imetn/dsh-lark-bridge
Bidirectional Lark/Feishu controller for DeepSeek Harness
dsh-lark-bridge is a secure, bidirectional Feishu/Lark controller for DeepSeek Harness: send a task from a DM, group, or topic, and the Bridge runs it in the right Harness Project and Session, updating one native card as work progresses and routing approvals, questions, files, images, and controls back to the same conversation. Each group maps to a Project (working directory, model route, access policy, card preset); each topic or thread maps to an isolated Session by default. You can start, continue, steer, stop, resume, and inspect sessions from Lark; approve one tool call or answer structured questions from card buttons; receive text, images, and files (the Agent can send safe workspace files back with lark_deliver); and choose compact, standard, or developer card detail per Project or Session. Cards show bounded tool summaries, never hidden model reasoning. Security features: owner pairing via official authorization identity or a hashed ten-minute one-use /claim code, per-user/per-chat access checks, secret redaction, 0700 inbound file dirs, symlink-escape rejection on outbound files, event deduplication and per-chat serialization, and one approval button = one operation.
Install
pnpm dlx github:imetn/dsh-lark-bridge setup --project "$PWD"npm package dsh-lark-bridge 0.1.0 published (registry-verified 2026-08-24), but the README install path is a one-shot setup command run from the Project you want the bot to control: pnpm dlx github:imetn/dsh-lark-bridge setup --project "$PWD". The setup opens the official Feishu/Lark authorization page, requests only the messaging/attachment/reaction/event/card-callback scopes, stores the App Secret in Harness's owner-only credential file (never the Profile), installs the plugin, writes an idempotent lark Profile, binds the authorizing user, and starts the Bridge. For ByteDance tenants add --brand larkoffice; for international Lark add --brand lark. Existing-app flow: printf '%s' "$LARK_APP_SECRET" | pnpm dlx github:imetn/dsh-lark-bridge setup --project "$PWD" --app-id cli_xxx --app-secret-stdin. Diagnostics: pnpm dlx github:imetn/dsh-lark-bridge doctor. Requirements: Node.js 22+, pnpm, a working DSH model configuration, and an installed dsh CLI or official Harness source checkout.
Compatibility
DeepSeek Harness 0.1.0-rc.6 (tested; Harness is in developer preview). Node.js 22+, pnpm required. WebSocket long connections only — no public webhook server. The lark Profile is a Bridge process, not the Web UI: dsh --profile lark starts the Bridge only; http://127.0.0.1:3080 belongs to the separate dsh web command. Git installs need no install-time build (lib/ is committed and the official Lark SDK is bundled).
Details
- Repo: imetn/dsh-lark-bridge
- Category: Messaging & Communication
- Stars: 7
- Version: npm package dsh-lark-bridge 0.1.0 (registry-verified 2026-08-24); install via pnpm dlx github:imetn/dsh-lark-bridge setup
- Last push: 2026-08-14
- First seen: 2026-08-13
Recent updates
The current English README documents: DM/group/topic-to-Project/Session mapping, card detail presets (compact/standard/developer), full control surface (plain text, /steer, /status, /stop, /approve, /reject, /new, /sessions, /projects, /bind, /unbind, /commands, /help), multiple-Project configuration via ~/.dsh/profiles/lark/cordis.patch.yml, one-click and existing-app setup flows, the /claim pairing flow, security model, common fixes, and development/discovery (dsh.bundle.patch + dsh-plugin keyword).
FAQ
- Does the Bridge expose a public webhook server?
- No — it uses WebSocket long connections, so there is no public webhook endpoint. Incoming events are deduplicated, stale events are rejected, and each chat is serialized.
- How does one group map to a Harness Project?
- If the Profile contains one accessible Project, the first owner message that mentions the bot binds that group automatically. With multiple Projects, send @bot /bind <project-id> once. Each topic or thread maps to an isolated Session by default (groupSessionScope: thread).
- Where is the App Secret stored?
- In Harness's owner-only credential file — never in the Profile. The setup flow requests only the scopes the Bridge actually uses (messaging, attachment, reaction, event, and card callback).
Alternatives
PlutoKeating/dsh-lark-bot · amlyczz/dsh-lark-link · Jiao-XXX/dsh-auto-approve