by PerryLink
Bounded, layered, approval-gated, auditable cross-session memory for DeepSeek Harness (capability seam: ctx.memory + SQLite provider + memory tool + frozen snapshot injection)
# Add to your Claude Code skills
git clone https://github.com/PerryLink/dsh-mementoLast scanned: 10/5/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-10-05T11:13:12.576Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how dsh-memento compares with popular alternatives.
dsh-memento is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by PerryLink. Bounded, layered, approval-gated, auditable cross-session memory for DeepSeek Harness (capability seam: ctx.memory + SQLite provider + memory tool + frozen snapshot injection). It has 139 GitHub stars.
Yes. dsh-memento passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/PerryLink/dsh-memento" and add it to your Claude Code skills directory (see the Installation section above).
dsh-memento is primarily written in JavaScript. It is open-source under PerryLink on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh dsh-memento against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
npm i -g dsh1024 once, then dsh1024 plugin --profile web add dsh-memento (counts toward the deepseek1024.com install ranking).
Bounded, layered, approval-gated, auditable cross-session memory for DeepSeek Harness.
A typed ctx.memory seam, a write-approval gate no model path can bypass, and an audit trail you can rebuild — from the approval pair plus the plugin's own audit table, with the session-log gap named out loud.
English · 简体中文 · Español · Português · हिन्दी
这个插件是 DSH 插件家族的一员(40+ 个,全部 Apache-2.0)。如果你在用,给个 star —— 它不会解锁任何功能,但会让下一个人在搜索里更容易找到它。
English: part of a 40+ plugin family for DeepSeek Harness. If it is useful, a star helps the next person find it — nothing is gated behind it.
| Surface | Status |
|---|---|
| Harness | DeepSeek Harness dsh-v0.2.1-alpha.1 (adapted 2026-10-04): the 0.1.7 line replaced the whole settings registration surface (installSettingsSection / SettingsProvider.installSection / SettingsNamespace / SettingsScope) with live Config forms, so both halves follow the new contract — a form's namespace is the profile entry id (memento), its editable fields are the .volatile() ones, and an accepted edit is committed into the running plugin instead of remounting it. The browser half reads that form through ctx.configForms.get(entryId) (the ctx.settingsScope service is gone). Both halves keep their installSection / settingsScope branches for the 0.1.2-rc.1, 0.1.5-alpha.1 and 0.1.6-0 lines the peer range still advertises, and the new >=0.1.7-0 <0.2.0 clause is what makes the target host itself installable (the old range excluded it by semver's prerelease rule). Still no plugin event-registration surface — KNOWN_SESSION_EVENT_TYPES does not carry memory/*, and Session.append's third argument only carries a SurfaceIntent for surface-eligible types, so the audit gate stays adaptive and skips as before (it says so once per process and in /memory audit). Type evidence comes from three faces: the local checkout's built types, the pinned published line in node_modules, and the browser half under a DOM lib. |
| Node | `^22.19.0 |
| Platforms | Windows / macOS / Linux (pure host; no native code, no network) |
| Model | Any |
dsh-memento is a capability seam, not another memory warehouse: a typed ctx.memory service, a local SQLite provider (node:sqlite, WAL, 0600, at $DSH_HOME/dsh-memento/memory.db), and its consumers — the memory tool and a frozen snapshot injected into the system prompt.
add / replace / remove / seed) is forced through the approval waterfall inside the service, not in the tool layer. writePolicy: ask | auto | off is model-invisible configuration; replace / remove / consolidate carry the full text of the entries they change in the approval payload, and a denied write still lands a *-denied audit row.system/message; every write is reconstructable from approval/asked + approval/decided + the plugin's own audit table./memory audit lists the plugin audit table and appends one line when the session-log side is not written: this harness does not know the memory/* session event types, and appending unknown types would make the session unloadable, so writes are audited through approval/asked + approval/decided and the plugin's table instead. The gate is adaptive — the line disappears on its own once the host knows those types.Two tracks × two layers × per-agent key: a user track (facts about the user) and an agent track (environment facts and conventions), each split into user-global and workspace layers, isolated per agentPreset. The snapshot is frozen once per session at first prompt assembly and never changes mid-session.
# 1. install the bundle into your profile
dsh plugin --profile web add "github:PerryLink/dsh-memento#main"
# or from npm (published releases)
dsh plugin --profile web add dsh-memento
# 2. restart and verify the row
dsh --profile web --dump-config | grep -A3 'id: memento'
main): dsh plugin --profile web add git+https://github.com/PerryLink/dsh-memento.git.dsh plugin --profile web add dsh-memento.npm pack in this repo, then dsh plugin --profile web add ./dsh-memento-<version>.tgz.dsh plugin --profile web remove dsh-memento (the memory database and session logs are kept).All tunables are Schemastery Config fields (changeable from cordis.yml). Invalid values fail loudly at load. Override under the memento row.
Settings panel. On the 0.1.7 line the plugin's own Config is its settings page: the form's namespace is the profile entry id (memento — the id: of this bundle's row), the editable fields are exactly the ones the plugin declares .volatile() (every key below except enabled), and an accepted edit is merged into the profile's plugin row and committed into the running plugin — no file editing, no restart. Nearly everything applies live (write policies, language, budgets, limits, proposals, panel, dbPath / auditRetentionDays via a store reopen, retrieval.vector via a retriever swap); what a plugin registers at load time (snapshotOrder, tool descriptions) is re-read on reload, and the page marks those fields. Numeric bounds are declared in the schema as well, so an out-of-range edit is refused at write time instead of leaving an unusable config behind. On the older lines (0.1.2-rc.1, 0.1.5-alpha.1, 0.1.6-0) the same card edits the dsh-memento settings namespace exactly as before; with no settings service at all, everything falls back to the composed cordis config. The floating panel button can be hidden from the same page (panel.enabled).
| Key | Default | Meaning |
|---|---|---|
enabled |
true |
Master switch; false removes the service, tools, snapshot, command, panel, and answerer (not editable from the settings page — a disabled plugin has no settings entry) |
panel.enabled |
true |
Show the web panel's floating button; saving false from the settings page hides the 🧠 entry immediately, no reload needed (the settings page itself stays reachable) |
dbPath |
'' → $DSH_HOME/dsh-memento/memory.db |
Absolute, or relative to $DSH_HOME (falls back to ~/.dsh on Windows) |
budgets.user.userGlobal |
2000 |
Hard character budget for the user track's user-global layer |
budgets.user.workspace |
2000 |
Hard character budget for the user track's workspace layer |
budgets.agent.userGlobal |
4000 |
Hard character budget for the agent track's user-global layer |
budgets.agent.workspace |
4000 |
Hard character budget for the agent track's workspace layer |
writePolicy |
'ask' |
Default write policy: ask / auto / off (model-invisible) |
writePolicies |
{} |
Per-track/scope or per-source overrides (e.g. user/workspace, source:claude) |
language |
'en' |
Model-visible and command output language: en / zh |
snapshotOrder |
-50 |
Snapshot section order (after harness identity, before persona) |
maxEntriesPerQuery |
20 |
Default per-query result cap (hard-capped at 1000) |
commandListLimit |
50 |
Entries rendered per /memory list / query |
commandAuditLimit |
10 |
Audit rows rendered per /memory audit |
recall.historyLimitDefault |
8 |
memory_recall sessions scanned by default |
recall.snippetCap |
5 |
memory_recall snippets per session |
recall.snippetChars |
300 |
memory_recall snippet characters |
recall.windowDays |
30 |
memory_recall recency window in days |
retrieval.vector |
false |
Semantic recall switch: true enab |