imetn/dsh-lark-bridge
DeepSeek Harness 的双向 Lark/飞书控制器
Project Overview项目介绍
This is a native DSH plugin that acts as a secure bidirectional bridge between DeepSeek Harness and Feishu/Lark. It lets users initiate tasks directly from Lark DMs, groups, or topics, then routes those tasks to the correct DSH project and session. It updates a native Lark card with real-time progress, and routes approvals, questions, files, images, and control inputs back to the original conversation. It has been tested against DSH version 0.1.0-rc.6 and is built to work with DSH’s current developer preview release.
The plugin supports core session actions including starting, continuing, steering, stopping, resuming, and inspecting DSH sessions directly from Lark. It supports configurable mapping of each Lark group to a DSH project, working directory, model route, access policy, and card preset, with each topic or thread getting an isolated session by default. Users can choose between compact, standard, or developer card detail levels per project or session, and the plugin uses WebSocket long connections so no public webhook server is required. Cards only show bounded tool summaries and never expose hidden model reasoning.
To install the plugin, you need Node.js 22 or newer, pnpm, a working DSH model configuration, and either an installed DSH CLI or a local DSH source checkout. A one-click setup command is available via pnpm dlx, which can automatically create a new Lark bot app, or manually connect an existing app if your enterprise blocks one-click creation. The plugin is open source under the MIT license, and includes multiple security protections such as access control, secret redaction, file sandboxing, and event deduplication to keep your workspace secure.
这是一个专为 DeepSeek Harness 开发的原生插件,用于实现飞书(Lark)与 DSH 之间的双向安全控制。用户可以从飞书的私聊、群组或话题发送任务,插件会将任务调度到对应 DSH 项目和会话中,实时更新飞书卡片的工作进度,同时把审批、问题、文件、图片等信息回传到原飞书对话。该插件已经过 DSH 0.1.0-rc.6 版本测试,适配当前 DSH 开发者预览版功能。
该插件支持从飞书启动、继续、停止、恢复、检查 DSH 会话,可将每个飞书群组映射到指定 DSH 项目、工作目录、模型路由和访问策略,每个话题或线程默认对应一个独立会话。插件提供三种卡片详情模式可选,采用 WebSocket 长连接,不需要公开的 Webhook 服务器,卡片只展示工具摘要,不暴露隐藏的模型推理过程。
安装要求 Node.js 22+ 版本和 pnpm 包管理器,可通过 pnpm dlx 命令一键完成配置,支持自动创建飞书机器人应用,也可手动绑定已有应用。该插件使用 MIT 许可证开源,内置严格的安全校验机制,包括权限验证、密钥脱敏、文件沙箱和事件去重,保障运行安全和用户数据隐私。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-lark-bridge(imetn/dsh-lark-bridge)
仓库:https://github.com/imetn/dsh-lark-bridge
本站详情页:https://www.yhbd.top/plugins/imetn-dsh-lark-bridge/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 6 · 最近提交 2026-08-14 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 6 stars - very few users, little community feedback星标只有 6,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:imetn/dsh-lark-bridge
把 imetn/dsh-lark-bridge 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
DeepSeek Harness Lark Bridge
English | 中文
A secure, bidirectional Feishu/Lark controller for DeepSeek Harness.
Send a task from a DM, group, or topic. The Bridge runs it in the right Harness Project and Session, updates one native card as work progresses, and routes approvals, questions, files, images, and controls back to the same conversation.
Tested with DeepSeek Harness 0.1.0-rc.6. Harness is still in developer preview.
What works
- Start, continue, steer, stop, resume, and inspect Harness Sessions from Lark.
- Map each group to a Project, working directory, model route, access policy, and card preset.
- Map each topic or thread to an isolated Session by default.
- Update one card from running to completed, blocked, cancelled, or failed.
- Approve one tool call or answer structured Agent questions from card buttons.
- Receive text, images, and files. The Agent can send safe workspace files back with
lark_deliver. - Choose compact, standard, or developer card detail per Project or Session.
- Use WebSocket long connections, with no public webhook server.
Cards show bounded tool summaries, never hidden model reasoning.
Quick start
Requirements: Node.js 22+, pnpm, a working DeepSeek Harness model configuration, and either an installed dsh CLI or an official Harness source checkout nearby.
Run this from the Project you want the bot to control:
pnpm dlx github:imetn/dsh-lark-bridge setup --project "$PWD"
The setup command:
- Opens the official Feishu/Lark authorization page for a new bot app.
- Requests only the messaging, attachment, reaction, event, and card callback capabilities used by the Bridge.
- Stores the returned App Secret in Harness's owner-only credential file, never in the Profile.
- Installs the plugin, writes an idempotent
larkProfile, binds the authorizing user, and starts the Bridge. - Opens the bot. A welcome card arrives automatically when the platform returns the user's Open ID.
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
xmanrui/dsh-im
tencent-connect/dsh-qqbot
flymysql/dsh-remote
whiteguo233/dsh-openbiliclaw
omdsh-dev/dsh-lark
hanshanyike/dsh-yolo
THEWOLFWALKER/dsh-notifier