链接

同类插件

查看整个分类 →

评论公开保存在 GitHub Discussions。加载评论会连接 GitHub 和 Giscus;发表内容需要 GitHub 账号。