Introduction¶
DeepSeek Harness (DSH) focuses on local Agent execution and tool invocation. In remote or mobile scenarios, directly controlling a local Agent usually requires configuring a public port or a tunnel. The dsh-feishu-channel plugin receives commands over Feishu’s official WebSocket long-lived connection, connecting the capabilities of a local DSH Agent to Feishu. It does not listen on a public port and sends text responses via the Feishu Open API. It is suitable for development scenarios that require session reuse and secure approval through Feishu.
Core Capabilities¶
The plugin receives events over Feishu’s official WebSocket long-lived connection and does not listen on a public port on the local machine. It implements the following features:
- Session reuse and binding: After binding a project directory, it reuses the same DSH Agent session, and the desktop side can see the same session.
- Command set: The following control commands are supported:
/project /absolute/path/to/project: Bind a project directory./status: View the current status./cancel: Cancel a running task./approve <id>: Approve a high-risk tool call./deny <id>: Deny a high-risk tool call./new: Clear the current session-level model selection and reset the session./help: Display help information.
- Security approval mechanism: High-risk tool calls (such as file deletion, external writes, forced Git operations, and system-level commands) require one-time approval. Approval expires after 10 minutes by default. Cancellation, disconnection, or stopping the plugin is treated as a denial.
- State recovery: After restart, a saved session is restored. If restoration fails, it does not silently create a replacement session; use
/newto explicitly reset. - Output limits: Only phase summaries and the final result (text) are returned. Tool parameters, file contents, environment variables, or the complete model stream are not sent.
- Configuration whitelist: For private chats, configure
allowedOpenIds. For group chats, configure the sender’sopen_idand the group’schat_id.
Installation and Credential Configuration¶
The plugin depends on @larksuiteoapi/node-sdk and requires Node.js version >= 22. Install it through the bundle mechanism of the DSH ecosystem (for specific installation instructions, refer to the dsh field configuration in the project package.json).
Before use, configure Feishu credentials. The App ID and App Secret are read only through the DSH credential service. Plugin configuration and state files store only references, not credential values:
dsh credentials set FEISHU_APP_ID <your-app-id>
dsh credentials set FEISHU_APP_SECRET <your-app-secret>
The default reference names must remain FEISHU_APP_ID and FEISHU_APP_SECRET.
Configuration and Security¶
Configure whitelists and allowed project root directories in the Cordis patch of the web profile. All lists default to empty. An empty list rejects the source or project binding:
- insert:
- id: feishu-channel
name: dsh-feishu-channel
config:
allowedOpenIds: [ou_example]
allowedChatIds: [oc_example]
allowedProjectRoots:
- /Users/example/Projects
agentPreset: restricted
Security boundaries:
* Whitelisted members have all capabilities of the selected Agent preset on the local machine. Treat Feishu access as handing the terminal to a whitelisted member.
* It is recommended to use a restricted preset and configure only the necessary allowedProjectRoots.
* The plugin enforces workspace-write and ask before creating or restoring a session. An existing live Agent that cannot be proven to be managed by the plugin will not be reused.
* File deletion, external writes, and similar actions require one-time approval.
* An approval token can be used only once by the original chat and cannot be reused across chats.
* stateFile can only be located within the cache directory under the DSH home directory.
Typical Usage¶
Enter the following in a Feishu chat window:
/project /absolute/path/to/project
Please modify a file and run the tests
/status
/cancel
/approve <id>
/deny <id>
/new
/help
Applicable Scenarios and Notes¶
This plugin is suitable for scenarios that require safely invoking a local DSH Agent through Feishu. Because the permission model is whitelist-based, check the source code and license (MIT) before installing. If the App Secret has been leaked, rotate it immediately on the Feishu Open Platform and update it through the DSH credential service.