dsh-lark-bridge avatar

dsh-lark-bridge

Feishu (Lark) entry point for DeepSeek Harness: drive dsh agents from a Feishu bot with streaming cards, ask/approval buttons and attachments.

Plugin
Verification
L2 · Structured
Security
Medium
Health
Active
Trust
Silver

What it does

Feishu (Lark) entry point for DeepSeek Harness: drive dsh agents from a Feishu bot with streaming cards, ask/approval buttons and attachments.

Installation

dsh plugin --profile web add dsh-lark-bridge-2

Install method: npm · not yet tested in container (L3+)

Compatibility

DSH VersionStatus
not statedDeclared — not tested

Requirements

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

Security Report

Automated static scan, not manual review.

DSH.SOWARNINGSCAN8 FILES
e1cfe7
Automated review · daily
WARNING

No critical findings, but warning-level issues were detected (file writes, remote imports, base64 decoding, downloads).

0 critical·1 warning·5 info·8 files scanned
scanned commite1cfe700c1e82026-08-17
latest commite1cfe700c1e8

The scan result is only valid for the scanned commit. If the latest commit differs, the badge shows outdated until the daily pipeline rescans.

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk: Medium0 critical · 1 warning · 5 info

• Static heuristic scan: done (8 files)

• Dependency vulnerabilities: requires deep audit (L3+)

• Permission sandboxing: requires runtime testing (L4+)

Scan findings · 6

  • warningHTTP request to a raw IP addresslib/index.js:503
    this.logger.info(`[lark-bridge] mock transport listening on http://127.0.0.1:${this.port}`);
  • infoReads process.envlib/index.js:1349
    const appId = config.appId ?? process.env.LARK_APP_ID;
  • infoReads process.envlib/index.js:1350
    const appSecret = config.appSecret ?? process.env.LARK_APP_SECRET;
  • infoReads process.envlib/index.js:1354
    const workspace = resolve(config.workspace || process.env.LARK_WORKSPACE || process.cwd());
  • infoHardcoded IP addresslib/index.js:502
    await new Promise((done) => this.server.listen(this.port, "127.0.0.1", done));
  • infoHardcoded IP addresslib/index.js:503
    this.logger.info(`[lark-bridge] mock transport listening on http://127.0.0.1:${this.port}`);

Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-08-17 · activity: Active

• Repo created: 2026-08-17

• Stars: ★ 4 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/JMOKSZ/dsh-lark-bridge

Was this page helpful?