yangzhaofeng496/dsh-feishu-plugin

Plugin插件 Native原生 ⭐ 4 MIT Notifications & Remote通知与远程

DeepSeek Harness 的飞书机器人桥接插件

Project Overview项目介绍

This is a native Cordis plugin built exclusively for DeepSeek Harness that connects Feishu bots to the DSH ecosystem. When a user sends a text message to a connected Feishu bot, the plugin passes the message as a task to a specified DSH profile for execution, then returns the execution result to the original Feishu conversation. It supports receiving messages via long connection, so no public network callback address is required, and it includes user whitelisting, dynamic authorization approval, and bidirectional file transfer between Feishu and DSH workspaces. It also automatically filters duplicate messages and terminates running child processes when the plugin stops.

Unauthorized users can submit authorization requests directly in Feishu, and admins can approve or revoke access without restarting the plugin. Authorization information is persistently stored, so it remains valid after a plugin or system restart. The plugin updates Feishu messages periodically to show task progress, isolates and stores conversation context per Feishu session, and queues tasks serially to avoid conflicts. It also provides an in-Feishu approval channel for one-time permission requests from DSH. Approval for one-time permissions only applies to that single task, so higher-level access is not permanently granted. Files up to 30MB are supported for both inbound and outbound transfers, with a limit of 5 outbound files per task.

The plugin is released under the open-source MIT license. Before installation, you need to have Node.js 20 or higher, pnpm package manager, a source-installed DeepSeek Harness, and a Feishu enterprise self-built app with bot capabilities enabled. You can install it directly from GitHub via the DSH CLI command dsh plugin --profile web add github:yangzhaofeng496/dsh-feishu-plugin#main, or install it from source by cloning the repo and running pnpm install. After installation, you need to configure Feishu credentials, admin list, workspace path, and authorization rules before enabling the plugin manually. Currently, the plugin only supports text messages, with no support for other message types.

这是专为 DeepSeek Harness 开发的原生 Cordis 插件,用于将飞书机器人接入 DSH。用户在飞书中发送文字消息后,插件会把消息作为任务交给指定的 DSH 配置文件执行,并将执行结果回复到原飞书会话。它支持无需公网回调地址的长连接收消息、用户白名单管控、动态授权审批,还支持飞书与 DSH 工作区之间的文件双向传输。

未授权用户可以在飞书中发起授权申请,由管理员在线审批通过后即可使用,授权信息会持久化保存,插件重启后依然有效。插件支持在执行任务过程中定时更新飞书消息显示进度,隔离并持久化每个飞书会话的对话上下文,还支持串行任务排队避免冲突,对一次性权限申请提供飞书内审批通道。

该插件采用 MIT 许可证开源,使用前需要准备 Node.js 20+、pnpm、已从源码安装的 DSH 以及一个启用机器人能力的飞书企业自建应用。安装后需要先配置飞书凭据、管理员列表、工作目录和授权规则,之后才能手动启用插件。目前仅支持文字消息和单文件大小不超过 30MB 的文件传输。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 4 stars - very few users, little community feedback星标只有 4,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:yangzhaofeng496/dsh-feishu-plugin#main

把 yangzhaofeng496/dsh-feishu-plugin 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

DSH Feishu Plugin

将飞书机器人连接到 DeepSeek Harness 的本地 Cordis 插件。用户在飞书中发送文字消息后,插件会把消息作为任务交给指定的 dsh profile 执行,并将结果回复到原会话。

社区标识:dsh-plugin · 支持 Node.js 20+ · MIT License

功能

  • 通过飞书开放平台长连接接收消息,无需公网回调地址
  • 使用 open_id 白名单限制可执行任务的用户
  • 支持用户在飞书内申请授权及管理员审批、撤销和查询
  • 动态授权持久化保存,重启后继续生效
  • 执行期间定时更新同一条飞书消息,显示运行时长和最新输出
  • 在排队、执行和结果消息中显示当前 Provider 与模型
  • 按飞书会话和用户隔离并持久化最近对话上下文
  • 主动运行必要脚本,并通过飞书处理 Harness 原生一次性权限审批
  • 支持飞书文件入站下载与 Harness 生成文件自动回传
  • 串行任务队列,避免多个任务同时操作同一工作区
  • 任务接收、开始、完成、失败和队列深度日志
  • 自动过滤重复消息
  • 执行超时和输出长度限制
  • 自动拆分过长的飞书回复
  • 插件停止时终止仍在运行的子进程

目前只支持文字消息。

前置条件

  • 已从源码安装 DeepSeek Harness,并可通过 dsh 命令运行
  • Node.js 20 或更高版本
  • pnpm
  • 一个已启用机器人能力的飞书企业自建应用

安装

从 GitHub 安装(推荐)

将主插件直接添加到 Harness 的 web profile:

dsh plugin --profile web add github:yangzhaofeng496/dsh-feishu-plugin#main

主插件默认处于禁用状态,且用户白名单为空。安装完成后仍需按下文保存飞书凭据、配置管理员和工作区,再手动启用。

从源码安装

克隆仓库并安装依赖:

git clone https://github.com/yangzhaofeng496/dsh-feishu-plugin.git
cd dsh-feishu-plugin
pnpm install
pnpm check

将本地插件添加到 Harness 的 web profile:

dsh plugin --profile web add "$(pwd)"

将配套的执行轨迹插件添加到 headless profile:

dsh plugin --profile headless add "$(pwd)/headless-trace"

第一个命令负责飞书连接和任务调度;第二个命令让 headless Agent 输出结构化的模型请求与工具执行事件。未安装 trace 子插件时,任务仍能执行,但飞书只能显示运行心跳和最终输出。

headless-trace 当前作为仓库内的可选配套插件提供;如需结构化执行轨迹,请使用源码安装方式添加该子目录。

配置飞书应用

在飞书开放平台创建企业自建应用,然后完成以下设置:

  1. 添加“机器人”应用能力。
  2. 在“权限管理”中开通接收消息和以应用身份发送消息所需的即时通讯权限。
  3. 在“事件与回调”中选择“使用长连接接收事件/回调”。
  4. 添加事件 im.message.receive_v1(接收消息)。
  5. 确保机器人拥有读取消息资源、上传文件和发送消息所需权限。
  6. 创建版本并发布应用,使机器人和权限配置生效。

具体权限名称可能随飞书开放平台界面更新而变化。发布前请确认机器人能够接收用户消息,并能向原会话发送消息。

保存凭据

不要把 App Secret 写入 Git 仓库或 cordis.patch.yml。将它保存到 Harness 凭据文件 ~/.dsh/.credentials.yaml:

FEISHU_APP_ID: cli_xxxxxxxxxxxxxxxx
FEISHU_APP_SECRET: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

限制该文件只对当前用户可读:

chmod 600 ~/.dsh/.credentials.yaml

启用插件

编辑 ~/.dsh/profiles/web/cordis.patch.yml,加入或覆盖 feishu 配置:

- id: feishu
  disabled: false
  config:
    appIdEnv: FEISHU_APP_ID
    appSecretEnv: FEISHU_APP_SECRET
    adminOpenIds:
      - ou_admin_xxxxxxxxxxxxxxxxxxxxxxxxxx
    allowedOpenIds:
      - ou_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
    authorizationFile: ~/.dsh/feishu-authorizations.json
    contextFile: ~/.dsh/feishu-contexts.json
    contextMaxTurns: 8
    contextMaxChars: 20000
    attachmentDirectory: .dsh-feishu/inbox
    maxInboundFileBytes: 31457280
    maxOutboundFileBytes: 31457280
    maxOutboundFiles: 5
    dshCommand: /absolute/path/to/dsh
    dshProfile: headless
    providerName: deepseek-official
    modelName: deepseek-v4-pro
    workspace: /absolute/path/to/your/workspace
    timeoutMs: 900000
    maxOutputChars: 50000
    streamUpdateIntervalMs: 5000
    streamHeartbeatIntervalMs: 30000
    streamPreviewChars: 2400
    maxMessageEdits: 15
    approvalTimeoutMs: 600000

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev memrec 下一个 Next dsh-factory →