Introduction

DeepSeek Harness (DSH) is based on the “everything is a plugin” philosophy, enabling agents to interact with the external world through extended tools. In office scenarios, the Lark ecosystem contains many documents, sheets, and agents, but AI programming assistants usually cannot access these contents directly and often require manual copy-and-paste.

The dsh-lark-bridge plugin transforms capabilities of the Lark Open Platform into tools that DSH can invoke. It resolves the problems of agents being unable to directly read documents, operate Bitable, or trigger Lark agents, enabling DSH agents to work as Lark bots or server-side interfaces.

Core Features

This plugin primarily provides the following capabilities:

  1. Credential Parsing and Automatic Refresh: Handles authentication via tenant_access_token; supports parsing from environment variables or the credentials domain, eliminating manual token maintenance.
  2. Outbound Message Tools: Supports sending text or card messages to users and groups.
  3. Document Reading: Provides reading of plain-text and structured block-level content.
  4. Bitable Read/Write: Supports listing, creating, updating, and batch-creating records.
  5. Agent Invocation: Triggers Lark bots or agents via messages.
  6. Private Chat Inbound (Phase 2): Establishes a long-lived connection to receive Lark private chat messages, with DSH agents processing and replying locally.

Installation and Activation

To install the plugin, run the following command. Replace <your-user> with your GitHub username.

dsh plugin --profile web add github:<your-user>/dsh-lark-bridge

After installation, enable the Bundle in the configuration file. DSH reads the dsh.profile.bundles list by default.

Configuration

In the plugin configuration, it is recommended to store secrets in environment variables rather than writing them directly into the configuration file.

Configuration item Default Description
appIdEnv FEISHU_APP_ID Environment variable name for the Lark App ID, used for credential parsing.
appSecretEnv FEISHU_APP_SECRET Environment variable name for the Lark App Secret, used for credential parsing.
baseURL https://open.feishu.cn/open-apis Base URL for the Lark Open Platform API.
timeoutMs 30000 Timeout for each tool invocation.
enableSendMessage true Whether to register the send message tool.
enableReadDoc true Whether to register the document reading tool.
enableBitable true Whether to register Bitable read/write tools.
enableCallAgent false Whether to register the agent invocation tool (disabled by default).
enableInbound false Whether to enable Lark long-lived connection inbound functionality.

Example configuration snippet:

- id: lark-bridge
  name: dsh-lark-bridge
  config:
    appIdEnv: FEISHU_APP_ID
    appSecretEnv: FEISHU_APP_SECRET
    baseURL: https://open.feishu.cn/open-apis
    enableInbound: true

First Run and Credential Setup

On the first start, the Web UI displays a dialog that guides the user to enter the Lark App ID and App Secret. These values are stored through the credentials domain and do not appear in configuration responses. You can also skip UI input by setting the environment variables FEISHU_APP_ID and FEISHU_APP_SECRET.

Tool List

The plugin registers the following tools (listing only enabled items):

  • feishu_send_message: Sends text or card messages.
  • feishu_read_doc: Retrieves plain-text content from a document.
  • feishu_list_doc_blocks: Retrieves structured block-level content from a document (with heading prefixes).
  • feishu_list_bitable_tables: Lists all tables in a Bitable app.
  • feishu_bitable_list_records: Queries records in a Bitable (supports filtering and sorting).
  • feishu_bitable_create_record: Creates a single record.
  • feishu_bitable_update_record: Updates a single record (overwrite style).
  • feishu_bitable_batch_create_records: Bulk-creates records.
  • feishu_call_agent: Triggers a Lark bot or agent (indirect invocation, triggered by sending a message).
  • feishu_aily_start_skill: Directly starts an Aily (Lark AI Companion) skill.

Private Chat Inbound (Phase 2) Setup

To enable inbound functionality, set enableInbound: true in cordis.patch.yml.

Lark-side Configuration

  1. Use the same App ID / Secret as outbound (a single app is sufficient).
  2. Grant the app permissions: im:message, im:message:send_as_bot, and im:message.p2p_msg.
  3. Enable event subscriptions for long-lived connection event receipt and im.message.receive_v1.
  4. Start dsh web first, then save the long-lived connection settings in the Lark Open Platform.
  5. Note: only one long-lived connection is allowed per App; do not run multiple WS clients.

Workflow

With enableInbound: true, the plugin establishes a Lark long-lived connection (im.message.receive_v1) and processes only private chat (P2P) messages. The message flow is:
Lark P2P message → long-lived connection receives it → create/resume an Agent session → Agent performs the reply → reply via the IM API.

Notes and Limitations

  1. Private Chat Limitation: Inbound functionality currently supports only private chats and does not yet support groups.
  2. Non-streaming Replies: Inbound replies wait for the complete Agent execution to finish before sending text.
  3. Indirect Invocation: feishu_call_agent is an indirect invocation because Lark does not have a direct server-side execution API; a bot must be triggered by sending a message.
  4. Exclusive Long-lived Connection: Only one long-lived connection is allowed per App to avoid conflicts.
  5. Security Mechanism: appId and appSecret have a secret role (role('secret')) and do not appear in describe() responses.

Summary

dsh-lark-bridge is a bridge connecting DeepSeek Harness to the Lark ecosystem. With it, developers can directly inject Lark documents, sheets, and agent capabilities into the DSH toolbox to automate office workflows.