DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Memento — DeepSeek Harness 插件(DSH Plugin)
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录
← Plugins

dsh-memento

Memento

面向 DeepSeek Harness 的有界、分层、需审批、可审计的跨会话记忆——一个能力接缝(ctx.memory 服务 + 本地 SQLite 提供程序 + memory 工具 + 冻结快照注入),而不是另一个记忆仓库

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add dsh-memento@0.5.14
README兼容性版本

兼容性与来源证明

Memento 以 dsh-memento 发布,当前版本为 0.5.14。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
web
发布来源
npm
Registry 更新时间
2026/9/20

版本

0.5.14stable
2026/9/19
0.5.13stable
2026/9/18
0.5.12stable
2026/9/12
查看其余 21 个版本收起版本
0.5.11stable
2026/9/10
0.5.10stable
2026/9/9
0.5.9stable
2026/9/9
0.5.8stable
2026/9/7
0.5.7stable
2026/9/7
0.5.6stable
2026/9/7
0.5.5stable
2026/9/4
0.5.4stable
2026/9/3
0.5.3stable
2026/9/2
0.5.2stable
2026/9/2
0.5.1stable
2026/9/1
0.5.0stable
2026/8/26
0.4.5stable
2026/8/23
0.4.4stable
2026/8/22
0.4.3stable
2026/8/21
0.4.2stable
2026/8/19
0.4.1stable
2026/8/19
0.4.0stable
2026/8/16
0.3.1stable
2026/8/15
0.3.0

相关插件

正在加载相关插件…

最新版
0.5.14
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
619.4 kB
文件数
44
Surface
web
许可证
Apache-2.0
发布源
npm
GitHub
★ 0
周下载
787
安全扫描
✓ v0.5.14 扫描通过
查看源码 ↗项目主页 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题
stable
2026/8/15
0.2.0stable
2026/8/14

相关插件

继续浏览 memory-context 分类下经过校验的插件。

Memory Plugin@openviking/dsh-memory-plugin适用于 DeepSeek Harness 的 OpenViking 记忆与上下文套件Contextdsh-context用于上下文洞察和管理的 DeepSeek Harness 插件,提供上下文仪表板和上下文命令,帮助了解上下文的构成及其演变过程。Weknora@wxg-prc-cpg/dsh-weknora适用于 DeepSeek Harness (dsh) 的 WeKnora 知识检索工具:通过自有知识库进行语义搜索、文档阅读以及 RAG/代理回答。Memsearch Dsh@zilliz/memsearch-dsh适用于 DeepSeek Harness 的 MemSearch 插件:在多个代理之间共享 Markdown 记忆,支持捕获、步骤前上下文注入、记忆召回技能和技能候选审核面板。

README

dsh-memento

  • 1024 store channel: npm i -g dsh1024 once, then dsh1024 plugin --profile web add dsh-memento (counts toward the deepseek1024.com install ranking).

Bounded, layered, approval-gated, auditable cross-session memory for DeepSeek Harness.

A typed ctx.memory seam, a write-approval gate no model path can bypass, and an audit trail you can rebuild — from the approval pair plus the plugin's own audit table, with the session-log gap named out loud.

English · 简体中文 · Español · Português · हिन्दी


Compatibility

SurfaceStatus
HarnessDeepSeek Harness dsh-v0.1.6-alpha.2 (re-checked 2026-09-18): still no plugin event-registration surface — KNOWN_SESSION_EVENT_TYPES does not carry memory/*, and Session.append's third argument only carries a SurfaceIntent for surface-eligible types, so the audit gate stays adaptive and skips as before (it now says so once per process and in /memory audit). Peer range keeps the 0.1.2-rc.1, 0.1.5-alpha.1 and 0.1.6-0 lines. Type evidence comes from three faces: the local checkout's built types, the pinned published line in node_modules, and the browser half under a DOM lib.
Node`^22.19.0
PlatformsWindows / macOS / Linux (pure host; no native code, no network)
ModelAny

What you get

dsh-memento is a capability seam, not another memory warehouse: a typed ctx.memory service, a local SQLite provider (node:sqlite, WAL, 0600, at $DSH_HOME/dsh-memento/memory.db), and its consumers — the memory tool and a frozen snapshot injected into the system prompt.

  • The approval gate cannot be bypassed. Every write path (add / replace / remove / seed) is forced through the approval waterfall inside the service, not in the tool layer. writePolicy: ask | auto | off is model-invisible configuration; replace / remove / consolidate carry the full text of the entries they change in the approval payload, and a denied write still lands a *-denied audit row.
  • Model-visible ⟺ logged. The injected snapshot lands verbatim in system/message; every write is reconstructable from approval/asked + approval/decided + the plugin's own audit table.
  • Bounded and honest. Hard per-track/per-layer character budgets (default user 2000 / agent 4000). A full store fails with a structured error (usage + limit) — never truncated, never auto-compacted.
  • The audit gap is visible. /memory audit lists the plugin audit table and appends one line when the session-log side is not written: this harness does not know the memory/* session event types, and appending unknown types would make the session unloadable, so writes are audited through approval/asked + approval/decided and the plugin's table instead. The gate is adaptive — the line disappears on its own once the host knows those types.

Two tracks × two layers × per-agent key: a user track (facts about the user) and an agent track (environment facts and conventions), each split into user-global and workspace layers, isolated per agentPreset. The snapshot is frozen once per session at first prompt assembly and never changes mid-session.

Quick start

# 1. install the bundle into your profile
dsh plugin --profile web add "github:PerryLink/dsh-memento#main"

# or from npm (published releases)
dsh plugin --profile web add dsh-memento

# 2. restart and verify the row
dsh --profile web --dump-config | grep -A3 'id: memento'

Install & uninstall

  • git channel (latest main): dsh plugin --profile web add git+https://github.com/PerryLink/dsh-memento.git.
  • npm channel (published releases): dsh plugin --profile web add dsh-memento.
  • tarball channel: npm pack in this repo, then dsh plugin --profile web add ./dsh-memento-<version>.tgz.
  • uninstall: dsh plugin --profile web remove dsh-memento (the memory database and session logs are kept).

Configuration

All tunables are Schemastery Config fields (changeable from cordis.yml). Invalid values fail loudly at load. Override under the memento row.

Settings panel. When the DSH settings service is mounted, every field below (except enabled) is editable from the plugin's own dsh-memento entry in the DSH settings sidebar (a top-level section, like General or Plugins); edits land in the settings user layer (settings.yaml) and need no file editing. Nearly everything applies live (write policies, language, budgets, limits, proposals, panel, dbPath / auditRetentionDays via a store reopen, retrieval.vector via a retriever swap) — only snapshotOrder needs a DSH reload. Without the settings service everything falls back to the composed cordis config, exactly as before. The floating panel button can be hidden from the same page (panel.enabled).

KeyDefaultMeaning
enabledtrueMaster switch; false removes the service, tools, snapshot, command, panel, and answerer (not editable from the settings page — a disabled plugin has no settings entry)
panel.enabledtrueShow the web panel's floating button; saving false from the settings page hides the 🧠 entry immediately, no reload needed (the settings page itself stays reachable)
dbPath'' → $DSH_HOME/dsh-memento/memory.dbAbsolute, or relative to $DSH_HOME (falls back to ~/.dsh on Windows)
budgets.user.userGlobal2000Hard character budget for the user track's user-global layer
budgets.user.workspace2000Hard character budget for the user track's workspace layer
budgets.agent.userGlobal4000Hard character budget for the agent track's user-global layer
budgets.agent.workspace4000Hard character budget for the agent track's workspace layer
writePolicy'ask'Default write policy: ask / auto / off (model-invisible)
writePolicies{}Per-track/scope or per-source overrides (e.g. user/workspace, source:claude)
language'en'Model-visible and command output language: en / zh
snapshotOrder-50Snapshot section order (after harness identity, before persona)
maxEntriesPerQuery20Default per-query result cap (hard-capped at 1000)
commandListLimit50

Tools & surfaces

SurfaceKindNotes
memorytooladd/replace/remove/consolidate/query with Save/Skip guidance; writes ride the approval gate
memory_recalltoolBounded memory matches plus recent session-history matches
/memorycommandlist · query · add · remove · consolidate · proposals · budgets · audit · export · import <path> · adapters
web panelclient drawerRead-only: browse entries, search, budget bars, audit tail; the floating entry button can be hidden (panel.enabled)
settings sectionDSH settings sidebar → dsh-mementoEdit every config field (except enabled) without touching files; live vs reload-required timing is marked on the page

MCP server

dsh-memento ships a read-only stdio MCP server (dsh-memento-mcp) so external MCP clients (Claude, Codex, …) can search the memory store without a harness. It speaks JSON-RPC 2.0 over newline-delimited JSON (NDJSON) — one JSON object per line, no Content-Length framing.

Read-only. The database is opened with node:sqlite readOnly: true (no migrations, no WAL writes, no recall-count bump); a missing database returns empty results instead of crashing.

ToolPurpose
memory_search{query, limit?} → ranked entries (case-insensitive substring via the retrieval Provider seam)
memory_stats{} → {total, namespaces} entry count + per-track/scope overview

Run it directly:

node bin/mcp-server.mjs
# or, after npm install: npx dsh-memento-mcp

The database path is $DSH_MEMENTO_DB_PATH (absolute, or relative to $DSH_HOME); it defaults to $DSH_HOME/dsh-memento/memory.db.

Claude Desktop (claude_desktop_config.json) example:

{
  "mcpServers": {
    "dsh-memento": {
      "command": "npx",
      "args": ["-y", "dsh-memento-mcp"],
      "env": {
        "DSH_MEMENTO_DB_PATH": "/home/you/.dsh/dsh-memento/memory.db"
      }
    }
  }
}

The server is read-only: no network, no writes, no approval gate — search and stats only.

How it's different

PluginWhat it isdsh-memento's difference
dsh-memory-evolvememory warehouse / evolution loopsa typed service seam, approval gate, and session-log audit; no warehouse ambition
dsh-mnemonmemory store helperprotocol + gate + audit, not another store
dsh-kb-sieveknowledge-base sievingno retrieval engineering: small-corpus substring search, cross-session recall via session_search/sessionQuery
dsh-tdai-memorytask-driven memory toolingbudgets are per track×layer and enforced in the service, not best-effort
claude-bridgeClaude Code bridgingDSH-native; a future seed(source:'claude') path lets a bridge feed the same store
dsh-external/Recallexternal agent memorylocal-first, zero-network, rides DSH's own approval seam
Official MCP memory examplesDSH's stated "memory = external MCP" positionthe native first-party complement: same goal, no external server; both coexist

The name is dsh-memento (published on npm and GitHub). Not dsh-recall (confusable with dsh-external/Recall), not the deleted legacy name dsh-memory.

dsh-memory-protocol v1

dsh-memento is the community rehearsal of the DSH memory protocol — a candidate shape for an official ctx.memory seam. The protocol normalizes this plugin's seam into a cross-plugin contract:

  • Entry spec — two tracks × two layers × per-agent key, plus short tags (≤16 × ≤32 chars) and a per-entry version that increments on every replace.

  • Write semantics — idempotent unique-substring conditional writes; approve-what-you-see payloads (replace / remove / consolidate carry the full text they change).

  • Audit contract — every write reconstructable from approval/asked + approval/decided + the provider ledger.

  • Budget model — BUDGET_EXCEEDED / AMBIGUOUS_MATCH semantics.

  • Schema versioning — migration rules with loud version checks.

  • Spec — docs/protocol-v1.md (中文: protocol-v1.zh.md); normative JSON Schema at docs/schemas/dsh-memory-protocol-v1.schema.json.

Adapter registry — ctx.memoryAdapters (register / list / adapt / export) lets third-party memory plugins speak the protocol by registering a pure data converter (reversible register(); import rides the approval-gated seed, export is read-only). Onboarding: docs/adapters-guide.md (中文: adapters-guide.zh.md).

Built-in adapterExternal formatNotes
mem0mem0 fact collections ({facts: [{memory, metadata?}]})metadata.category / metadata.tags become tags; raw messages arrays are rejected — adapters convert, never extract
hermes-memory-mdHermes memory.md (## section + bullets)section names become tags; non-bullet prose fails loudly
claude-code-memory-mdCLAUDE.md-style markdown (headings, bullets, paragraphs)bullets and paragraphs become entries; section names become tags

Conformance suite — test/protocol-conformance/: a distributable case set any provider claiming compatibility runs (node test/protocol-conformance/run.mjs --provider ./your-factory.mjs); this repo's CI runs it against its own provider as the golden reference (npm run test:conformance).

  • Upstream proposal — docs/upstream-proposal.md (中文: upstream-proposal.zh.md): why the official ctx.memory seam should adopt the protocol, the differences, and the migration path.

Permissions & data

  • Permissions: declares harness:tool, filesystem:read, filesystem:write, and network:none / subprocess:none / shell:none / python:none / credentials:none in its workshop manifest. Write approval rides the official approval seam.
  • Data: local SQLite database (0600), zero network, zero credentials.
  • Session log: audit completeness comes from the approval pair (approval/asked + approval/decided) plus the plugin's own audit table; the session-log side of that gap is declared in /memory audit and disappears once the host registers memory/*.

Security boundaries

  • Public services only. Consumes tools, systemPrompt, and the approval seam; no engine / agent-loop / apiproxy / official-UI changes.
  • Zero network, zero credentials. Local database with POSIX file mode 0600.
  • Fail loud. Corrupt DB, newer schema, or invalid config fails at load; full budgets and ambiguous substring matches fail with structured errors.
  • One process, one store. Multiple sessions share the SQLite store; two processes sharing one $DSH_HOME write the same file (last-writer-wins under SQLite locking).

Known limitations

  • Session events are declared, not yet emitted (rc.2). memory/added|updated|removed|recalled|snapshot are merge-declared, but rc.2 has no registration surface for out-of-repo event types; emission turns on once a harness build registers them.
  • ask policy needs an answerer. With no UI/ACP answerer composed, writes fail closed.
  • No FTS5 indexing. Substring search runs on case-insensitive instr (correct for CJK).

What we learned from the terminal memories

dsh-memento is not a port of Claude Code, Codex, or Hermes — but its design deliberately absorbed the parts each got right, and refused the parts that hurt:

Terminal memoryWhat it got rightWhat dsh-memento adopted
Claude Code — CLAUDE.mdhierarchical plain-text memory files (user-level → project-level), human-readable and human-editable, merged automatically into every sessionplain-text entries; user-global / workspace layers merged per session; a store you can browse, export, and audit — transparency as a feature
Codex — AGENTS.mdper-directory scoped instructions auto-discovered and injected with zero model frictionthe workspace layer keyed by the session cwd (Windows case-insensitive); the frozen snapshot injected automatically at session start
Hermes — memory.mdproactive memory saves and the security lesson that a gate enforced only in the tool layer is bypassable by late tool injectionthe memory tool with Save/Skip guidance + approval-gated auto-capture proposals; the gate lives inside ctx.memory's write methods, not in the tool layer

Sources: Claude Code memory · Codex AGENTS.md · Hermes memory · Hermes #48181.

And the parts deliberately refused: hidden auto-summarization into model-private state (compaction summaries here become pending proposals that wait for a human approve/dismiss), warehouse/vector-store ambitions, and any write that lacks a human-visible approval or audit trail. Also adopted: Hermes's documented caveat that two processes sharing one home directory write the same memory file — see Security boundaries.

Development

npm install              # node ^22.19 || >=24
npm test                 # node --test: 187 tests
npm run lint             # oxlint
npm run test:conformance # dsh-memory-protocol v1 conformance suite
npm run typecheck        # host face vs a local D:\deepseek-harness checkout (prints "not verifiable" and exits 0 without one)
npm run typecheck:ci     # host face vs the pinned published line in node_modules
npm run check:client     # browser half (DOM lib) type gate
npm run check:coverage   # line-coverage gate
npm run check:readmes    # five-language README consistency gate
npm run verify:self-contained # reject out-of-repo dependency specs
npm run verify:artifacts # artifact presence + syntax + import

lib/ is zero-DSH-dependency (node: builtins only); DSH imports exist only in index.mjs.

Topics

dsh, dsh-plugin, deepseek-harness, memory, agent-memory, approval, audit, sqlite, cordis, llm

Contributors

  • @Niuniu-Sir — the boot-crash report in issue #1 that led to the ~/.dsh fallback shipped in 0.3.1.

PerryLink DSH Plugin Family

This project is one of the 40 DeepSeek Harness plugins maintained by PerryLink. If this one helps you, the others likely will too:

PluginOne-liner
dsh-auto-reviewSecond-model auto-review on the approval chain, fail-closed by default
dsh-background-agentsDurable background child agents with a Web UI sidebar, messaging and interrupt
dsh-budgetCost governance for DeepSeek Harness: budgets, carbon, and latency in one panel.
dsh-checkpoint-rewindClaude Code /rewind-equivalent: snapshots, session forks, one-shot restore
dsh-claude-moveMigrate Claude Code sessions, memory, skills and CLAUDE.md into DSH
dsh-clickCross-platform native desktop control for DeepSeek Harness — Windows first.
dsh-composer-historyTerminal-style input history for the web composer: arrows, Ctrl+R search
dsh-data-qualityDataset quality checks and citation cross-checks (the optional numeric bridge consumed here)
dsh-defendPrompt-injection, jailbreak, and secret-leak defense for DeepSeek Harness.
dsh-doublecheckEngineering-discipline guard: requirements grill, test gates, adversary review
dsh-drawUnified static-image generation routing for DeepSeek Harness.

Install from the DSH Desktop Market

All PerryLink plugins are browsable in the built-in DSH Desktop Market: Market → Sources → add source → paste https://perrylink-dsh-catalog.perrylink.workers.dev/catalog-source.json → select it. Installation still goes through the Market's npm-identity verification and your confirmation.

License

Apache License 2.0 © 2026 dsh-memento contributors

Entries rendered per /memory list / query
commandAuditLimit10Audit rows rendered per /memory audit
recall.historyLimitDefault8memory_recall sessions scanned by default
recall.snippetCap5memory_recall snippets per session
recall.snippetChars300memory_recall snippet characters
recall.windowDays30memory_recall recency window in days
retrieval.vectorfalseSemantic recall switch: true enables memory_recall vector recall (fake hash embedding) when an embedding provider is available; otherwise degrades to substring
panelEntriesLimit200Web panel entries page size
panelAuditLimit20Web panel audit rows by default
auditRetentionDays0Audit retention (0 = keep forever)
proposals.enabledtrueAuto-capture a memory proposal after each successful compaction
proposals.maxChars2000Proposal character cap
proposals.maxPending8Pending proposal cap
dsh-fastRead-only performance diagnostics for DeepSeek Harness.
dsh-fund-researchDeterministic research reports for Chinese public mutual funds
dsh-githubGitHub PR/issues integration for DSH, every write gated by approval
dsh-industry-researchIndustry research orchestration that seals its deliverables through this plugin's ctx.researchReport.assemble
dsh-libraryLocal document knowledge base for DeepSeek Harness.
dsh-local-aiLocal-model (Ollama) integration for DeepSeek Harness.
dsh-lsp-actionsLSP diagnostics, formatting, completion, code actions and rename over language servers
dsh-maskPII masking middleware: anonymize at the model boundary, restore at the display layer
dsh-mcp-panelRead-only MCP runtime panel: /mcp command + Settings tab with status, tools and errors
dsh-observeOpenTelemetry and Langfuse observability exporter for DeepSeek Harness.
dsh-output-stylesClaude Code outputStyles-equivalent runtime style switching
dsh-permission-rulesClaude Code-style declarative allow/deny/ask permission rules with audit
dsh-personal-directivePersonal directive injector with top-bar toggle (framework edition)
dsh-plugin-guidePlugin-development knowledge base as an on-demand agent skill
dsh-plugin-doctorZero-dependency static + sandbox smoke detector for DSH plugins
dsh-reachMulti-channel approval/question bridge: WeChat/Telegram/Feishu, session console
dsh-research-reportVerifiable research-report engine: content-addressed evidence ledger and sealed versions
dsh-scoreMulti-dimensional quality scoring for DeepSeek Harness plugins.
dsh-session-pinPin sessions in the Web sidebar with durable ordering
dsh-session-syncCross-device session sync for DeepSeek Harness — a dedicated git mirror of your session store.
dsh-skill-pack-securitySecurity-audit skill pack: secret scan, dependency and supply-chain review
dsh-talkVoice-first session loop for DeepSeek Harness: talk to it, hear it answer.
dsh-test-driveIsolated install-and-smoke test drives for DeepSeek Harness plugins.
dsh-ticktickTickTick/Dida365 task bridge: session-header panel + 11 tools
dsh-translateVendor parameter translation and deterministic JSON repair for DeepSeek Harness.
dsh-wechatWeChat ↔ DSH bridge (Tencent iLink bot): text/image/file/voice, approvals in chat
dsh-autotierAutomatic strong/cheap model-tier routing with deterministic risk guards and a /tier command
dsh-catalogDSH Desktop Market standard catalog source for the PerryLink family
dsh-cert-mcpRead-only MCP server exposing the certification registry: grades, snapshots and five-dimension evidence
dsh-kitOne-command starter pack that installs the core family
dsh-plugin-certificationCommunity certification registry with repro-checkable grades and badges
dsh-plugin-kitShared zero-runtime-dependency toolkit for the PerryLink DSH plugins
dsh-plugin-portalZero-dependency static portal rendering the whole plugin family as one page
dsh-plugin-upgrade-015Merged 0.1.3-alpha.1 → 0.1.5-rc.1 upgrade corridor card plus a zero-dependency seam scanner
dsh-team-roomsCross-session team rooms: shared message bus, task board and timeline