Files
t0saki b7d0415c24 feat(plugins): skill catalog and openviking-skills for the memory plugins (#5161)
* refactor(skills): install skills through one shared helper

POST /api/v1/skills kept its whole install loop (source resolution, per-skill
install, source metadata, list_only) inline in the route. Move it into
openviking/server/skill_ingest.py:install_skills so the MCP add_skill tool
and signed skill uploads can reuse the exact same code path. The REST
route's behavior is unchanged.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* feat(mcp): add an add_skill tool

MCP clients had no way to create a skill: write refuses the skills/
subtree (_USER_MANAGED_SUBTREES) and add_resource validates its target as
a resource. Agents that should keep skills in OpenViking could read them
but never add one.

add_skill takes either the full SKILL.md text (data) or a path. A Git or
GitHub tree URL installs through the same source resolution as REST, with
skills=[...] to pick from a multi-skill repository and list_only to
preview it. A local SKILL.md, directory, or zip gets the add_resource
treatment: the tool mints a one-time upload token, now tagged kind="skill"
with the target root, selection and list_only, and the signed temp_upload
installs the file as skills instead of ingesting it as a resource.
target_uri="viking://agent/skills" shares the skill with the account.

All three paths (REST, MCP inline/Git, signed upload) go through
skill_ingest.install_skills. The tool count in the server log, app
comment, docs, and the Codex plugin's REAL_MCP_TOOLS moves to 16.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* fix(mcp): search shared skills in find(context_type="skill")

Without a target_uri, find resolved the generic default targets, which
stop at the caller's user root, so a skill search never reached the
account-shared viking://agent/skills. REST /skills/find and the context
search already cover both roots. When context_type resolves to skill only
and no target_uri is given, the MCP tool now targets
default_target_directories(ctx, context_type=SKILL): the user's own skills
plus viking://agent/skills. REST find semantics are unchanged.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* fix(mcp): print directory abstracts in tree(include_abstract=true)

The tree tool skipped to the next entry right after printing a directory,
and only printed abstracts for files, but the storage layer only fills
abstracts for directories (files always come back empty). The flag
therefore never printed anything. Print the abstract after either kind
of entry and ask for up to 1024 characters, enough for a full skill
description, so tree(uri="viking://~/skills", level_limit=1,
include_abstract=true) lists every skill with its description.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* fix(skills): honor node_limit in GET /api/v1/skills

list_skills declared node_limit but always listed each skill root with a
hardcoded 1000. Pass it through per root; 0 keeps the default so the CLI's
accepted range (-n 0) still lists everything.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* fix(mcp): point skill hits in find/search at their SKILL.md

A skill is indexed through its directory's .abstract.md, so find and
list-mode search printed hits like viking://agent/skills/x/.abstract.md.
Following the "use the read tool to expand a URI" advice returned only
the frontmatter, and read_content inlined the same stub. Skill hits now
show <dir>/SKILL.md, and read_content reads that file.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* fix(mcp): validate add_skill targets and sources before minting an upload

Review findings on the add_skill tool:

- target_uri passed the content-kind check for any path under a skills
  root (viking://~/skills/pdf) and, for ROOT, for another user's root,
  but the installer only accepts the caller's own skills root or
  viking://agent/skills. On the local-path branch the tool minted a
  one-time upload token anyway, and the upload failed with 400 after the
  token was spent. The target is now resolved with the installer's own
  rule first; shared subpaths map to viking://agent/skills, the rest fail
  at once, and the error names both allowed roots.
- Non-Git remote sources such as tos:// were treated as remote, then
  refused as "direct host filesystem paths". add_skill now decides Git
  with the same prefixes resolve_skill_source uses (shared as
  GIT_SKILL_SOURCE_PREFIXES) and reports other schemes as unsupported.
- With list_only, the upload instructions still said the skill would be
  installed and that no further call was needed; they now say the upload
  only lists the source's skills.
- The zip example packaged hidden files, so .git and .env files went
  into the stored skill. It now excludes VCS data, .env files,
  node_modules and .DS_Store, starting from a fresh archive.
- tree(include_abstract=true) printed the "abstract is not ready"
  placeholder for directories that never get an abstract, such as a
  skill's scripts/. Those placeholders are skipped.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* docs(mcp): say that write only refuses the user's own skills subtree

The capability reference claimed MCP write refuses every skill URI. It
refuses the user's own skills/ subtree, but under viking://agent/skills
it writes a plain file that skips skill installation. State that, and
point shared skills at add_skill as well.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* style(skills): format skill_processor.py

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* feat(plugins): inject an <available-skills> catalog at session start

Agents on every harness learned about memories at session start but had
no idea which skills OpenViking held, so a stored skill was only found if
a later recall happened to surface it.

buildProfileBlock() now takes the caller's resolved config as a fourth
argument and, when skillCatalog is on (default), adds <available-skills>
after <available-memories>: one GET /api/v1/skills lists the user's own
skills first, then account-shared ones, dropping a shared skill the user
shadows by name. Descriptions are cut to about 40 tokens and envelope
tags in them are escaped, since the shared root is written by anyone on
the account. The block has its own budget (skillCatalogTokenBudget,
default 1200) and degrades from descriptions to names to a one-line
count; with no skills, or a server without the endpoint, it is omitted.

The shared formatListing now gives entries back so its "+N more" tail
fits: a greedily filled listing never left room for it, so a cut listing
ended silently. This also applies to <available-memories>.

All six callers (claude-code, codex, opencode, dsh, pi, and the thin hook
runtime for cursor/trae/zcode) pass their config through.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* feat(plugins): recall account-shared skills and flag skill entries

The server context face already mixes both skill roots into per-prompt
recall, but the plugins' last-resort ranked find only searched
viking://~/memories and viking://~/skills, so on servers without the
context face a shared skill in viking://agent/skills could never be
recalled. Add it as a third source, and name each skill hit by its
directory rather than the .abstract.md it was indexed through, matching
the context face and the session-start catalog.

When an injected recall block carries a skill (a type="skills" entry, or
a [skill] line from the fallback), its header gains one line telling the
agent to read the skill's SKILL.md before following it. Turns without a
skill are unchanged.

The openclaw plugin's vendored recall-core copy is regenerated with it.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* feat(plugins): point skill writes at add_skill in the URI guard

A local Write or Edit aimed at viking://.../skills/... was denied with a
hint to use MCP write or edit instead, but the server refuses both under
the skills subtree, so the hint led straight into a second error. Hints
may now depend on the URI: for a skill URI (viking://~/skills,
viking://user/<id>/skills, viking://agent/skills) the default table and
dsh's bridged table name add_skill with an add_skill(data="<the full
SKILL.md text>") example. Other URIs keep their hints.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* feat(plugins): bundle an openviking-skills skill

Nothing told an agent how to work with skills stored in OpenViking: how
to load one from the catalog, run its helper files, create one through
add_skill, install from Git or a local folder, share it with the account,
or move the user's existing local skills over.

examples/skills/openviking-skills covers all of that, including a
user-triggered, one-time migration of ~/.claude/skills, ~/.agents/skills
and ~/.cursor/skills that keeps environment-bound skills local (shipped
by a plugin or marketplace, symlinked in by a CLI installer such as
lark-cli, or needing a local binary) and uploads only what the user
approves skill by skill. It passes strict server validation.

sync.mjs ships it wherever add_skill is a real tool and a bundled skill
loads: the codex, claude-code, cursor and dsh plugins. openviking-memory
now points to it for skill work. A new sync test keeps synced skills
flat, since copySkill copies a flat file list and a subdirectory would
crash it; the marketplace tests pin the packaged copies, and dsh's
provider test expects both bundled skills.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* chore(plugins): bump versions for the skill integration

claude-code 0.6.0, codex 0.10.0, agent-hook (cursor/trae/zcode) 0.4.0 and
dsh 0.5.0 gain the skill catalog and, except trae/zcode, the bundled
openviking-skills skill; opencode 0.3.3 and pi 0.3.3 gain the catalog.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* feat(codex): recall shared skills and flag skill entries in Codex too

Codex builds its recall block itself instead of through recall-core's
wrappers, so the previous commit's changes never reached it: its raw
search still skipped viking://agent/skills, its digest carried no skill
hint, and its post-processing kept only level-2 leaves, which silently
dropped every skill hit (skills are found through their directory's
level-0 abstract), including the viking://~/skills search it already ran.

recall-core now exports skillEntryHint() and skillHitUri(). The hint is
added when a block carries a type="skills" entry or cites any skill URI,
which also covers digests that only keep URIs. Codex searches the shared
skill root as a third bucket, labels skill hits "skills" under their
directory URI, lets them through post-processing, and adds the same hint
line to its envelope.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* fix(cursor): install openviking-skills next to openviking-memory

sync.mjs puts openviking-skills into hosts/cursor/skills, but the
installer copied only openviking-memory into ~/.cursor/skills, so Cursor
never saw the new skill. Install, uninstall, the post-install check and
the doctor's file list now cover both skills. The install test also moves
to the agent-hook plugin's new 0.4.0 version string.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* fix(dsh): keep PLUGIN_VERSION in step with package.json

The version bump moved package.json to 0.5.0 but left the PLUGIN_VERSION
constant at 0.4.3, which bundle.test.mjs and npm run check:version
compare against the manifest.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* docs(skills): match ov-skills commands to the real ov CLI flags

The ov-skills skill documented flags the CLI never had (--json, and a
--limit that is only a hidden alias), a raw-content "ov skills add -"
form that sends a literal "-", and ov resources subcommands that do not
exist. Every command line now follows the clap definitions: -o json for
JSON, -n/--node-limit, -p/--uri on read commands and
-p/--parent-auto-create on add, -s/--skill as a comma list, show
--format, and validate's --strict-only body-length warning. ov add-skill
is documented as the same command as ov skills add.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* docs(plugins): document the skill catalog, openviking-skills, and skill-aware recall

The integration pages (Claude Code, Codex, Cursor, TRAE, opencode, pi,
dsh), the capability reference, the plugin development guide, and the
plugin READMEs now describe the <available-skills> session-start block,
its skillCatalog / skillCatalogTokenBudget knobs, the bundled
openviking-skills skill where it ships, recall reaching
viking://agent/skills with the skill-entry hint, and the URI guard
sending skill writes to add_skill. en and zh pages carry the same facts.

Stale statements fixed on the lines touched: thin hook hosts use the
same 10000-token profile budget as the rest, the claude-code and codex
plugins ship four skills, dsh mounts the server MCP surface, and the
opencode install guide lists openviking_add_skill once.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* fix(plugins): let the user's own skills use the catalog budget the shared group leaves

Review findings on <available-skills>:

- Each group got at most its even share of the listing budget, with
  unused tokens passing only forward, so the user's own skills (always
  first) never got more than half. Twenty own skills and one shared skill
  fell back to names only while most of the 1200 tokens went unused. A
  group now takes its even share or everything the later groups leave
  when listed in full, whichever is larger.
- When a group's share could not hold its header plus the "+N more"
  tail, formatListing gave back every entry and printed a bare header,
  which reads as an empty directory. It now prints the one-line
  "N entries, budget too tight" stub instead (memory listings too).
- A budget too small for even the one-line count now injects nothing
  rather than overrunning it.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* fix(plugins): rank skill hits like memory leaves in the recall fallbacks

Naming a skill hit by its directory instead of its .abstract.md cost it
the 0.12 leaf boost, since the boost keyed on a ".md" URI, so a skill
that main would recall lost to ten slightly weaker memory leaves. In
Codex, skills were also never picked while enough memory leaves passed
the threshold (leaves are picked first), and a hit the server labeled
with another category lost its "skills" label. Skill hits now count as
leaves in ranking and picking in both recall-core and Codex, and Codex
always labels them "skills".

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* fix(plugins): send shared-skill edits back to the shared root in the URI guard

The guard's add_skill example carried no target_uri, and add_skill
without one installs into the caller's own root. Fixing a shared skill
that way left the team copy unchanged and created a private copy that
the catalog then shows instead. For viking://agent/skills URIs the
example now passes target_uri="viking://agent/skills", and a helper file
(anything below a skill's SKILL.md) points to a folder upload through
add_skill(path=...) rather than SKILL.md text. addSkillExample() builds
the example for both the default table and dsh's.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* docs(skills): tighten openviking-skills where review found unsafe steps

- The catalog is a snapshot that drops descriptions or entries with many
  skills, so a name missing from it does not prove the name is free.
  Check <root>/<name>/SKILL.md, and confirm with the user before
  replacing an existing skill, since add_skill replaces silently.
- Updating a shared skill must pass target_uri="viking://agent/skills"
  after the user confirms; otherwise add_skill creates a private copy
  that shadows it.
- Every file in an uploaded folder is stored with the skill: zip without
  .git, .env files, node_modules and .DS_Store, and delete the archive
  afterwards. The migration now inspects the whole folder, hidden files
  included, for secrets.
- Migration flags frontmatter keys OpenViking drops (for example
  disable-model-invocation or context), and fixes a missing name or
  description in a temporary copy, never in the user's file.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* feat(plugins): keep the session-start block under the host's inline limit

Claude Code saves hook context over 10,000 characters to a file and
shows the model a 2 KB preview; Codex and trae-cli spill past about
10,000 bytes; ZCode drops stdout over 32 KB. The session-start block
(profile at a 10,000-token budget, memory index, skill catalog, and the
archive on resume) routinely ran 25-40 KB, so on these hosts the model
saw only the start of the profile, and the catalog appended at the end
never reached it.

sessionStartMaxBytes caps the whole block in UTF-8 bytes: 9500 for
claude-code and codex, 20000 for zcode, no cap elsewhere. Under the cap
buildProfileBlock shrinks its token budgets (about 4 bytes per estimated
token); if the block still does not fit it drops the memory index, then
the catalog. On resume/compact the archive takes up to half, truncated
on a line with a pointer to viking://~/sessions/<id>/history/.

On resume, claude-code and codex skip the profile block when it matches
the one this session already received, since the restored history holds
it; a changed block is injected again.

Claude-Session: https://claude.ai/code/session_01ECVkFufAU2LKe4g83cxt28

* fix(mcp): return one hit per skill package in find

#5045 made a skill index as a whole package, so an item-level find now
returns one hit per file inside it. Route skill-only find through
SearchService.find_skills, which keeps the best hit per package, and
resolve every skill hit to its package's SKILL.md instead of only
rewriting the two index sidecars.

Claude-Session: https://claude.ai/code/session_01CrZadR75kCueyZyoiGUFBW

* docs(mcp): point skill changes at add_skill in the tool descriptions

The server keeps accepting write/edit under viking://agent/skills, and
forget still removes a skill directory, so the constraint lives in the
tool descriptions: add_skill is the one entry point for creating and
updating a skill, and removal goes through ov skills remove or Studio.

Claude-Session: https://claude.ai/code/session_01CrZadR75kCueyZyoiGUFBW

* fix(mcp): describe a skill hit by its own abstract

A package hit can be any file inside the skill, whose abstract describes
that file and not the skill, so find would list a skill under a helper
script's summary. Read the package's abstract for those hits, the way
GET /skills/find already does. Keep a filter-only skill query on the
generic find, which find_skills does not serve.

Claude-Session: https://claude.ai/code/session_01CrZadR75kCueyZyoiGUFBW

* docs(mcp): document package-level skill retrieval in find

Claude-Session: https://claude.ai/code/session_01CrZadR75kCueyZyoiGUFBW

* feat(agent-plugins): ship the openviking-skills skill

Agent Plugins has no hooks, so no session-start catalog: without this skill
the model never learns that the account's skills exist. The skill's own text
now reaches for find(context_type="skill") first and treats
<available-skills> as something only some harnesses inject, so one copy
reads correctly in both kinds of harness.

Claude-Session: https://claude.ai/code/session_01CrZadR75kCueyZyoiGUFBW

* fix(plugins): name the skill package a recall hit came from

Since a skill is indexed as a whole package, a hit can be any file inside
it, not just the two index sidecars the old rewrite stripped. Derive the
package root the way the server's skill_root_uri does, drop the internal
update backups, and keep one entry per package at its best score.

Claude-Session: https://claude.ai/code/session_01CrZadR75kCueyZyoiGUFBW

* fix(plugins): let the skill catalog use both roots' full listings

The server already caps each skill root at node_limit, so a second cap over
the merged list only bites once the private root alone fills it — and then
it drops the shared root whole while reporting nothing dropped. The token
budget is what should decide, and it already does.

Claude-Session: https://claude.ai/code/session_01CrZadR75kCueyZyoiGUFBW

* docs(plugins): say node_limit caps each skill root, not the merged list

Claude-Session: https://claude.ai/code/session_01CrZadR75kCueyZyoiGUFBW

* fix(mcp): do not paste an unready abstract over a skill hit's own summary

fs.abstract returns a placeholder string rather than raising when a package
has no usable .abstract.md, so the substitution replaced a useful file
summary with a diagnostic line. Reject the same placeholders tree already
rejects, and bound the per-package reads the way read_content is bounded.

Claude-Session: https://claude.ai/code/session_01CrZadR75kCueyZyoiGUFBW

* docs(mcp): correct how search reports skill hits, and refresh the tool table

find and search both render one line per skill package, so the earlier
wording — that search returns several hits per package — contradicted the
code. Say what actually differs: search still spends a limit slot per
matching file and keeps that file's summary. Also point forget and
add_resource at add_skill where an agent would look for them, name the REST
delete alongside the CLI, and bring the capability table's line citations
back in step with mcp_endpoint.py.

Claude-Session: https://claude.ai/code/session_01CrZadR75kCueyZyoiGUFBW

* docs(agent-plugins): list add_skill among the tools the package exposes

Claude-Session: https://claude.ai/code/session_01CrZadR75kCueyZyoiGUFBW

* refactor(mcp): drop guards and prose no caller can reach

install_skills only ever returns a dict, add_skill always fills root_uri,
and a source with no SKILL.md raises before it gets here, so the
isinstance, empty-list and missing-uri branches were unreachable.
fs.abstract only returns the directory placeholder. One skill package
resolves to one rendered item, so the pending map holds one each. In the
docstrings, drop what Args already says and the one removal path an MCP
caller cannot take.

Claude-Session: https://claude.ai/code/session_01CrZadR75kCueyZyoiGUFBW

* docs(plugins): drop a comment about a branch formatListing cannot take

A listing left with only its header returns the stub above, so it never
reaches the silent close the comment described. Also name
sessionStartMaxBytes in buildProfileBlock's options type, where the .d.mts
already has it.

Claude-Session: https://claude.ai/code/session_01CrZadR75kCueyZyoiGUFBW

* revert(plugins): drop the skill changes in the recall fallback

Reverts the recall half of the skill integration: 992215bfb, 553416200,
5e838a0a0 and 62a456c08. The seven files they touched go back to their
state at aa77061c1, the merge base with main.

Those four commits taught the local recall assembly about skills: a third
source for viking://agent/skills, skillHitUri naming a hit's package,
dedupeSkillHits keeping one entry per package, rankItem scoring a skill
like a memory leaf, and a header line telling the model to read SKILL.md.
Four of the five only ever ran in the raw-find fallback. recallForPeer
calls buildServerAssembledBlock first and returns as soon as it answers,
so searchAllSources, rankItem and the fallback block builder are reached
only on a deployment whose server has no context face. The fifth, the
header line in wrapContext, did run on the main path, but the server
already reports each entry's type and the URI it wants read, so the line
restates what the block carries.

Skills still reach the model on the path that runs: the context face
searches both skill roots, returns them as entries with type="skills",
and the session-start <available-skills> catalog lists every skill with
its description. Both stay.

The documentation that described the fallback behaviour goes with it. The
statements that survive are the ones the context face makes true on its
own, such as recall covering the skills shared with the account.

Claude-Session: https://claude.ai/code/session_01CrZadR75kCueyZyoiGUFBW

* chore(plugins): bump opencode and pi past main's releases

Both were 0.3.3 on this branch and main has since shipped 0.3.3 of its
own, so the version a host installs by no longer moves for the skill
catalog they now carry through the shared library.

Claude-Session: https://claude.ai/code/session_01CrZadR75kCueyZyoiGUFBW

* docs(mcp): say what list-mode search actually reports for a skill hit

The search row claimed a skill package's summary is the matching file's.
It is not: _format_search_result rewrites every skill hit onto the
package's SKILL.md, keeps the best-scored one per package, and
_describe_skills_by_package replaces the summary with the package's own
abstract. What is true is that limit applies during retrieval, before
that merge, so a package matching several files still spends several
slots and fewer than limit results come back.

Claude-Session: https://claude.ai/code/session_01CrZadR75kCueyZyoiGUFBW
2026-09-22 15:09:44 +08:00

15 KiB
Raw Permalink Blame History

Codex 记忆插件

本插件旨在为 Codex 提供持久化的跨会话(session)记忆功能。只需安装一次,即可实现:在会话开始时加载 OpenViking profile、记忆索引和 skill 清单,在每次用户输入前自动召回相关记忆,在每轮对话结束后进行增量捕获,并在上下文压缩(compaction)前将完整记录提交给记忆抽取器。同时,该插件将 Codex 连接至 OpenViking 的 /mcp 端点,使模型能够直接调用 find、search、read、remember 等工具来主动管理记忆。

源码:examples/codex-memory-plugin | 博客:动机与效果展示

安装

Claude Code 和 Codex 共用同一个安装脚本。它会依次询问界面语言(English/中文)、要安装的 harness、下载源和 OpenViking 凭据;所有步骤幂等,可安全地重复执行。

bash <(curl -fsSL https://raw.githubusercontent.com/volcengine/OpenViking/main/examples/memory-plugin-shared/install.sh)

TraeCode CLI 2.0 可以直接安装这一 Codex 格式插件,默认安装入口是 --harness trae-cli:

bash <(curl -fsSL https://raw.githubusercontent.com/volcengine/OpenViking/main/examples/memory-plugin-shared/install.sh) \
  --harness trae-cli

GitHub 访问受限的地区,从火山引擎 TOS 镜像运行同一个安装脚本(或在下载源提问时选择「TOS 镜像」)。Codex 走 TOS 时安装自 TOS 托管的 git 仓库,保留远程更新能力:

bash <(curl -fsSL https://ovrelease.tos-cn-beijing.volces.com/memory-plugin-shared/install.sh)

现在不再需要任何 shell wrapper——插件自带的 stdio MCP 代理会在运行时读取 ~/.openviking/ovcli.conf(或 OPENVIKING_* 环境变量),与 hooks 使用同一套配置链。安装完成后启动 Codex(TraeCode CLI 2.0 是 trae-cli):

codex

首次启动:信任 hooks

插件的 hooks 对 Codex 是新的,启动时会先停在一次信任确认上,选 Trust all and continue;想先看一眼 hook 命令就选 Review hooks:

Hooks need review
6 hooks are new or changed.
Hooks can run outside the sandbox after you trust them.

  1. Review hooks
> 2. Trust all and continue
  3. Continue without trusting (hooks won't run)

全新安装会一次列出插件注册的全部 6 个 hook。之后每次插件更新只要动了 hook,Codex 都会再拦一次,数字是这次新增或改动的条数(比如只改了一个就是 1 hook is new or changed),同样选 Trust all and continue。

选第 3 项或错过这一步,hooks 就不会运行:MCP 工具仍能调用,但自动召回和捕获全部停摆。要恢复,得让两个彼此独立的开关都处于开启状态:

  • /hooks — hook 的信任与开关,把标着 New hook - review required 或 Modified since last trusted 的条目信任并打开。
  • /plugins — 插件本身的启用状态,确认 openviking-memory 是 enabled。

任何一边是关着的,自动召回和捕获都不会发生。

手动安装

前置条件:需安装 Node.js >= 22、Codex >= 0.130.0,并启用 plugin_hooks 特性。

  1. 配置连接 — 手写 ~/.openviking/ovcli.conf(url、api_key,可选 account/user),或装完后运行插件自带向导 node <插件目录>/scripts/setup.mjs。

  2. 从远程 marketplace 安装插件:

    codex plugin marketplace add volcengine/OpenViking
    codex plugin add openviking-memory@openviking
    

    若你的 Codex 版本未默认启用 plugin hooks,在 ~/.codex/config.toml 中加上 [features] → plugin_hooks = true。之后可用 codex plugin marketplace upgrade openviking 更新。

验证

启动 codex 后,当前会话首次提交 prompt 时触发的 SessionStart 会加载 profile,之后插件将在每次用户输入前自动召回相关记忆。若设置环境变量 OPENVIKING_DEBUG=1,则会将相关事件日志写入 ~/.openviking/logs/codex-hooks.log。 TraeCode CLI 2.0 用户启动 trae-cli,并可用 trae-cli plugin list 确认插件已启用。

工作原理

本插件深度挂载于 Codex 的生命周期之中:在 SessionStart(startup、clear 或 resume)阶段,它会复用其他 coding-agent 集成共用的 CJK-aware profile 构建逻辑,注入 profile.md、preferences/ 与 entities/ 的 URI 和摘要索引,以及列出你的 OpenViking skill 的 <available-skills> 清单;在每次用户输入前,它会搜索 OpenViking 并注入相关的记忆(触发 UserPromptSubmit);在每轮对话结束后,会将新的对话追加至当前会话(触发 Stop);在上下文压缩前,补齐并提交(commit)完整的对话记录(触发 PreCompact);在线程正常退出时提交整段会话(触发 SessionEnd),以确保记忆抽取器能够在完整的上下文环境中运行。shell 命令执行前(Bash 上的 PreToolUse),插件会检查命令里是否带 viking:// URI:命令照常执行,模型会收到一条提示,建议改用 OpenViking MCP 工具;如果该 URI 是有意传入的数据(例如 ov 命令参数),模型可以忽略这条提示。此外,在启动新会话时,插件还会清扫前次运行遗留的孤儿会话(orphan session)。恢复已有会话时,固定 profile 背景还会与最新的 archive digest 合并注入。

已知局限:SessionEnd 需要 Codex 0.145 及以上版本,且只在正常退出时触发(/quit、/exit、连按两次 Ctrl-C、EOF、codex exec 运行结束)。SIGTERM、直接关闭终端、kill -9 或崩溃都不会触发;当 TUI 挂在 codex app-server 守护进程上时,该事件会被延后。这些会话——以及 Codex 低于 0.145 的所有会话(以及没有该事件的 TraeCode CLI 版本)——由下一次 SessionStart 的闲置 TTL(生存时间,默认为 30 分钟)清扫回收。

<available-skills> 清单先列你自己的 skill,再列 viking://agent/skills 下共享给整个账号的 skill;共享 skill 与你自己的某个 skill 同名时不再列出。清单有独立的 token 预算,不占 profile 预算:放不下描述时只列名称,连一个名称都放不下时缩成一行总数。清单第一行提示模型:按某个 skill 操作前,先用 OpenViking read 工具读取它的 SKILL.md。插件在 openviking-memory、ov-experience-memory 之外还自带 openviking-skills skill,告诉模型如何查找 skill、用 MCP add_skill 工具新建或替换 skill、从 Git 或本地文件夹安装 skill、把 skill 共享给整个账号,以及在你要求时把本地 skill 迁移到 OpenViking。

工具调用和结果会作为独立的 tool part 捕获,tool_output 原样上报。截断由服务端负责:超过 tool_output_externalization.threshold_chars(默认 20000)的输出会写入 session 的 tool-result 存储,part 中只保留 synopsis stub 和 tool_output_ref,原文仍可通过 /api/v1/sessions/{id}/tool-results 读回。

配置

凭据来源:默认环境变量优先——只要设置了任一 OPENVIKING_* 凭据环境变量(OPENVIKING_URL/OPENVIKING_BASE_URL、OPENVIKING_BEARER_TOKEN/OPENVIKING_API_KEY、OPENVIKING_ACCOUNT、OPENVIKING_USER、OPENVIKING_PEER_ID),其取值就会覆盖当前激活的 ovcli.conf。只有在这些环境变量都未设置时,才由激活的 ovcli.conf(OPENVIKING_CLI_CONFIG_FILE 或 ~/.openviking/ovcli.conf)统一驱动 hook、MCP 代理和 Codex 内部运行的 ov 命令,此时 ov config switch <name> 会在下次启动时生效。若希望在设置了凭据环境变量的情况下仍强制使用 ovcli 配置,可设置 OPENVIKING_CREDENTIAL_SOURCE=cli。两者都未覆盖的字段依次回退到 ovcli.conf、ov.conf 和内置默认值。

环境变量 默认值 说明
OPENVIKING_URL / OPENVIKING_BASE_URL — 完整的服务器 URL
OPENVIKING_API_KEY — API 密钥(将通过 Authorization: Bearer 标头发送)
OPENVIKING_CLI_CONFIG_FILE ~/.openviking/ovcli.conf hook、MCP 和 Codex 内部 ov 命令共同使用的当前 CLI 配置
OPENVIKING_CREDENTIAL_SOURCE auto auto 下已设置的凭据环境变量优先;设为 cli 强制使用激活的 ovcli 配置;设为 env 只读环境变量,两个配置文件都不读
OPENVIKING_NO_AUTO_INJECT false 关闭会话启动阶段的固定 profile/背景注入(包括 skill 清单),但不关闭逐 prompt 语义召回
OPENVIKING_PROFILE_TOKEN_BUDGET 10000 profile.md 及 preferences/、entities/ 索引共用的 CJK-aware token 预算
OPENVIKING_SKILL_CATALOG true 在会话启动注入中加入 <available-skills> 清单;设为 false 则不加
OPENVIKING_SKILL_CATALOG_TOKEN_BUDGET 1200 <available-skills> 清单的 CJK-aware token 预算,独立于 OPENVIKING_PROFILE_TOKEN_BUDGET;设为 0 同样不加清单
OPENVIKING_SESSION_START_MAX_BYTES 9500 SessionStart 注入的总字节上限,保证低于 Codex 默认的 hook 输出上限(约 10,000 字节),模型拿到的是全文而不是截断预览;resume 时会话归档最多占一半。设为 0 取消上限
OPENVIKING_CODEX_IDLE_TTL_MS 1800000 SessionStart 闲置 TTL 清理阈值(毫秒)
OPENVIKING_CODEX_LOCK_WAIT_MS 120000(SessionEnd)、40000(PreCompact) 捕获类 hook 等待单会话状态锁的时长(毫秒)
OPENVIKING_CODEX_COMMITTED_TTL_MS 2592000000 已提交会话的转录游标保留时长(毫秒),过期后删除状态文件
OPENVIKING_RECALL_QUERY_FILTERS "" CSV 格式的 sed 风格正则规则,在 prompt 变成检索 query 前生效(语法与示例)
OPENVIKING_CAPTURE_FILTERS "" CSV 格式的 sed 风格正则规则,作用于每个被捕获的回合(同一套语法)
OPENVIKING_DEBUG false 是否将日志写入 ~/.openviking/logs/codex-hooks.log

这些旋钮大多也可以写在 ovcli.conf 的 plugin 段下——见插件配置。两个过滤器 knob 尤其建议写在那里,用 JSON 数组,因为环境变量形式会按逗号切分。

如果更看重召回响应速度,请参阅低延迟召回,其中说明了如何通过环境变量或 ovcli.conf 关闭查询扩展与 Codex 本地结果压缩。

更多调参说明(如 OPENVIKING_RECALL_LIMIT、OPENVIKING_CAPTURE_ASSISTANT_TURNS 等),请参考 插件 README。

工作区 peer

记忆按你所在仓库派生出的 peer 归档,因此同一个项目在不同 clone、worktree 和子目录下共用同一份记忆。默认的 peer.source: "git" 取仓库归一化后的 origin URL——origin 为 git@github.com:volcengine/OpenViking.git 时,peer 就是 github.com-volcengine-openviking——其次是仓库根路径;不在仓库中则完全不发送 peer,在那里记下的内容进入用户级空间 viking://user/<you>/memories。fork 的 origin 不同,因此默认是独立的 peer。

可通过 OPENVIKING_PEER_SOURCE、ovcli.conf 中的 plugin.peerSource,或工作区 .openviking/config.json("version": 1 的配置文件,可提交给团队共用)中的 peer.source 修改:"cwd" 恢复此前的行为——把工作目录路径中的非字母数字字符全部替换成 -;"none" 表示不发送 peer;也可以用 "team-{dir}" 这样的模板自定义。要让一个不是仓库的目录拥有独立记忆,在该目录下创建 .openviking/config.json,内容为 {"version": 1, "peer": {"id": "my-project"}}。此前按工作目录派生的 peer 下写入的记忆仍能被召回,无需迁移。分层优先级和工作区配置文件的完整 schema 见客户端配置 → 工作区配置。

故障排查

现象 可能原因 修复方法
MCP 工具调用报认证错误 当前 ovcli 配置没有 authenticated server 所需的有效 api_key 修正 ~/.openviking/ovcli.conf(或运行 node <插件目录>/scripts/setup.mjs)后重启 Codex;stdio 代理会在启动时和认证失败后重新读取配置
MCP 工具调用报连接错误 服务器不可达或 URL 配置错误 执行 curl "$(jq -r '.url' ~/.openviking/ovcli.conf)/health" 检查服务器状态
6 hooks need review,或插件已装但 hook 不生效 全新安装要信任全部 6 个 hook,之后每次插件更新改动到 hook 时还会再问一次;当时选了 Continue without trusting 或直接跳过,hooks 就一直不会运行 /hooks 里信任并开启相关条目,/plugins 里确认 openviking-memory 已启用——两个开关相互独立,都要是开着的
ov config switch 后插件仍指向旧服务器 上个会话的代理进程仍在运行 重启 Codex;代理在启动时解析凭据
Hook 与 MCP 指向不同服务器 某一侧残留了过期的 OPENVIKING_* 凭据环境变量(默认环境变量优先于 ovcli.conf) 清除过期环境变量(让 ovcli.conf 同时驱动两者)、设置 OPENVIKING_CREDENTIAL_SOURCE=cli,或保证环境变量一致

参见

召回压缩

设置 OPENVIKING_RECALL_COMPRESS=server 可让 OpenViking 服务端压缩召回内容,Codex 不启动本地压缩进程。client 仅用本地压缩,auto(默认)在本地压缩器不可用时走服务端,off 关闭压缩。服务端已有摘要时直接使用;明确返回无相关记忆时不注入。

Codex 通过共享 buildRecallBlockDetailed() 执行召回、排序、预算和旧服务端回退,仅保留会话映射、模型调用与 hook 输出适配。本地压缩失败保留预算内的检索结果;原始检索回退在不使用本地压缩时遵循 recallPreferAbstract,不再固定读取所有叶子全文。预算包含正文、URI 和包装文本。配置详见 共享插件说明。