Feishu/Lark bridge for DeepSeek Harness: scan-to-connect PersonalAgent binding, streaming cards, git-worktree project workspaces, parallel per-scope tasks, multi-role agents, cross-session notify, in-chat model/key management, and a safety-net guardian that still answers in Feishu after dsh crashes.
Install
# from npm (prebuilt)
dsh plugin --profile web add dsh-lark-bot
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:PlutoKeating/dsh-lark-bot
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
Overview
Make DeepSeek Harness a member of your Feishu/Lark and drive your local coding agent directly from phone, group, or thread. It uses a Feishu WebSocket long connection, so you need no public IP, domain, server, or NAT-tunnelling; Linux / macOS / Windows, Node.js ≥ 22.
Quick start
Prerequisites: DeepSeek Harness (dsh) is installed with DEEPSEEK_API_KEY configured; Node.js ≥ 22.19; a Feishu / Lark account.
npx dsh-lark-bot@latest setup --profile dsh-lark # ① one-command install (into a dsh profile + safety-net guardian by default)
dsh --profile dsh-lark # ② start
③ On first start the terminal prints a QR code → scan it with the Feishu app to create / select a PersonalAgent
app → once bound, message the bot directly; groups / threads default to @bot.
- Already have an app: skip the scan with
DSH_LARK_APP_ID=cli_xxx DSH_LARK_APP_SECRET=<secret> DSH_LARK_TENANT=feishu dsh --profile dsh-lark. - Upgrade:
npx dsh-lark-bot@latest upgrade --profile dsh-lark --yes.
No terminal needed: an admin just sends
/upgradein Feishu.
Core capabilities
Unique to the ecosystem
- Safety-net guardian: Feishu still replies if dsh crashes;
/safemodeopens a core-only safe mode to self-heal, queued tasks are restored on restart, and/jobsretries explicitly. Most bridges are "serial single chat + lost on crash". - Multi-bot trusted hand-off:
bot addadds independent instances and trusted bots hand off with a real @ in the same group, capped. - Full workspace & session management: an isolated git worktree is auto-created per session;
/sessionlists / binds sessions and/archive+/retentionauto-archive and clean up, so the session list never gets cluttered. - Robust version management: an admin just sends
/upgradein Feishu to update, verify, and reload in the background; you're only nudged when a new version exists, with no interruption to current work. - dsh Web visual settings: point-and-click work dir, model, concurrency, and reminders in Settings → Plugins — no env vars to memorize.
Other core capabilities
- Parallel tasks: many tasks run concurrently in the same group with isolated sessions.
- Multi-role agents:
/roleswitches / assigns PM, dev, doc, etc., each with its own persona, model preference, and rules. - In-chat model & key management: one
/configcard to switch providers and hot-reload keys, without leaving Feishu. - Quick / balanced / deep mode:
/modepicks the strength for the next turn without interrupting the current task. - Plan gate for key tasks:
lark_request_plan_approvalsends the full plan first, then approves or revises. - Cross-session notify + @: a task finishing in group A can push to group B / DM and @ you.
- Forward notifications to other IMs (notification-only): after
/channelsis configured, completion / failure / approval and urgent/fault notifications can be pushed one-way to Telegram / WeCom group robots and more. Push-only, no inbound interaction; Feishu stays the sole full-interaction platform and the default behavior is unchanged when no channel is configured./channels add --qr <wechat|qq|telegram>shows a QR code image in the Feishu session — scanning it with the matching IM app creates and binds the notification channel.
Streaming process cards render in a native Feishu collapsible panel.
Command reference
Command help, status, and cards are bilingual; /help is the full authoritative list. All commands are in docs/MANUAL.md.
| Command | What it does |
|---|---|
/config |
Model / provider / credential management card (/model, /provider(s), /key are aliases of the same card) |
/new /reset |
Start a new session |
/status |
Status card (workspace / model / session / run / token / job ledger) |
/mode (/effort) |
Pick quick / balanced / deep strength |
/cd <path> |
Switch to an independent session in that directory |
/ws list|save|use|remove |
Manage named workspaces |
/jobs [list|show|retry] |
Reconcile and retry queued/running/failed/interrupted jobs |
/session、/session bind |
Browse / explicitly bind a DSH session |
/role list|show|set|clear |
View / bind roles |
/notify <scope|chatId> <text> |
Cross-session notification (admin) |
/notifications [show|off|on …] |
Configure completion / failure / approval / urgent reminders (sinks= forwards to other IM channels) |
/channels [list|show|add|accept|remove|enable|disable …] |
Manage outbound notification channels (admin); add --qr <wechat|qq|telegram> is scan-to-bind |
/stop |
Stop current tasks |
/upgrade |
Self-update (admin) |
/doctor |
Generate a redacted diagnostic bundle (admin) |
/help |
Show the command list |
⚠️ Official channels only: the only official repo is PlutoKeating/dsh-lark-bot, and the only official npm packages are
dsh-lark-bot/dsh-feishu-bot(maintainerplutokeating). This project never ships a Windows .exe or a "download & run" installer — any page or repo distributing one under its name is fake / malicious. The only official install command isnpx dsh-lark-bot@latest setup --profile dsh-lark. See the Security notice below.
FAQ
Q: How do I connect DeepSeek Harness to Feishu?
A: With Node ≥ 22 and dsh installed (and DEEPSEEK_API_KEY set), run npx dsh-lark-bot@latest setup --profile dsh-lark, then dsh --profile dsh-lark and scan the QR code. DM the bot directly; groups / threads default to @bot.
Q: Do I need a public IP, domain, or server? A: No. Feishu uses a WebSocket long connection (outbound), so it works behind NAT — no public server, domain, or NAT-tunnelling.
Q: How is this different from other DeepSeek Harness Feishu plugins?
A: The most complete feature set: safety-net guardian, parallel tasks, multi-role agents, multi-bot hand-off, persistent job ledger, session archive, cross-session notify, dsh Web visual settings, in-chat model & key management, execution modes, plan gate, and in-Feishu self-update. It's a standard dsh profile bundle and setup is the only install path.
Q: Could there be a fake version?
A: The only official repo / npm packages are above under "Official channels only"; this project never ships an .exe or a "download & run" installer — anything distributing an exe is fake.
Compatibility
- DeepSeek Harness (
dsh): verified against 0.1.0-rc.8 (2026-08-25) via the official@deepseek-ai/dsh-sdk-client/dsh-acp; locked versions & upgrade policy indocs/COMPATIBILITY.md. - Runtime: Node.js ≥ 22.19; Platforms: Linux / macOS / Windows. Default adapter
sdk(native resume / streaming / image blocks); switchable toacp/headless/web.
Configuration
- Recommended: local dsh Web → Settings → Plugins → dsh-lark-bot to view / edit service region, App ID, App Secret, work dir, default model, concurrency, adapter, and reminders; App Secret is write-only.
- Or use
/config,/providers,/provider,/keyin Feishu to inspect / write providers, models, and credentials (admin-only). - Env vars use the
DSH_LARK_*prefix; state root is~/.dsh-lark; template in.env.example; full env-var matrix indocs/MANUAL.md§9.
Behavior details (crash reconciliation, session isolation, plan gate, per-tool approval, multi-bot hand-off, safety-net guardian) are in
docs/FEATURES.md; permissions & data indocs/MANUAL.md§6 andSECURITY.md.
Security & licensing
- License: GNU AGPL-3.0 (see
LICENSE). Open source and self-hostable, free for personal / internal use; commercial / SaaS / closed-source reuse needs a separate license. - Security: default-deny, secret redaction, path containment, SSRF protection, stale-event rejection, interaction tools disabled by default — see
SECURITY.md; report vulnerabilities privately via GitHub Security Advisory.
Upgrade & uninstall
npx dsh-lark-bot@latest upgrade --profile dsh-lark --yes # upgrade (or admin /upgrade in Feishu)
- Disable: export
DSH_LARK_DISABLED=1before starting the profile (plugin stays loaded, bridge engine stops). - Uninstall:
dsh plugin --profile dsh-lark remove dsh-lark-bot; local state (config / sessions / archives / roles) stays in~/.dsh-lark.
About the project
- Development:
pnpm install && pnpm typecheck && pnpm test && pnpm build; delivery standards indocs/ECOSYSTEM.md, AI-agent workflow inAGENTS.md. Dual-package publishpnpm publish:dual(dsh-lark-bot+dsh-feishu-bot, shared dist). - Author: PlutoKeating (profile).
- Contributors: zhuguangjun2002 · chensimo1992-sys · estelledc · fredjiangyysx · Geoffrey-hougaojie · hellxiaoao · koprivnikarurnaa-oss · Normanyin · pancong0711 · qvivp.
- Docs:
QUICK_START(install / quick start) ·MANUAL(full manual + commands + env vars) ·FEATURES(capability behavior) ·COMPATIBILITY·ARCHITECTURE·API·roadmap.
Community & ecosystem
| Platform | Status |
|---|---|
| awesome-dsh-plugin | ✅ listed (#1408) |
| awesome-dsh-plugins | ✅ listed · runtime-verified |
| dshfind | ✅ listed |
| dshbase | ✅ listed · install-verified |
| dsh-plugin.org | ✅ listed · official source verified |
| omdsh-dev/community | ✅ accepted · active |
Security notice
On 2026-08-17 a fake repo
tarraencompassing61/dsh-lark-botwas found: a non-fork re-upload, 113 of 114 commits authored as PlutoKeating, all CI removed, Issues closed, 0 Releases, yet posing as the official distribution with a "download Windows exe & run" README. This project never ships an exe; any such download is fake / malicious.Evidence archive:
docs/security/2026-08-17-impostor-repo-evidence/· Official download channel:docs/DOWNLOAD.md· Ongoing monitor:pnpm security:monitor.
Disclaimer
This is an unofficial community tool, unaffiliated with and not endorsed by DeepSeek or ByteDance / Feishu (Lark). DeepSeek Harness, Feishu / Lark, and related trademarks belong to their respective owners.
Links
More in this category
xmanrui/dsh-im★ 1579
Connect IM bots to DeepSeek Harness via QR codes or bot credentials (9 channels: Feishu, WeChat, DingTalk, WeCom, QQ, Slack, Telegram, Discord, and WhatsApp).
shaobeichen/dsh-pocket★ 1456
Remote phone access to the DSH Web UI: scan a QR code for LAN or public (cloudflared tunnel) access with real-time sync, a mobile-adaptive layout, and a settings tab.
inclusionAI/Avernet#deepseek-harness-channel-bcn★ 602
Connects DeepSeek Harness to Avernet's Bot Collaboration Network over WebSocket V2, with automatic onboarding, isolated agent sessions, tool-call events, and multi-bot routing tools.
omdsh-dev/dsh-notification★ 85
Desktop notifications for turn completions, with per-outcome controls and keyword rules.
whyihaveyou/dsh-suite#plugin-notify★ 56
IM webhook and local notifications on turn completion, errors, or approval (Feishu/WeCom/DingTalk/Slack/Discord/custom).
omdsh-dev/dsh-lark★ 55
Lark/Feishu bot channel for DeepSeek Harness: each chat drives its own agent, and tool approvals, model questions, and plan reviews return as cards answered by a button or a reply. Switch workspace and model from the chat (`/cd`, `/model`, `/new`), and run several bots that keep separate sessions and can hand turns to each other in one group.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.