Introduction¶
DeepSeek Harness (DSH) uses a plugin-based architecture and is designed to extend functionality through plugins. dsh-dingtalk-channel is a plugin that connects the DingTalk IM bot channel to DSH. This plugin establishes connections using DingTalk’s official Stream mode (WebSocket long connection), so no public callback address or server webhook configuration is required. Each direct or group chat message can serve as an entry point to drive a complete agent, and replies are streamed back into the conversation.
Core Features¶
The following describes the main capabilities of this plugin.
One Agent per Session¶
The plugin creates an independent agent for each session. Session IDs are deterministically derived from the session key (format: ding-<chatId>), ensuring stability across restarts. By configuring sessionScope: chat-sender, each member in a shared group can have an independent agent.
Immediate Feedback and Silent Processing¶
DingTalk does not natively support typing indicators or thinking-process cards. The plugin provides immediate feedback by first sending an acknowledgment message, “🤔 Received.” While the agent calls tools such as bash and read, intermediate steps do not send chat messages. Only the final Markdown-formatted answer is sent. The thinking process is only implied by the acknowledgment or a thinking emoji.
Access Policy and Permissions¶
The plugin provides fine-grained access control.
- Direct/group chat restrictions: Restrict direct chat senders with
senderAllowlist, and restrict group conversations withgroupAllowlist. - Group chat mention: Configure
requireMentionto respond only when the bot is mentioned in group messages. - Approval workflow: Supports an approval process. When the agent requires approval, it sends an approval message in the conversation. Reply “Allow once” or “Reject” to settle the request.
- Permission scope: The chat agent has the same permissions as the host process, and can execute bash, read/write files, use git, perform network operations, and use skills.
Long Connection and Commands¶
- Long connection self-recovery: The SDK includes an automatic reconnection mechanism that attempts to recover after disconnection.
- Command support: Supports commands such as
/ping,/help,/status,/stop, and/new. - Observability: Events such as rejections, failures, and disconnections are reported via stderr.
Installation and Enablement¶
DingTalk Preparation¶
- Log in to the DingTalk Developer Console.
- Create an in-house enterprise application and record the ClientID and ClientSecret.
- Add a bot to application capabilities, complete the information, set the message receiving mode to Stream mode, and then publish the application.
- Add the bot to the target group or have members chat with it directly.
Install the Plugin¶
Run the following command in the terminal to install the plugin:
dsh plugin --profile web add github:ttmouse/dsh-dingtalk-channel
Configure Credentials¶
Add the configuration to ~/.dsh/profiles/web/cordis.patch.yml. If you need to use environment variables, you can use the !!js process.env.… syntax.
- id: dingtalk-channel
name: 'dsh-dingtalk-channel'
config:
clientId: 'ding...'
clientSecret: '...'
botName: '我的助手'
requireMention: true
# sessionScope: chat-sender
# preset: standard
# cwd: /path/to/workspace
Start DSH:
dsh web
If the startup log shows that credential verification passed, the connection is successful. In DingTalk, send /ping to the bot in a direct message and you should receive pong.
Typical Usage¶
Basic Conversation¶
After configuring clientId, clientSecret, and botName, you can interact with the agent through chat. Tools can be mounted onto the session agent via a preset.
Multi-user in Shared Groups¶
In a shared group, if you want each person to have an independent agent, set sessionScope: chat-sender in the configuration. The plugin then generates an independent session key for each sender, so each person gets their own agent.
Approval Operations¶
When the agent needs to perform a sensitive operation (such as an approval action), it initiates an approval request in the chat. You can directly reply “Allow once” or “Reject” to control the process.
Notes¶
- Permission risk: The chat agent has the same permissions as the host process, including executing bash commands and reading/writing files. Use it only in trusted environments or groups.
- Feature limitations: DingTalk does not natively support visualization of the thinking process, and tool invocation progress is not directly displayed in the chat. Forwarding images and files is currently not supported. QR-code registration is not supported; you must create the application manually in the backend.
- Workspace switching: Functions such as
/cd,/model use, and/wsfor workspace switching and hot model switching are currently not supported. - Default configuration: The
ask_user_questionandexit_plan_modetools are disabled by default. Approvals are settled by replying in the conversation.
License¶
This plugin follows the MIT license.