DeepSeek Harness (DSH) is currently in developer preview. Its “everything is a plugin” architecture allows developers to flexibly extend features. In practice, Agents need to retain context to complete multi-turn tasks, but traditional logging can leak sensitive information such as passwords or raw tool-invocation parameters. dsh-focal is a plugin designed to resolve this conflict: it provides task-isolated local memory, injects only the active task’s context into model requests, and ensures that all stored data is privacy-filtered.
Plugin Positioning¶
This is a privacy-first task memory and adaptive local desktop observation plugin, maintained by Haoran2099. It is implemented based on the FOCAL paper, filtering Agent sessions into task-isolated memory and providing limited context snapshots only when needed.
Core Features¶
dsh-focal filters and organizes session records locally. It mainly includes the following capabilities:
- Session Observation and Filtering: The plugin observes committed session/event records. It uses a small, deterministic similarity filter to route direct user messages into task-isolated memory.
- Selective Logging: It records only tool names, success/failure status, and path parameters, and never records assistant token streams, raw tool parameters, or raw tool result content.
- Privacy Protection: Stored text is de-identified, and common credentials and email addresses are redacted. Absolute paths are processed (only the file name is retained, and workspace absolute paths are not written), and non-absolute paths are also reduced to basenames.
- Context Injection: When
injectContextis enabled, the plugin provides a runtime context snapshot and an anti-injection policy section for an active task, and appends it to the next model request. - Data Storage: Each session stores a bounded JSON document under
$DSH_HOME/focal-dsh/v1. - Commands and Tools:
- Human commands:
/focal status,/focal tasks,/focal forget task-1,/focal forget all. - Model tools:
focal_status,focal_recall.
- Human commands:
Installation and Enablement¶
Before installing, ensure that DeepSeek Harness v0.1.0-rc.6 is installed and that the environment meets the Node.js version requirement (^22.19.0 || >=24.0.0).
Use the official command to add the plugin:
dsh plugin --profile web add github:Haoran2099/focal-dsh#v0.1.1
dsh --profile web --dump-config
dsh --profile web
If you need to use it in headless CLI runs, use --profile headless.
After installation, you can adjust behavior by overriding the cordis.patch.yml entry in the plugin configuration file. This configuration supports the following items:
- id: focal-memory
config:
captureUserText: false
captureToolPaths: true
injectContext: true
maxTasks: 32
maxObservationsPerTask: 40
maxContextObservations: 8
maxContextChars: 4000
captureUserText: false: Replaces the stored request text with a generic marker.injectContext: false: Keeps collection and explicit recall available, but no longer adds it automatically to model requests.
Typical Usage¶
After installing and running DSH, you can interact with the memory system using the following commands:
- View current status:
/focal status - List all task memories:
/focal tasks - Remove a specific task memory:
/focal forget task-1 - Clear all task memories:
/focal forget all
The model can read memory by calling the read-only tools focal_status and focal_recall, but deletion operations must be performed through human commands.
Use Cases and Notes¶
This plugin is suitable for developers who need persistent task memory in DeepSeek Harness and have strict data privacy requirements.
Notes:
1. Untrusted Data: Memory data is explicitly marked as untrusted data and should not be treated as instructions.
2. Defense in Depth: Filtering is a defense-in-depth measure and does not guarantee identification of all sensitive values. Do not place credentials in prompts or tool parameters.
3. Local Execution: The plugin makes no network requests, has no telemetry, and all storage is local.
4. Compatibility: DeepSeek Harness is currently in developer preview and may include breaking changes. This plugin currently supports only Host mode and has no Web UI extension.
Brief Conclusion¶
dsh-focal provides controllable memory capabilities for DeepSeek Harness by privacy-filtering and task-isolating Agent sessions locally. It does not record sensitive raw data and only injects necessary context into the model, making it suitable for developers who prioritize data security.