feishu

feishu is a skill for Claude Code, Codex from Hmbown/CodeWhale. It costs 33 tokens per session (400 once invoked), scanned A, original, MIT.

A guide for connecting Feishu or Lark—workplace collaboration platforms—to bots, documents, spreadsheets, databases, approvals, and their APIs.

In plain words
What is it for?
Use it to configure webhooks or API integrations for Feishu or Lark, or to build narrow tools for reading and writing supported workplace data.
Why use it?
It helps choose the correct service and credential setup while keeping app secrets and tokens out of source code.

Skill for Claude CodeCodex

About the project

Hmbown/CodeWhale is an open-source coding agent that runs in the terminal and is written in Rust. Developers use it to inspect repositories, edit files, run commands, and coordinate work with configurable model providers, skills, MCP servers, and approval controls; the catalogue entries extend its available workflows.

Hmbown/CodeWhale · 40,889 stars · on GitHub

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/hmbown/codewhale/feishu
Any agent
npx skills add Hmbown/CodeWhale --skill feishu
Clone the repo
git clone --depth 1 https://github.com/Hmbown/CodeWhale

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for feishu

README.md
[![agentmods](https://agentmods.dev/badge/skills/hmbown/codewhale/feishu.svg)](https://agentmods.dev/skills/hmbown/codewhale/feishu)
Your own site
<a href="https://agentmods.dev/skills/hmbown/codewhale/feishu"><img src="https://agentmods.dev/badge/skills/hmbown/codewhale/feishu.svg" alt="Measured on agentmods" height="20"></a>
Per session 33 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 400 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00033 $0.00400
Opus 5 $0.00016 $0.00200
Sonnet 5 $0.00007 $0.00080
Haiku 4.5 $0.00003 $0.00040

Measured 5d ago against content hash e3e20a53c526, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

feishu scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

crates/tui/assets/skills/feishu/SKILL.md · 45 lines

What it actually says

Feishu / Lark

Use this skill when the user asks for Feishu, Lark, or "飞书" integration work.

Ground Rules

  • Feishu China APIs use open.feishu.cn; Lark international APIs use open.larksuite.com.
  • Never hardcode app secrets, webhook secrets, tenant tokens, or user tokens. Use environment variables such as FEISHU_APP_ID, FEISHU_APP_SECRET, FEISHU_WEBHOOK_URL, and FEISHU_WEBHOOK_SECRET.
  • If credentials are unavailable, produce setup instructions or a local stub instead of pretending the integration is live.

Common Use Cases

  • Bot webhook messages
  • App access token and tenant access token flows
  • Docs, Sheets, Wiki, and Bitable reads/writes
  • Approval or workflow status updates
  • Feishu/Lark MCP server configuration

Workflow

  1. Clarify whether the target is Feishu or Lark.
  2. Identify the credential type: webhook, internal app, marketplace app, or OAuth user token.
  3. Prefer official OpenAPI endpoints and signed webhooks when secrets are configured.
  4. For MCP, build or configure a server that exposes narrow tools such as send_message, read_doc, append_sheet_row, or query_bitable.
  5. Register the MCP server with codewhale mcp add, then run codewhale mcp validate and codewhale mcp tools.
  6. Verify with a dry run, sandbox document, or read-back call before sending externally visible messages.

Ask for confirmation before sending messages, writing production documents, or changing approval/workflow state.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 45 lines · 33 tokens per session scan A e3e20a53c526

Subscribe to this mod's changes

feishu is a skill published in the GitHub repository Hmbown/CodeWhale (40,889 stars, last pushed 3d ago), licensed MIT. It adds 33 tokens to every session and 400 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.