Introduction¶
DeepSeek Harness (DSH) uses a plugin-based architecture, and developers usually need to handle agent memory persistence and cost control themselves. The dsh-nexus plugin aims to provide a zero-configuration, cost-protective memory layer. By default, it requires zero tokens and zero external services, and manages memory through a three-layer structure of “atomic + gated + auditable,” rather than simple text appending.
Core Features¶
The plugin implements all interactions through a single panel, with core capabilities focused on cost control, auditing, and data cleanup.
Panel and Injection Status¶
The panel is packaged in lib/nexus.html and can be accessed from the “Memory” entry on the settings page or the standalone page /nexus.
The top area displays the current number of injected context entries, total bytes, and remaining budget. Expanding the details lets you see the specific reason each memory did not enter the context, including:
* A single entry exceeds the budget
* Evicted
* Unknown ownership
* Belongs to another project
* This session
* Inactive
Cost Control and Auditing¶
- Budget highlighting: When a single memory entry consumes more than 30% of the total budget, it will be highlighted in orange.
- Runtime status: The “Runtime Status” module on the settings page tracks today’s writes, pending confirmations, rejections, and injection counts in real time.
- Cost details: In the same module, token and byte counts are provided for injection, distillation, and encoding.
Data Management¶
- One-click cleanup: The plugin can automatically identify miswritten content such as sub-agent receipts and prompts (for example, 29/33 entries in one test were miswritten), and supports one-click archiving and blacklisting, with undo available within 5 seconds.
- Three-state deletion: Supports archive (traceable) → trash (recoverable) → hard delete (true deletion and edge cleanup). Note that the
/memory purgecommand only performs archiving; true deletion must be done from the trash area in the panel. - Custom interactions: The status, scope, and distillation model dropdowns in the panel are custom popups, avoiding styling issues with native
<select>elements in macOS light mode.
Installation and Enablement¶
Because it has not been published to npm yet, it can currently only be installed from a GitHub source or a local tarball.
- Install from GitHub (recommended):
dsh plugin --profile web add github:chenqiuyushuang/dsh-nexus
After installation, run `dsh web` to start the service.
- Install from a local tarball:
If offline installation is required, build and package it locally first:
npm run build && npm pack
When installing, point to the generated tarball file using the `file:` protocol, and make sure to bump the version to trigger an update.
- Verify installation:
After installation completes, it is recommended to run the verification script to ensure consistency between the code and the panel:
npm run verify:install
Typical Usage¶
During a session, command-line operations can be used together with the panel:
- Basic operations:
/memory list|search <q> # 列表或搜索
/memory show <id> # 查看详情
/memory edit <id> <新陈述> # 编辑
/memory delete <id...> # 删除(进入回收站)
- Review and conflict handling:
/memory confirm <id...> # 确认记忆
/memory reject <id...> [原因] # 拒收记忆
/memory conflict [keep-new|keep-old|keep-both <id...>|--all] # 处理冲突
- Session and maintenance:
/memory session [read-write|write-only|pause] # 修改会话模式
/memory cost # 查看成本
/memory doctor # 自检(检查库计数、待裁决冲突、注入占用等)
/memory import <file> # 导入记忆
/memory integrate [run] # 整合记忆
Security and Storage¶
Security Configuration¶
- Write restrictions: Write operations require an exact match between
Origin == Host(including the port). - Read restrictions: Read operations require
Hostto beloopback, preventing DNS rebinding attacks. - Remote access: If remote access is required,
webuiAllowRemote: truemust be explicitly enabled in the host configuration. - Security scanning: Built-in scanning is supported for API keys, ID numbers, and private keys.
Storage Structure¶
The plugin uses two types of storage, which should be distinguished carefully:
* Projection directory (default ~/.dsh/nexus): Stores human-readable MEMORY.md / USER.md; permissions are directory 0700, file 0600.
* Atomic store: Stored through the host’s storage-domain backend, with permissions determined by the host.
Notes¶
- Not published to npm: It currently cannot be installed directly via
npm install; you must use the GitHub source or a local tarball. - Value density gate (shadow period): The current memory scoring mechanism (value density gate) is in shadow mode, meaning it only records and does not block. It will switch to blocking mode only after accumulating real usage samples and verifying a false-block rate of 0.
- Version updates: When installing with
file:, if the package contents are unchanged, pnpm will not update it, so the version must be bumped. - Plugin restart: After installing a new version, the
dsh webprocess must be restarted for the changes to take effect.
Conclusion¶
dsh-nexus provides a structured memory management solution. Through budget control, an audit panel, and a three-state deletion mechanism, it addresses cost and traceability challenges in agent memory management. For DSH users who need fine-grained control over context costs, this is a plugin worth deploying.
- Project address: https://github.com/chenqiuyushuang/dsh-nexus
- License: MIT