Apache-2.0, DSH-native cross-session memory: a `ctx.memory` seam with an un-bypassable approval gate and session-log audit, stored locally in SQLite with zero network and POSIX `0600` permissions.
DSH integration
Native runtime
Author-claimed
Safety audit
Unaudited
Last verified
2026-08-29
License
Apache-2.0
01What can it help you accomplish?
Capture and persist facts about the user and the agent environment across DeepSeek Harness sessions
Two tracks × two layers of typed `ctx.memory` entries in a local SQLite store ($DSH_HOME/dsh-memento/memory.db), each capped by a hard per-track character budget
DeepSeek Harness users who want durable, human-auditable memory instead of losing context between sessions
Recall what was remembered and reconstruct every write for audit
A frozen session snapshot in the system prompt plus audit rows (approval/asked + approval/decided) rebuildable from the session log
Teams and developers who need every memory write to be approval-gated and traceable to a human decision
02How to install into DeepSeek Harness
Prerequisites
- Node `^22.19.0 || >=24.0.0` (per the Compatibility table)
- DeepSeek Harness `0.1.1-rc.2` (per the Compatibility table)
Installation steps
- 01
$ dsh plugin --profile web add dsh-memento
- 02
$ dsh plugin --profile web add git+https://github.com/PerryLink/dsh-memento.git
Verify the integration
- dsh --profile web --dump-config | grep -A3 'id: memento'
03DSH integration and capability boundaries
DSH-native capability seam: a typed `ctx.memory` service, a write-approval gate on the official approval seam, and a frozen snapshot injected into the system prompt
memory tool
natural-language add / replace / remove / consolidate / query requests from the assistant→memory entries persisted to the local SQLite store, gated by the write-approval waterfall
every write is forced through the approval waterfall inside the service, not in the tool layerApproval-gated write seam
write operations (add / replace / remove / seed)→approved entries written to the store; denied writes still recorded as `*-denied` audit rows
denied writes land a `*-denied` audit rowFrozen snapshot injection
the assembled system prompt at first prompt assembly each session→a frozen snapshot of the memory store injected verbatim into `request/header.system`
snapshot is frozen once per session and never changes mid-sessionRead-only MCP server (dsh-memento-mcp)
JSON-RPC 2.0 over NDJSON: `memory_search` / `memory_stats`→ranked entries and store stats for external MCP clients
no network, no writes, no approval gate — search and stats only
04Who is it for? When not to use it?
Good for
- DeepSeek Harness users who want durable, human-auditable memory instead of losing context between sessions
- Teams and developers who need every memory write to be approval-gated and traceable to a human decision
Not for
- Session events are declared but not yet emitted in rc.2; emission turns on once a harness build registers them.
- One process, one store: multiple sessions share the SQLite store, and two processes sharing one `$DSH_HOME` write the same file (last-writer-wins).
05Compatibility, maintenance and safety notes
- Declares `harness:tool`, `filesystem:read`, `filesystem:write`, and `network:none`; write approval rides the official approval seam.
- Zero network, zero credentials. The database is a local SQLite file with POSIX file mode `0600`.
- Session events are declared but not yet emitted in rc.2; emission turns on once a harness build registers them.
- One process, one store: multiple sessions share the SQLite store, and two processes sharing one `$DSH_HOME` write the same file (last-writer-wins).
Apache-2.0 · actively maintained (latest release v0.4.5, 2026-08-23)
06Frequently asked questions
How do I install dsh-memento?
Add it through the dsh CLI: `dsh plugin --profile web add dsh-memento` (npm) or `dsh plugin --profile web add git+https://github.com/PerryLink/dsh-memento.git` (latest main). Then restart and check the row with `dsh --profile web --dump-config | grep -A3 'id: memento'`.
Can a model bypass the approval gate?
No. Every write path (add / replace / remove / seed) is forced through the approval waterfall inside the `ctx.memory` service, not in the tool layer, so no model path can skip it. `writePolicy: ask | auto | off` is model-invisible configuration.
Where is my memory stored?
In a local SQLite database at `$DSH_HOME/dsh-memento/memory.db` (mode `0600`), with zero network and zero credentials. Uninstalling keeps the database and session logs.
What does the read-only MCP server do?
dsh-memento-mcp is a read-only stdio MCP server that lets external clients (Claude, Codex, …) search the store via `memory_search` / `memory_stats` over NDJSON — no network, no writes, no approval gate.
Does it work with other memory tools?
It speaks the dsh-memory-protocol v1 and ships adapters for mem0, Hermes memory.md and CLAUDE.md-style markdown via `ctx.memoryAdapters`; it is the native first-party complement to external-MCP memory, not a replacement.
07Related DSH workflows
weknora
by tencent
Open-source LLM knowledge platform: turn raw documents into a queryable RAG, an autonomous reasoning agent, and a self-maintaining Wiki.
honcho
by plastic-labs
Memory library for building stateful agents
webnovel-writer
by lingfengqaq
A long-form Chinese web-novel writing assistant for Claude Code and DeepSeek Harness, designed to reduce memory loss and hallucinations in serialized projects of up to 2 million characters.
mirage
by strukto-ai
The World's First Virtual Terminal for AI Agents
08Data and sources
dsh-memento` is a capability seam, not another memory warehouse: a typed `ctx.memory` service
DeepSeek Harness `0.1.1-rc.2`
This page is generated from the project’s public documentation, repository metadata and a structured parse of DSH Plugins; last verified on 2026-08-29. Found an error? Submit a correction.
Best DeepSeek Harness Plugins
Twelve plugins worth installing first — picked from the whole catalog, across every category.
