Open-source project
larksuite/openclaw-lark avatar
larksuite/openclaw-lark

The Lark plugin for OpenClaw is the one README that tells you not to use it in group chats

飞书官方出品的 OpenClaw 飞书/Lark Channel 插件

2,383 stars312 forksTypeScriptMIT

At a glance

What is it?
Official Lark support, a capability table covering messages, docs, bases, sheets, calendar and tasks, and a warning section long enough that the security posture is the most specified part of the project.
Who is it for?
This plugin is two products in one repository. There is a capable Lark integration, with a capability table covering six product families and interactive cards that stream status into the message thread, and there is a security stance that most integrations of this class do not publish.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 77 days ago.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 28, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What the capability table actually covers

The README's feature section is a table, and the table is the honest summary of the project. Messenger covers reading group and direct message history, thread replies, sending messages, replying to messages, searching messages, and downloading images and files. Docs covers creating, updating and reading documents. Base covers creating and managing bases, tables, fields and records with CRUD, batch operations and advanced filtering, plus views. Sheets covers creating, editing and viewing spreadsheets. Calendar covers creating, querying, updating, deleting and searching events, managing attendees and checking free/busy status. Tasks covers creating, querying, updating and completing tasks, plus lists, subtasks and comments.

Read as a list, that is the whole Lark workspace surface an agent could plausibly need. Read as a risk, it is the same list, because every row is a write operation against shared business data under a single set of granted permissions.

Four features sit outside that table. Interactive cards give real-time status updates in three states, thinking, generating and complete, plus confirmation buttons for sensitive operations. Streaming responses push live text into the message card rather than waiting for a finished message. Permission policies give separate access control for direct messages and group chats. Advanced group configuration adds per-group allowlists, skill bindings and custom system prompts.

That last item is the one that gives the permission warning its meaning. Per-group system prompts means the behaviour of your agent in a given chat can be configured independently, which is a legitimate power feature and also the exact mechanism by which a group member could talk it into doing something the direct chat never would.

The warning section is the most detailed part of the README

A plugin whose README contains a section headed Security and Risk Warnings, marked as something to read before use, is unusual, and the contents are unusually blunt.

It says the plugin integrates with OpenClaw's AI automation and carries inherent risks such as model hallucinations, unpredictable execution and prompt injection. It says that after you authorize Lark permissions, OpenClaw will act under your user identity within the authorized scope, which may lead to sensitive data leakage or unauthorized operations. It says default protections are enabled at multiple layers but that the risks still exist, and that you should not proactively modify any default security settings, because relaxing restrictions raises the risk and you bear the consequences.

Then the concrete recommendation: use the Lark bot connected to OpenClaw as a private conversational assistant, and do not add it to group chats or allow other users to interact with it, to avoid abuse of permissions or data leakage. The README ends that section by saying that by using the plugin you are deemed to voluntarily assume all related responsibilities.

That last framing is what you are agreeing to. The plugin runs with your identity, so every action it takes is an action taken as you, in every system the permission grant reaches. The disclaimer also links the Feishu and Lark privacy policies, user terms, and the Feishu store app service provider security management specifications, since running the software means calling the Lark Open Platform APIs under agreements you are required to comply with.

Installation has a version contradiction worth resolving first

Requirements are Node.js v22 or higher, and OpenClaw installed and working, with details at the openclaw website. The version note then says OpenClaw must be 2026.2.26 or higher, tells you to check with `openclaw -v`, warns that a lower version may cause issues, and gives the upgrade command:

bash
npm install -g openclaw

Here is the problem. The README floor is 2026.2.26, and `package.json` declares a peer dependency of `openclaw` at `>=2026.5.4`. Those are different numbers and the package manifest is the one your installer enforces.

There is a second, softer version inconsistency. The dev dependency on `openclaw` is `^2026.4.9`, which is below both stated floors, and it is marked optional in `peerDependenciesMeta`, so the plugin is installable without OpenClaw present at all. That combination is defensible for a channel plugin that is loaded by the host rather than by a user's project, but it means the README's stated requirement is advisory and the manifest's floor is real.

The published version is `2026.7.9` and the package manager is pinned to pnpm 10.32.1. The install path is a global npm install of the host, not of this plugin, which is unusual to see stated that way: the plugin is picked up by OpenClaw through its plugin manifest, and the README's own usage guide is a Lark document rather than anything in the repository.

The package layout says this is a real TypeScript project

The tree shows a conventional, well-organised TypeScript build. `index.ts` is the entry point, `src/` holds the implementation, and `tests/` sits beside it. `vitest.config.ts` and a `test` script running `vitest run` mean the test suite exists. `tsconfig.json` with a `typecheck` script running `tsc --noEmit` means types are checked in isolation from the build.

The build tool is tsdown, configured in `tsdown.config.ts`, and the npm `files` array shows exactly what ships: `bin/`, `dist/`, `skills/`, `secret-contract-api.js`, `openclaw.plugin.json`, `README.md` and `LICENSE`. The exports map publishes types at `dist/index.d.mts` and the implementation at `dist/index.mjs`, and there is a binary entry named `openclaw-lark` pointing at `bin/openclaw-lark.js`. Module format is ESM only.

Two files are worth naming individually. `openclaw.plugin.json` is how the host discovers the plugin. `secret-contract-api.ts` and its compiled `secret-contract-api.js` are both in the tree and both in the shipped files list, and the name describes a contract for credential handling that the plugin exposes. Shipping a compiled copy alongside the TypeScript source is a deliberate choice, since it means the contract is consumable without a build step.

Runtime dependencies are modest and tell you the scope: the Lark Node SDK at `^1.64.0`, typebox and zod for schema validation, `image-size` for handling downloaded attachments, and `undici-types`. Development tooling is ESLint with the import and node plugins, Prettier, TypeScript, tsdown and vitest. `skills/` shipping in the package is a reminder that this plugin carries its own agent-facing instructions, not only code.

How to read the maintenance numbers

The repository has 2,383 stars, 312 forks and 313 open issues, with the default branch `main`, MIT licensed, no homepage, and the last push on 2026-07-22.

Three hundred and thirteen open issues is roughly one open issue per thirteen stars, which reads badly in isolation and better in context. An agent plugin is a large surface of unpredictable behaviour, and people file issues when their agent did something strange rather than when they want a feature. It is a support queue, not a backlog.

Two other numbers are more informative. The fork ratio of 312 forks against 2,383 stars is about thirteen percent, which for an official first-party plugin is high and usually means people are forking to adjust group configuration, permission policies or skill bindings rather than to contribute upstream. And there are no published GitHub releases, even though the npm package is versioned on a date scheme at 2026.7.9, which means versioning happens on npm and the repository has no release page to check.

One small inconsistency is worth noting so you do not chase it. The contributing section directs issues and pull requests to a repository path with a different suffix from this repository's own name. Following those links may land somewhere other than where you expect, so check before filing.

What you are really evaluating is the security posture described earlier, not the star count. A first-party plugin that publishes an unusually long risk section and tells you to keep it out of group chats has made a deliberate choice about what kind of user it is for.

Editorial conclusion

This plugin is two products in one repository. There is a capable Lark integration, with a capability table covering six product families and interactive cards that stream status into the message thread, and there is a security stance that most integrations of this class do not publish. The README names hallucination, unpredictable execution and prompt injection as inherent, states that the agent acts under your user identity once permissions are granted, and recommends keeping the bot in direct conversations only. The 313 open issues against 2,383 stars will read differently depending on whether the repo is seen as a fast-moving integration surface or as an under-maintained one, and the July push date argues for the first reading. The version constraint discrepancy is the practical thing to sort out before you install: the README asks for OpenClaw 2026.2.26 or newer while the package declares a peer dependency of 2026.5.4 or newer, and the declared floor is the one that will actually be enforced.

Frequently asked questions

How do I install the Lark CLI?

The README does not describe a Lark CLI, so that question is likely about a different product. What this repository documents is the prerequisite host: Node.js v22 or higher, and OpenClaw installed globally with `npm install -g openclaw`. The README states OpenClaw 2026.2.26 or newer is needed, while package.json declares a peer dependency of `openclaw` at `>=2026.5.4`, so check the installed version with `openclaw -v` before connecting the plugin.

What can this plugin do once it is authorized?

The capability table covers reading and sending messages including thread replies and search, creating and reading docs, managing bases with tables, fields, records and views, creating and editing sheets, managing calendars and events with attendees and free/busy checks, and managing tasks, lists, subtasks and comments. Interactive cards add live status and confirmation buttons, and per-group configuration adds allowlists, skill bindings and custom system prompts.

Should I add this plugin to a group chat?

The README recommends against it. It says to use the bot as a private conversational assistant and not to add it to group chats or let other users interact with it, in order to avoid abuse of permissions or data leakage, and it advises against modifying any default security settings.

Under whose identity does the agent act?

Yours. The README states that after you authorize Lark and Feishu permissions, OpenClaw will act under your user identity within the authorized scope, which it identifies as a route to sensitive data leakage and unauthorized operations.

Who publishes this plugin?

The README describes it as the official Lark and Feishu plugin for OpenClaw, developed and maintained by the Lark and Feishu Open Platform team, and it is published to npm as `@larksuite/openclaw-lark` under the MIT licence. Version at time of writing is 2026.7.9.

Official sources

  1. Issues
  2. larksuite/openclaw-lark on GitHub
  3. License: MIT
  4. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/larksuite-openclaw-lark.svg)](https://hysenlabs.com/projects/larksuite-openclaw-lark)