yangzhaofeng496/dsh-feishu-plugin
DeepSeek Harness 的飞书机器人桥接插件
Project Overview项目介绍
This is a native Cordis plugin built exclusively for DeepSeek Harness that connects Feishu bots to the DSH ecosystem. When a user sends a text message to a connected Feishu bot, the plugin passes the message as a task to a specified DSH profile for execution, then returns the execution result to the original Feishu conversation. It supports receiving messages via long connection, so no public network callback address is required, and it includes user whitelisting, dynamic authorization approval, and bidirectional file transfer between Feishu and DSH workspaces. It also automatically filters duplicate messages and terminates running child processes when the plugin stops.
Unauthorized users can submit authorization requests directly in Feishu, and admins can approve or revoke access without restarting the plugin. Authorization information is persistently stored, so it remains valid after a plugin or system restart. The plugin updates Feishu messages periodically to show task progress, isolates and stores conversation context per Feishu session, and queues tasks serially to avoid conflicts. It also provides an in-Feishu approval channel for one-time permission requests from DSH. Approval for one-time permissions only applies to that single task, so higher-level access is not permanently granted. Files up to 30MB are supported for both inbound and outbound transfers, with a limit of 5 outbound files per task.
The plugin is released under the open-source MIT license. Before installation, you need to have Node.js 20 or higher, pnpm package manager, a source-installed DeepSeek Harness, and a Feishu enterprise self-built app with bot capabilities enabled. You can install it directly from GitHub via the DSH CLI command dsh plugin --profile web add github:yangzhaofeng496/dsh-feishu-plugin#main, or install it from source by cloning the repo and running pnpm install. After installation, you need to configure Feishu credentials, admin list, workspace path, and authorization rules before enabling the plugin manually. Currently, the plugin only supports text messages, with no support for other message types.
这是专为 DeepSeek Harness 开发的原生 Cordis 插件,用于将飞书机器人接入 DSH。用户在飞书中发送文字消息后,插件会把消息作为任务交给指定的 DSH 配置文件执行,并将执行结果回复到原飞书会话。它支持无需公网回调地址的长连接收消息、用户白名单管控、动态授权审批,还支持飞书与 DSH 工作区之间的文件双向传输。
未授权用户可以在飞书中发起授权申请,由管理员在线审批通过后即可使用,授权信息会持久化保存,插件重启后依然有效。插件支持在执行任务过程中定时更新飞书消息显示进度,隔离并持久化每个飞书会话的对话上下文,还支持串行任务排队避免冲突,对一次性权限申请提供飞书内审批通道。
该插件采用 MIT 许可证开源,使用前需要准备 Node.js 20+、pnpm、已从源码安装的 DSH 以及一个启用机器人能力的飞书企业自建应用。安装后需要先配置飞书凭据、管理员列表、工作目录和授权规则,之后才能手动启用插件。目前仅支持文字消息和单文件大小不超过 30MB 的文件传输。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-feishu-plugin(yangzhaofeng496/dsh-feishu-plugin)
仓库:https://github.com/yangzhaofeng496/dsh-feishu-plugin
本站详情页:https://www.yhbd.top/plugins/yangzhaofeng496-dsh-feishu-plugin/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 4 · 最近提交 2026-08-17 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 4 stars - very few users, little community feedback星标只有 4,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:yangzhaofeng496/dsh-feishu-plugin#main
把 yangzhaofeng496/dsh-feishu-plugin 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
DSH Feishu Plugin
将飞书机器人连接到 DeepSeek Harness 的本地 Cordis 插件。用户在飞书中发送文字消息后,插件会把消息作为任务交给指定的 dsh profile 执行,并将结果回复到原会话。
社区标识:
dsh-plugin· 支持 Node.js 20+ · MIT License
功能
- 通过飞书开放平台长连接接收消息,无需公网回调地址
- 使用
open_id白名单限制可执行任务的用户 - 支持用户在飞书内申请授权及管理员审批、撤销和查询
- 动态授权持久化保存,重启后继续生效
- 执行期间定时更新同一条飞书消息,显示运行时长和最新输出
- 在排队、执行和结果消息中显示当前 Provider 与模型
- 按飞书会话和用户隔离并持久化最近对话上下文
- 主动运行必要脚本,并通过飞书处理 Harness 原生一次性权限审批
- 支持飞书文件入站下载与 Harness 生成文件自动回传
- 串行任务队列,避免多个任务同时操作同一工作区
- 任务接收、开始、完成、失败和队列深度日志
- 自动过滤重复消息
- 执行超时和输出长度限制
- 自动拆分过长的飞书回复
- 插件停止时终止仍在运行的子进程
目前只支持文字消息。
前置条件
- 已从源码安装 DeepSeek Harness,并可通过
dsh命令运行 - Node.js 20 或更高版本
- pnpm
- 一个已启用机器人能力的飞书企业自建应用
安装
从 GitHub 安装(推荐)
将主插件直接添加到 Harness 的 web profile:
dsh plugin --profile web add github:yangzhaofeng496/dsh-feishu-plugin#main
主插件默认处于禁用状态,且用户白名单为空。安装完成后仍需按下文保存飞书凭据、配置管理员和工作区,再手动启用。
从源码安装
克隆仓库并安装依赖:
git clone https://github.com/yangzhaofeng496/dsh-feishu-plugin.git
cd dsh-feishu-plugin
pnpm install
pnpm check
将本地插件添加到 Harness 的 web profile:
dsh plugin --profile web add "$(pwd)"
将配套的执行轨迹插件添加到 headless profile:
dsh plugin --profile headless add "$(pwd)/headless-trace"
第一个命令负责飞书连接和任务调度;第二个命令让 headless Agent 输出结构化的模型请求与工具执行事件。未安装 trace 子插件时,任务仍能执行,但飞书只能显示运行心跳和最终输出。
headless-trace当前作为仓库内的可选配套插件提供;如需结构化执行轨迹,请使用源码安装方式添加该子目录。
配置飞书应用
在飞书开放平台创建企业自建应用,然后完成以下设置:
- 添加“机器人”应用能力。
- 在“权限管理”中开通接收消息和以应用身份发送消息所需的即时通讯权限。
- 在“事件与回调”中选择“使用长连接接收事件/回调”。
- 添加事件
im.message.receive_v1(接收消息)。 - 确保机器人拥有读取消息资源、上传文件和发送消息所需权限。
- 创建版本并发布应用,使机器人和权限配置生效。
具体权限名称可能随飞书开放平台界面更新而变化。发布前请确认机器人能够接收用户消息,并能向原会话发送消息。
保存凭据
不要把 App Secret 写入 Git 仓库或 cordis.patch.yml。将它保存到 Harness 凭据文件 ~/.dsh/.credentials.yaml:
FEISHU_APP_ID: cli_xxxxxxxxxxxxxxxx
FEISHU_APP_SECRET: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
限制该文件只对当前用户可读:
chmod 600 ~/.dsh/.credentials.yaml
启用插件
编辑 ~/.dsh/profiles/web/cordis.patch.yml,加入或覆盖 feishu 配置:
- id: feishu
disabled: false
config:
appIdEnv: FEISHU_APP_ID
appSecretEnv: FEISHU_APP_SECRET
adminOpenIds:
- ou_admin_xxxxxxxxxxxxxxxxxxxxxxxxxx
allowedOpenIds:
- ou_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
authorizationFile: ~/.dsh/feishu-authorizations.json
contextFile: ~/.dsh/feishu-contexts.json
contextMaxTurns: 8
contextMaxChars: 20000
attachmentDirectory: .dsh-feishu/inbox
maxInboundFileBytes: 31457280
maxOutboundFileBytes: 31457280
maxOutboundFiles: 5
dshCommand: /absolute/path/to/dsh
dshProfile: headless
providerName: deepseek-official
modelName: deepseek-v4-pro
workspace: /absolute/path/to/your/workspace
timeoutMs: 900000
maxOutputChars: 50000
streamUpdateIntervalMs: 5000
streamHeartbeatIntervalMs: 30000
streamPreviewChars: 2400
maxMessageEdits: 15
approvalTimeoutMs: 600000
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
xmanrui/dsh-im
tencent-connect/dsh-qqbot
flymysql/dsh-remote
whiteguo233/dsh-openbiliclaw
omdsh-dev/dsh-lark
hanshanyike/dsh-yolo
THEWOLFWALKER/dsh-notifier