Introduction¶
The core value of DeepSeek Harness (DSH) lies in local agent development and execution. For developers, operating an Agent directly in the terminal is convenient, but interactions are less intuitive in mobile scenarios. dsh-feishu-bridge solves this problem: it is a bridge plugin that connects Feishu to local DSH, allowing users to send messages in a Feishu direct chat to directly drive the local DSH Agent to execute tasks and reply.
Unlike the official Web UI or desktop wrapper approaches, this solution does not require a public IP address or reverse tunnel; it directly uses a local persistent connection to handle events.
Core Features¶
- Message-driven: Listens to the Feishu persistent connection event
im.message.receive_v1and converts remote text into a follow-up task for the local Agent. - Reply strategy: First replies “Processing…”, then sends the full reply text after the turn ends.
- Security validation: Supports whitelist validation and
message_iddeduplication; an empty whitelist rejects all requests. - High-risk restrictions: High-risk tools such as
bash,write, andeditare denied by default (deny). - Management commands: Supports
/statusto view the status and/cancelto cancel the current task.
Installation and Enablement¶
Prerequisites:
* Node.js version >= 22.
* DeepSeek Harness version 0.1.0-rc.6.
Installation steps:
1. Clone and build from source (optional; direct installation with npx is recommended).
2. Create or specify a profile (for example, feishu-dev).
3. Run the installation command:
npx --yes @deepseek-ai/dsh@0.1.0-rc.6 plugin --profile feishu-dev add .
Configuration¶
The plugin requires injecting Feishu credentials and permission settings through environment variables or a configuration file. The fields to configure include:
* appId: Feishu app ID.
* appSecret: Feishu app secret.
* allowOpenIds: Whitelist of Feishu user IDs allowed to receive messages.
* workspace: Local Agent workspace path.
Security configuration:
* Empty whitelist: If allowOpenIds is empty or not configured, all messages are rejected.
* Tool permissions: High-risk tools are prohibited by default. If you need to temporarily relax this (extremely unsafe), it must be controlled manually via environment variables; approval is not supported from the Feishu side.
Typical Usage¶
After installing and starting DSH, send the following instructions in a Feishu direct chat:
- Normal conversation: Send “Hello”.
- Expected: You first receive “Processing…”, then receive the model’s full reply.
- Security test: Send “Use bash to run echo hi”.
- Expected: You receive the “Safety gate denied” prompt, and the terminal log shows
tool_denied.
- Expected: You receive the “Safety gate denied” prompt, and the terminal log shows
- Status query: Send
/status.- Expected: You receive the current Agent status (such as “Idle” or “Busy”).
- Cancel task: Send
/cancel.- Expected: The currently running task is canceled.
Notes¶
- Disclaimer: This plugin is an independent community project and has no affiliation with DeepSeek or Feishu. Remote messages will drive the local Agent to read and write files; the operator is solely responsible for any changes and security consequences.
- Session limitations: If the previous message in the same session has not been processed completely, new messages are answered with “Busy” (no queuing).
- Compatibility: After a process restart, the session is not restored and starts as a new session. Compatibility is subject to
COMPAT.md; DSH is still in the Preview stage. - Message types: Currently, only direct chat + plain text is supported; group chat @mentions, rich text, and card messages are not supported yet.
Summary¶
dsh-feishu-bridge provides a minimally invasive way to use Feishu as a remote console for the local DeepSeek Harness Agent. It uses a persistent connection for immediate responses and includes strict security restrictions, making it suitable for scenarios that require quickly triggering local compute tasks from mobile devices or remotely.