DeepSeek Harness 插件

dsh-lark-channel

Feishu and Lark text, image, and file channel bridge for DeepSeek Harness(英文原文)

跳到安装方式

来源信息

GitHub 仓库
sliverp/DeepSeek-harness-lark
最近更新
2026年8月19日
分类
远程与移动
GitHub stars
3
载体类型
plugin
目录证据
上游声明已找到 dsh.bundle
证据路径
package.json#dsh.bundle
核对版本
0.1.0-rc.8
上游核对日期
2026-08-20

该证据由上游目录提供。本站没有安装、运行或安全审核这个插件。

安装

默认先复制一段 Prompt,让 Agent 读 GitHub 仓库和源码;需要自己装时再切到命令。

复制这段 Prompt,发给 DSH、Codex 或其他 Agent,让它先读 GitHub 仓库和源码。

请先不要安装或执行任何命令。阅读这个插件的 GitHub 仓库、README 和关键源码,然后用清楚、直接的方式回答以下问题,帮助我判断它是否适合我的需求:

1. 这个插件是什么,解决什么问题;
2. 适合哪些用户和典型使用场景;
3. 安装后如何使用,并给出一个最小使用示例;
4. 有哪些已知限制,以及隐私、安全、兼容性或维护风险;
5. 给出“推荐 / 有条件推荐 / 不推荐”的明确建议和理由。

请区分仓库明确说明、根据源码推断和未知信息。证据不足时请明确说明,不要猜测或照抄 README。

GitHub:https://github.com/sliverp/DeepSeek-harness-lark
插件名:dsh-lark-channel
作者:sliverp

检查来源文件

安装前先看这个插件目录里的 README 和其他文件。

文件资源管理器3 个文件
README.md来源说明 · 只读预览

DeepSeek Harness Lark / Feishu plugin

A DeepSeek Harness channel powered by the official @larksuiteoapi/node-sdk. It uses the official WebSocket transport, so no public callback server is required, and supports both Feishu and international Lark.

Features

  • Official WebSocket connection and automatic reconnection
  • Direct and group access policies; groups require a bot mention by default
  • Text, rich-text, image, and ordinary-file input
  • Durable Harness attachments with model-aware multimodal input
  • Ordinary files are downloaded into .dsh-lark/inbox/ under the Agent workspace so filesystem tools can inspect them
  • Model text replies, generated-image upload, and workspace-file delivery
  • Persistent, isolated Harness sessions per chat; /new retains old history and switches to a blank session
  • Agent presets are mounted and recorded for both creation and resume; the default is standard
  • Registered Harness slash commands execute directly instead of being sent to the model
  • Same-conversation /approve <code> and /reject <code> decisions for one-shot tool approvals
  • /bot-ping, /bot-help, /bot-image-test, /bot-file-test, /bot-status, /bot-cancel
  • App Secret resolution through the Harness credential service
  • Dormant startup when App ID or App Secret is not configured, so installation alone never blocks Harness Web

Requirements

  • Node.js 22.19 or later
  • pnpm 10.33.4
  • DeepSeek Harness 0.1.0-rc.7 or later

Install

pnpm dsh plugin --profile web add github:sliverp/DeepSeek-harness-lark

For a local checkout:

pnpm dsh plugin --profile web add /absolute/path/to/DeepSeek-harness-lark

Configure the Lark application

1. Create a custom application in the Feishu developer console and enable its bot capability. 2. Grant im:message.p2p_msg:readonly, im:message.group_at_msg:readonly, im:message:readonly, im:message:send_as_bot, and im:resource. The im:message:readonly scope is required by Feishu's message-resource download endpoint for user-sent images and files. 3. Select long-connection event delivery and subscribe to im.message.receive_v1. 4. Publish an application version and add the bot to the required chats. 5. Put the App ID in LARK_APP_ID and store the App Secret under the Harness credential reference LARK_APP_SECRET.

Environment injection is supported for development:

export LARK_APP_ID='cli_your-app-id'
export LARK_APP_SECRET='your-app-secret'
pnpm dsh --profile web

For durable use, put the App ID in ~/.dsh/.env and store the App Secret through the Harness credential settings surface. Never commit credentials.

Bundle configuration

- id: lark-channel
  name: deepseek-harness-lark
  config:
    appId: !!js process.env.LARK_APP_ID
    appSecretRef: LARK_APP_SECRET
    cwd: !!js process.env.DSH_LARK_CWD ?? process.cwd()

International Lark and restrictive policy example:

    domain: lark
    singlePolicy: allowlist
    singleAllowFrom: [ou_xxx]
    groupPolicy: allowlist
    groupAllowChats: [oc_xxx]
    groupRequireMention: true
    imageInputMode: auto
    maxInboundFiles: 10
    maxInboundFileBytes: 52428800
    maxInboundMessageFileBytes: 104857600
    maxReplyFiles: 5
    maxOutboundFileBytes: 31457280
    approvalTimeoutMs: 240000
    agentPreset: standard

Access policies accept open, allowlist, or disabled. Use allowlists and least-privilege Harness permissions in production.

Connection and authentication run in the background. Missing or invalid Lark credentials leave this channel offline and are logged without blocking Harness startup.

Inbound images and ordinary files are downloaded through the message-scoped resource endpoint using their matching message_id and resource key; this requires im:message:readonly (or the broader im:message). The separate im:resource scope remains necessary for bot-side image/file upload. Filenames are reduced to safe leaf names, files are created without overwriting existing paths, and each message gets a private directory below <cwd>/.dsh-lark/inbox/. The defaults allow 10 files, 50 MiB per file, and 100 MiB total per message. The model receives the saved path and must use its normal filesystem tools to read the file; file contents are not executed or silently injected into the prompt.

When the model intentionally returns a regular workspace file, it places an explicit Markdown link to that file in the final visible answer. The plugin resolves the canonical path, rejects missing files, directories, symlink escapes, and every target outside the session cwd, then uploads the bounded bytes with Lark's file API. Only the final assistant message is inspected; intermediate tool output cannot trigger a file send. By default, one reply may send up to 5 non-empty files of at most 30 MiB each.

When Harness requests tool approval, the plugin sends a requester-bound six-digit code to the originating chat. Reply /approve <code> to allow that operation once or /reject <code> to deny it. Codes are one-shot, cannot cross chats, bypass ordinary message capacity while the original turn waits, and fail closed on timeout, cancellation, send failure, or shutdown. approvalTimeoutMs must remain below responseTimeoutMs.

agentPreset is the explicit fallback for new sessions and persisted records without a preset. The tool-loop fix advances the plugin session namespace from lark-v1-* to lark-v2-*: existing files are neither deleted nor rewritten, but the plugin no longer appends to potentially DSML-contaminated lark-v1-* records. They remain available for inspection in the Web UI.

Verify

Send /bot-ping, /bot-image-test, /bot-file-test, and /new. The bot should return pong, a blue diagnostic image, a downloadable text file, and confirmation that it switched to a blank session. Send ordinary text, an image, and a CSV file; ask the bot to inspect the CSV and verify that it uses the downloaded workspace path. Then ask it to create and send a CSV; the final reply should contain the file attachment. Request an operation that needs approval and reply with the exact /approve <code> or /reject <code> shown; the same turn should continue or stop without using the Web approval panel.

Develop

pnpm install
pnpm run check
pnpm pack

The repository uses PNPM 10.33.4. Plugin runtime requires Node.js >=22.19 and does not require PNPM 11.

Protocol and configuration behavior were cross-checked against larksuite/openclaw-lark. Transport and media operations use the official Lark Node SDK. MIT licensed.