highland0971/dsh-native-memory
DeepSeek Harness的原生按工作区长期记忆:审批门控写入、引用来源、FTS跨会话召回——无需外部服务器,无额外运行时依赖。
Project Overview项目介绍
dsh-native-memory adds per-workspace long-term memory to the DeepSeek Harness. It stores facts and profiles in a dedicated harness storage-domain, supports cross-session recall via session-query FTS, and gates every write behind explicit human approval with cited provenance and a session-log audit. Use it when a project needs durable, workspace-scoped context that survives sessions. Caveat: the plugin runs third-party code with your permissions, so review the source and security model first; secret-shaped text is rejected by default, though the credential detector may flag benign long token-like values.
DSH 原生长记忆插件:每个工作区在 harness 自有存储域中独立保存事实与画像,通过会话查询 FTS 跨会话召回,写入需人工审批并记录出处,工具涵盖记忆、编辑、遗忘、检索、合并、导入、导出与画像读取。当心:插件以你的权限执行第三方代码,请审阅源码与安全模型;默认拒绝写入密钥类文本,但凭证检测可能误判较长的 token 字段。
请帮我了解并安装插件:【dsh-native-memory】【https://github.com/highland0971/dsh-native-memory】
Send this message to DSH in your current session. CLI install commands may not be accurate across systems — DSH will figure it out for you.把上面这条消息直接发给当前会话里的 DSH,让它帮你了解并安装。安装命令不一定准确,发给 DSH 更稳。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add dsh-native-memory
把 highland0971/dsh-native-memory 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-native-memory
Native, per-workspace long-term memory for DeepSeek Harness (dsh): facts and profiles stored on the harness's own storage-domain, cross-session recall through session-query FTS, approval-gated writes, and cited provenance — no external server, no extra runtime dependency.
⚠️ Installing a plugin runs third-party code on your machine with your own permissions. Review the source (
src/) and the security model before installing.
Why this one
| dsh-hermes-memory | dsh-native-memory | |
|---|---|---|
| Storage | ~/.dsh/settings.yaml namespace |
dedicated storage-domain unit (~/.dsh/storages/dsh_memory.json) |
| Scope | user-global, all projects | per workspace (exact-cwd authorization) |
| Write safety | silent, model-only | human approval gate + session-log audit |
| Recall | everything always injected (hard caps) | bounded always-on profile plus on-demand recall + FTS over past sessions |
| Dependencies | vendored imports into the harness checkout | none beyond zod + the harness itself |
See docs/design.md for the full architecture and the competitive landscape analysis.
Install
dsh plugin --profile web add dsh-native-memory # npm after release
dsh plugin --profile web add /path/to/this/repo # from a checkout
Restart dsh web. The bundle enables session-query full-text search and adds
the memory tools to every session. Details and configuration:
docs/install.md.
Tools
| Tool | Kind | Gate |
|---|---|---|
memory_remember |
add/update a fact in this workspace (secrets rejected by default) | approval |
memory_edit |
replace a fact | approval |
memory_forget |
archive a fact (soft delete) | approval |
memory_recall |
deterministic three-tier keyword scan (tags > text > fuzzy; freshness/access tie-breaks) | none |
memory_search |
FTS over this workspace's past sessions (caller excluded) | none |
memory_expand |
expand a fact's citation to the original log excerpt | none |
memory_consolidate |
near-duplicate merge suggestions + cap budget | none |
memory_import |
import candidate facts from a past session's log | approval (per fact) |
memory_profile |
read the always-injected workspace profile | none |
memory_export |
write a git-friendly Markdown mirror (.dsh-memory/memory.md, masked, idempotent) |
none |
Every fact records its origin (sessionId, seq) — memory stays
reconstructable from the lossless session log.
Writes reject secret-shaped text (tokens / keys / passwords) by default;
secretPolicy: "mask" | "off" in the bundle patch relaxes that. The
credential-assignment detector can flag benign token: … values of ≥16
characters. Prompt injection and tool output always mask secrets.
A read-only browser page (settings → 记忆) lists every workspace's facts with
secrets masked; deletions are copied as a memory_forget instruction and land
in the chat through the approval gate.
Opt-in session-end proposals (proposeOnSessionEnd: true): one cheap LLM call
distills a finished session into candidate facts shown in the next sessions;
they become facts only through the approval-gated memory_remember.
A compaction drift guard (compactionGuard: true, on by default) surfaces
literal anchors a compaction summary dropped, as data to verify in the next
sessions — deterministic, no LLM.
Development
pnpm install
pnpm build && pnpm typecheck && pnpm test
New contributors start at docs/handoff.md and docs/contributing.md. Chinese docs: README.zh.md.
vshulcz/deja-vu
sandbaseai/sandbase-harness
adoresever/graph-memory
mnemon-dev/mnemon
modusensus/dsh-mneme
Phant0Meow/dsh-meow-memory