Preface

The core idea of DeepSeek Harness (DSH) is “everything is a plugin.” When developing agents for instant messaging (IM) scenarios, connecting an agent to WeCom (Enterprise WeChat) is a common requirement. The dsh-wecom plugin uses the aibot WebSocket gateway to turn DeepSeek Harness agents into assistants that can have two-way conversations in WeCom. It does not require a public address or a self-hosted application callback; you only need the smart bot’s bot_id and secret. This plugin is maintained by michaelcode-wang and licensed under the MIT License.

Core Features

  • WeCom persistent connection: Establishes a WebSocket persistent connection to wss://openws.work.weixin.qq.com, and automatically reconnects with backoff after disconnection.
  • Independent session management: Each chat window corresponds to an independent agent session, preserving multi-turn context and automatically releasing resources after idle periods.
  • Access control: Controls who can drive the agent via the allowedUserIds allowlist.
  • Rich text support: Supports Markdown replies and automatically splits overly long messages (default 4000 characters).
  • Chat commands: Supports instructions such as /help, /reset, and /status.

Prerequisites

  1. WeCom smart bot: Create a “smart bot” in the WeCom admin console and obtain the bot_id and secret.
  2. Preset Roster: The im profile itself does not include a Web layer, and the default agent-presets are provided by dsh-web-app. If you want to mount a preset for the agent, you need to manually insert the roster into the im profile configuration.

Installation and Activation

Use the official installation command to add the plugin:

dsh plugin --profile im add dsh-wecom

After installation, configure it in $DSH_HOME/profiles/im/cordis.patch.yml.

Configuration

Open $DSH_HOME/profiles/im/cordis.patch.yml and modify it according to the following steps:

  1. Insert the preset roster: Because the im profile lacks a Web layer, you must manually complete the roster configuration.
  2. Enable the plugin: Declare the plugin ID and configure the connection parameters.
# 1) 插入 preset roster
- insert:
    - id: agent-presets
      name: '@deepseek-ai/dsh-agent-presets'
      config:
        default: taibai

# 2) 启用本插件
- id: dsh-wecom
  disabled: false
  config:
    botId: '你的机器人ID'
    secret: '你的机器人密钥'
    allowedUserIds: ['你的企业微信userid']
    agent:
      preset: taibai

After configuration, start the DSH IM profile:

dsh --profile im

It is recommended to run it as a resident service using launchd or systemd.

Configuration Options

Key Default Description
enabled true Master switch
botId '' WeCom smart bot ID
secret '' WeCom smart bot secret (write-only)
websocketUrl wss://openws.work.weixin.qq.com WebSocket gateway address
allowedUserIds [] Allowlist of userids permitted to chat; empty means everyone
agent.preset taibai Mounted agent preset
agent.cwd '' agent working directory (default process cwd)
agent.provider / agent.model '' Model override; empty uses deployment default
agent.maxMessageLength 4000 Maximum characters in a single outbound message
agent.idleTimeoutMs 1800000 How long to let the chat idle before releasing the agent (0=never)

Security Notes

  • The allowlist is mandatory: Be sure to configure allowedUserIds. If left empty, any WeCom user can drive your agent to execute host tools, which poses security risks.
  • Secret protection: The secret configuration option is marked as role('secret') and will not be echoed in the browser interface.

Use Cases and Notes

The plugin protocol is ported from Hermes Agent. Before use, make sure the environment meets the following conditions:
- Node.js version >= 22
- DeepSeek Harness and its related dependencies are installed

The plugin runs with the permissions of the current DSH process. It is recommended to review the source code and license before use.

Conclusion

dsh-wecom provides a standardized way to extend the intelligent capabilities of DeepSeek Harness to WeCom IM scenarios. By configuring the preset roster and allowedUserIds, you can quickly build a secure, private enterprise-grade intelligent assistant.