sugarforever/dsh-lark
DeepSeek 集成用 Lark 插件
Project Overview项目介绍
This is a DeepSeek Harness-specific plugin that enables users to chat with the Harness Agent directly from Feishu or Lark, while retaining all configured models, tools, system prompts and session storage from DSH. It uses the official Lark Node SDK to receive messages via a persistent WebSocket connection, so no public server, domain or webhook callback URL is required. The plugin maps Lark chat sessions to native Harness sessions and passes incoming messages directly to the DSH agent for processing.
To use the plugin, you first need to create a self-built bot application in the Feishu or Lark developer console, enable the bot capability, and configure long-lived event reception with the im.message.receive_v1 event subscribed. It requires Node.js 22.19.0 or higher, or Node.js 24.0.0 and above, as well as DeepSeek Harness version 0.1.0-rc.6 or a later 0.1.x release. It supports whitelisting for group and direct chats, and lets users either use DSH's default model or set a dedicated model for the Lark channel.
You can install the plugin to your DSH Web Profile using the DSH CLI command, and configure it through the DSH Settings UI after installation. Configuration changes support hot reloading, so you do not need to restart Harness after adjusting app credentials or access rules. The project is open source under the MIT license, uses GitHub Actions for automated testing, building and npm publishing, and includes a detailed troubleshooting guide for common connection and messaging issues.
这是一个专为 DeepSeek Harness 开发的原生插件,安装后用户可以直接通过飞书或Lark与Harness Agent对话,继续使用Harness中已配置的模型、工具、系统提示和会话存储。它使用飞书官方Node SDK通过WebSocket长连接接收消息,不需要公网服务器、域名或Webhook回调地址,负责将飞书会话映射到Harness会话,再将消息交给Agent处理。
它支持通过白名单限制单聊和群聊用户,既可以沿用Harness的默认模型,也可以为飞书渠道单独指定模型。使用该插件需要提前在飞书或Lark开发者后台创建自建应用,开启机器人能力,配置长连接事件接收并订阅im.message.receive_v1事件。运行要求Node.js版本不低于22.19.0(或24.0.0以上),同时需要DeepSeek Harness 0.1.0-rc.6或更高的0.1.x版本。
插件可通过DSH的CLI命令安装到Harness Web Profile,安装后可直接在Harness的设置页面完成配置,配置变更支持热更新,无需重启Harness。本项目采用MIT许可证开源,支持通过GitHub Actions自动化完成测试、构建并发布到npm。用户遇到连接或消息问题时,可通过检查权限、网络配置和插件设置来排查故障。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-lark(sugarforever/dsh-lark)
仓库:https://github.com/sugarforever/dsh-lark
本站详情页:https://www.yhbd.top/plugins/sugarforever-dsh-lark/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 26 · 最近提交 2026-09-07 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- 26 stars - an early-stage project星标 26,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
npx @deepseek-ai/dsh plugin --profile web add @sugarforever/dsh-lark
把 sugarforever/dsh-lark 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
DeepSeek Harness Lark / 飞书
@sugarforever/dsh-lark 是一个 DeepSeek Harness Host 插件。安装后,用户可以直接从飞书或 Lark 与 Harness Agent 对话,并继续使用 Harness 中配置的模型、工具、系统提示和会话存储。
插件使用飞书官方 @larksuiteoapi/node-sdk 的 Channel API,通过 WebSocket 长连接接收消息,不需要公网服务器、域名或 Webhook 回调地址。官方 SDK 负责连接、自动重连、消息去重、过期事件过滤、同一聊天的串行处理、消息格式转换和发送回复;插件负责把飞书会话映射到 Harness Session,再把消息交给 Agent。
功能
- 支持飞书中国版和国际版 Lark。
- 使用 WebSocket 长连接接收事件,无需公网回调地址。
- 回复会关联原始消息,并保留在原来的话题线程中。
- 可以通过白名单限制群聊和单聊用户。
- 可以沿用 Harness 默认模型,也可以为飞书渠道指定模型。
运行要求
- Node.js
^22.19.0或>=24.0.0。 - 已安装或能够通过
npx运行 DeepSeek Harness0.1.0-rc.6或更高的0.1.x版本。 - 一个飞书或 Lark 自建应用。
- 应用已经启用机器人能力。
- 应用使用长连接接收事件,并订阅
im.message.receive_v1。
如果尚未运行过 Harness,可以先启动一次 Web Profile:
npx @deepseek-ai/dsh web
首次启动会创建 web Profile。默认目录是 ~/.dsh/profiles/web;如果设置了 DSH_HOME,则位于 $DSH_HOME/profiles/web。
创建飞书应用
以下名称在飞书中国版和国际版 Lark 控制台中可能略有区别,但配置内容相同。
创建自建应用
- 打开飞书或 Lark 开发者后台。
- 创建一个企业自建应用。
- 填写应用名称、描述和图标。
- 进入“凭证与基础信息”,记录 App ID 和 App Secret。
不要把 App Secret 直接写进仓库中的 YAML 文件。后续通过 Harness Settings 页面保存,或者通过启动环境变量传给插件。
启用机器人
- 进入“添加应用能力”。
- 添加“机器人”能力。
- 设置机器人名称和头像。
添加权限
默认配置下,应用需要开通以下三个权限:
| 权限标识 | 控制台中的权限名称 | 用途 | 是否必需 |
|---|---|---|---|
im:message.p2p_msg:readonly |
获取用户发给机器人的单聊消息 | 接收用户与机器人的单聊消息 | 是 |
im:message.group_at_msg:readonly |
获取群组中 @机器人的消息 | 接收群聊中明确 @机器人的消息 | 是 |
im:message:send_as_bot |
以应用的身份发消息 | 让机器人回复单聊、群聊和话题消息 | 是 |
飞书控制台中显示的中文名称可能随平台版本略有调整,应以权限标识为准。添加 im.message.receive_v1 事件时,控制台通常也会提示补充前两个接收权限。
如果开发者后台支持批量导入权限,可以直接复制下面的配置:
{
"scopes": {
"tenant": [
"im:message.group_at_msg:readonly",
"im:message.p2p_msg:readonly",
"im:message:send_as_bot"
],
"user": []
}
}
这组配置对应插件的默认行为:接收单聊消息、接收群聊中 @机器人的消息,以及以机器人身份发送回复。导入后仍需在事件订阅中添加 im.message.receive_v1,并发布新版本,权限和事件配置才会应用到已安装的机器人。
如果需要让机器人处理群聊中没有 @机器人的普通消息,还要额外开通:
| 权限标识 | 控制台中的权限名称 | 用途 | 是否必需 |
|---|---|---|---|
im:message.group_msg |
获取群组中所有消息 | 配合 requireMention: false 接收群内全部消息 |
仅关闭 @限制时需要 |
im:message.group_msg 的权限范围更大,通常需要企业管理员审批。默认的 requireMention: true 不需要申请这个权限。
有些企业会直接批准范围更大的 im:message 权限,它也可以覆盖消息读取和发送场景,但本插件不要求使用这个宽泛权限。优先申请上表中的最小权限即可。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
xmanrui/dsh-im
tencent-connect/dsh-qqbot
flymysql/dsh-remote
whiteguo233/dsh-openbiliclaw
omdsh-dev/dsh-lark
hanshanyike/dsh-yolo
THEWOLFWALKER/dsh-notifier