Agent skill

Feishu Openapi Skill

by holon-run in holon-run/uxc

Operate Feishu or Lark IM APIs through UXC with a curated OpenAPI schema, tenant-token bearer auth, and chat/message guardrails.

MITAuto-check passedBackend & APIs

Install Feishu Openapi Skill

skills CLI
$ npx skills add holon-run/uxc --skill feishu-openapi-skill -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install holon-run/uxc feishu-openapi-skill --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/holon-run/uxc.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/feishu-openapi-skill .claude/skills/feishu-openapi-skill && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
feishu-openapi-skill
GitHub stars
116
Token cost
~2.3k tokens
SKILL.md length
782 words
Files
7 (incl. scripts, references)
Skills in repo
62
Repo updated
First seen
Licence
MIT

At a glance

Operate Feishu or Lark IM APIs through UXC with a curated OpenAPI schema, tenant-token bearer auth, and chat/message guardrails.

  • Works in 5 steps: Use the fixed link command by default → Inspect operation schema first → Prefer read/setup validation before writes → …
  • Tasks that involve Messaging and chat bots
  • SKILL.md covers Prerequisites, Scope, Subscribe Status and Endpoint Choice, plus 5 more sections
  • Runs Python and Shell scripts from its folder; calls curl; reaches open.feishu.cn and open.larksuite.com; needs FEISHU_APP_SECRET and FEISHU_TENANT_ACCESS_TOKEN

What it does

Feishu Openapi Skill is an agent skill from holon-run/uxc. Operate Feishu or Lark IM APIs through UXC with a curated OpenAPI schema, tenant-token bearer auth, and chat/message guardrails.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `agents/openai.yaml`, `references/feishu-im.openapi.json` and `references/feishu-openapi.overlay.json`).

It sits in Backend & APIs, covering Messaging and chat bots and OpenAPI specifications. It works with Feishu (Lark) and OpenAPI. The repository describes itself as: A unified CLI for discovering and invoking tools across OpenAPI, MCP, GraphQL, gRPC, and JSON-RPC. The licence is MIT.

When your agent uses it

  • Tasks that involve Messaging and chat bots
  • Tasks that involve OpenAPI specifications

Example prompts

  • “/feishu-openapi-skill”

Requirements

  • Python 3
  • A Bash shell
  • A credential in FEISHU_APP_SECRET
  • A credential in FEISHU_TENANT_ACCESS_TOKEN

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Use the fixed link command by default
  2. Inspect operation schema first
  3. Prefer read/setup validation before writes
  4. Execute with key/value or positional JSON
  5. For inbound message intake, use uxc subscribe directly

What it can do on your machine

Read from SKILL.md and the folder at commit 562d47c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python and Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • open.feishu.cn
    • open.larksuite.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • FEISHU_APP_SECRET
    • FEISHU_TENANT_ACCESS_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Feishu Openapi Skill loads about 2.3k tokens when it runs, and up to ~54k if it reads all its reference files. Until then it costs about 37 tokens; SKILL.md has 782 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~54k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from holon-run/uxc at commit 562d47c, republished under its MIT licence (© holon-run). 782 words, ~2,329 tokens.

Download SKILL.mdSave it as .claude/skills/feishu-openapi-skill/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
feishu-openapi-skill
description
Operate Feishu or Lark IM APIs through UXC with a curated OpenAPI schema, tenant-token bearer auth, and chat/message guardrails.

Feishu / Lark IM Skill

Use this skill to run Feishu or Lark IM operations through uxc + OpenAPI.

Reuse the uxc skill for shared execution, auth, and error-handling guidance.

Prerequisites

  • uxc is installed and available in PATH.
  • Network access to https://open.feishu.cn/open-apis or https://open.larksuite.com/open-apis.
  • Access to the curated OpenAPI schema URL:
    • https://raw.githubusercontent.com/holon-run/uxc/main/skills/feishu-openapi-skill/references/feishu-im.openapi.json
  • A Feishu or Lark app with bot capability enabled.
  • A Feishu or Lark app app_id + app_secret, or a current tenant_access_token if you are using the manual fallback path.

Scope

This skill covers an IM-focused request/response surface:

  • bot identity lookup
  • chat lookup
  • chat member lookup
  • image and file upload for IM sends
  • message send and reply
  • selected message history reads
  • basic user lookup through contact APIs

This skill does not cover:

  • docs, bitable, approval, or non-IM product families
  • the full Feishu or Lark Open Platform surface

Subscribe Status

Feishu and Lark expose event-delivery models beyond plain request/response APIs, including long-connection event delivery in the platform ecosystem.

Current uxc subscribe status:

  • request/response IM operations are validated
  • inbound message intake is validated through the built-in feishu-long-connection transport
  • live validation confirmed real im.message.receive_v1 events delivered into the subscribe sink for a p2p bot chat

Important runtime notes:

  • feishu-long-connection is a provider-aware transport inside uxc subscribe; it is not a plain raw WebSocket stream
  • the runtime opens a temporary WebSocket URL from /callback/ws/endpoint
  • frames are protobuf binary messages, not text JSON
  • the runtime sends required event acknowledgements and ping control frames automatically

Endpoint Choice

This schema works against either Feishu or Lark Open Platform base URLs:

  • China / Feishu default: https://open.feishu.cn/open-apis
  • International / Lark alternative: https://open.larksuite.com/open-apis

The fixed link example below uses Feishu. For Lark, use the same schema URL against the Lark base host.

Authentication

Feishu and Lark service-side APIs use Authorization: Bearer <tenant_access_token> for these operations.

Preferred setup is to store app_id + app_secret as credential fields and let uxc auth bootstrap fetch and refresh the short-lived tenant token automatically.

Feishu bootstrap-managed setup:

bash
uxc auth credential set feishu-tenant \
  --auth-type bearer \
  --field app_id=env:FEISHU_APP_ID \
  --field app_secret=env:FEISHU_APP_SECRET

uxc auth bootstrap set feishu-tenant \
  --token-endpoint https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal \
  --header 'Content-Type=application/json; charset=utf-8' \
  --request-json '{"app_id":"{{field:app_id}}","app_secret":"{{field:app_secret}}"}' \
  --access-token-pointer /tenant_access_token \
  --expires-in-pointer /expire \
  --success-code-pointer /code \
  --success-code-value 0

uxc auth binding add \
  --id feishu-tenant \
  --host open.feishu.cn \
  --path-prefix /open-apis \
  --scheme https \
  --credential feishu-tenant \
  --priority 100

For Lark, use the same bootstrap shape against the Lark host and bind the credential to open.larksuite.com.

To use long-connection subscribe, the credential still needs app_id and app_secret fields because the transport opens its own temporary event URL outside the normal bearer-token request path.

Manual fallback if you already have a tenant token:

bash
curl -sS https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal \
  -H 'Content-Type: application/json; charset=utf-8' \
  -d '{"app_id":"cli_xxx","app_secret":"xxxx"}'

Lark uses the same path shape on the Lark host:

bash
curl -sS https://open.larksuite.com/open-apis/auth/v3/tenant_access_token/internal \
  -H 'Content-Type: application/json; charset=utf-8' \
  -d '{"app_id":"cli_xxx","app_secret":"xxxx"}'

Configure one bearer credential and bind it to the Feishu API host:

bash
uxc auth credential set feishu-tenant \
  --auth-type bearer \
  --secret-env FEISHU_TENANT_ACCESS_TOKEN

uxc auth binding add \
  --id feishu-tenant \
  --host open.feishu.cn \
  --path-prefix /open-apis \
  --scheme https \
  --credential feishu-tenant \
  --priority 100

For Lark, create the same binding against open.larksuite.com:

bash
uxc auth binding add \
  --id lark-tenant \
  --host open.larksuite.com \
  --path-prefix /open-apis \
  --scheme https \
  --credential feishu-tenant \
  --priority 100

Inspect or pre-warm bootstrap state when auth looks wrong:

bash
uxc auth bootstrap info feishu-tenant
uxc auth bootstrap refresh feishu-tenant

Validate the active binding when auth looks wrong:

bash
uxc auth binding match https://open.feishu.cn/open-apis
Show full SKILL.md (365 more words)Show less

Core Workflow

  1. Use the fixed link command by default:

    • command -v feishu-openapi-cli
    • If missing, create it: uxc link feishu-openapi-cli https://open.feishu.cn/open-apis --schema-url https://raw.githubusercontent.com/holon-run/uxc/main/skills/feishu-openapi-skill/references/feishu-im.openapi.json
    • feishu-openapi-cli -h
  2. Inspect operation schema first:

    • feishu-openapi-cli get:/bot/v3/info -h
    • feishu-openapi-cli get:/im/v1/chats -h
    • feishu-openapi-cli post:/im/v1/images -h
    • feishu-openapi-cli post:/im/v1/files -h
    • feishu-openapi-cli post:/im/v1/messages -h
    • feishu-openapi-cli get:/im/v1/messages -h
  3. Prefer read/setup validation before writes:

    • feishu-openapi-cli get:/bot/v3/info
    • feishu-openapi-cli get:/im/v1/chats page_size=20
    • feishu-openapi-cli get:/im/v1/chats/{chat_id} chat_id=oc_xxx
    • feishu-openapi-cli get:/contact/v3/users/{user_id} user_id=ou_xxx user_id_type=open_id
  4. Execute with key/value or positional JSON:

    • key/value: feishu-openapi-cli get:/im/v1/messages container_id_type=chat container_id=oc_xxx page_size=20
    • multipart upload: feishu-openapi-cli post:/im/v1/images image_type=message image=/tmp/example.png
    • positional JSON: feishu-openapi-cli post:/im/v1/messages receive_id_type=chat_id '{"receive_id":"oc_xxx","msg_type":"text","content":"{\"text\":\"Hello from UXC\"}"}'
  5. For inbound message intake, use uxc subscribe directly:

    • uxc subscribe start https://open.feishu.cn/open-apis --transport feishu-long-connection --auth feishu-tenant --sink file:$HOME/.uxc/subscriptions/feishu.ndjson
    • send a bot-visible message, then inspect the sink for header.event_type = "im.message.receive_v1"

Operation Groups

Bot Identity
  • get:/bot/v3/info
Chat Reads
  • get:/im/v1/chats
  • get:/im/v1/chats/{chat_id}
  • get:/im/v1/chats/{chat_id}/members
Message Reads / Writes
  • get:/im/v1/messages
  • get:/im/v1/messages/{message_id}
  • post:/im/v1/messages
  • post:/im/v1/messages/{message_id}/reply
Uploads
  • post:/im/v1/images
  • post:/im/v1/files
User Lookup
  • get:/contact/v3/users/{user_id}
  • post:/contact/v3/users/batch_get_id

Guardrails

  • Keep automation on the JSON output envelope; do not use --text.
  • Parse stable fields first: ok, kind, protocol, data, error.
  • Prefer uxc auth bootstrap over manual token management. Manual tenant_access_token setup is still supported as a fallback.
  • get:/bot/v3/info requires a tenant token for an app with bot capability enabled, but does not require additional API scopes.
  • feishu-long-connection requires the app credential fields app_id and app_secret; a plain bearer-only credential is not enough for event intake.
  • post:/im/v1/images and post:/im/v1/files use multipart/form-data. File fields must be local path strings; help output marks them as multipart file fields.
  • post:/im/v1/messages requires the receive_id_type query parameter and the body content field is a JSON-encoded string, not a nested JSON object.
  • Upload first, then send by returned key:
    • image sends use msg_type=image with content='{\"image_key\":\"img_xxx\"}'
    • file sends use msg_type=file with content='{\"file_key\":\"file_xxx\"}'
  • post:/im/v1/messages/{message_id}/reply is for explicit replies to an existing message. Treat it as a high-risk write.
  • History reads only return chats and messages visible to the bot/app configuration. Auth success does not imply access to every chat.
  • Long-connection message intake is validated for Feishu bot chats; webhook-style callbacks and non-IM products are still out of scope.
  • feishu-openapi-cli <operation> ... is equivalent to uxc https://open.feishu.cn/open-apis --schema-url <feishu_openapi_schema> <operation> ....

References

© holon-run, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in skills/feishu-openapi-skill of holon-run/uxc.

  • SKILL.md
  • agents/openai.yaml
  • references/feishu-im.openapi.json
  • references/feishu-openapi.overlay.json
  • references/usage-patterns.md
  • scripts/generate_openapi.py
  • scripts/validate.sh

Open the folder on GitHubat commit 562d47c

Compare with similar skills

Feishu Openapi Skill next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Feishu Openapi Skill compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Feishu Openapi Skill this skillholon-run/uxc116—~2.3kAutomated safety check: PassMIT
Lark Openapi Explorerappleweiping/WEIPING_WIKI1194 repos~788Automated safety check: PassMIT
SpecfusionLiangNiang/OpenMantis110—~2.1kAutomated safety check: NotesApache-2.0
Feishucodewhale-hq/Codewhale41k—~413Automated safety check: PassMIT
Lark Contactrongxinzy/RongxinAI1542 repos~479Automated safety check: PassAGPL-3.0
Lark Contactappleweiping/WEIPING_WIKI1191 repos~403Automated safety check: PassMIT

Similar skills

  • Lark Openapi Explorer

    appleweiping/WEIPING_WIKI

    飞书/Lark 原生 OpenAPI 探索:从官方文档库中挖掘未经 CLI 封装的原生 OpenAPI 接口。当用户的需求无法被现有 lark- skill 或 lark-cli 已注册命令满足,需要查找并调用原生飞书 OpenAPI 时使用。

    119 GitHub starsUsed in 4 repos~788 tokens
    Backend & APIsAuto-check passed
  • Specfusion

    LiangNiang/OpenMantis

    企业微信 飞书 钉钉 淘宝 小红书 抖音电商 微信小程序 微信小店 拼多多 有赞 微信支付 支付宝 京东 SHEIN 得物 火山引擎 阿里云百炼 泛微 北森 API文档搜索。

    110 GitHub stars~2.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Feishu

    codewhale-hq/Codewhale

    Work with Feishu or Lark bots, docs, sheets, bitables, approval flows, and OpenAPI/MCP setup without hardcoding credentials.

    41k GitHub stars~413 tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Lark Contact

    rongxinzy/RongxinAI

    飞书 / Lark 通讯录:按姓名 / 邮箱解析成 openid,或按 openid 反查姓名 / 部门 / 邮箱 / 联系方式 / 个人状态 / 签名。当用户提到某人姓名要下一步发消息 / 排日程,或拿到 openid 想查具体信息时使用。不负责部门树遍历、按部门列员工、组织架构图,这类需求走原生 OpenAPI。

    154 GitHub starsUsed in 2 repos~479 tokens
    Productivity & AutomationAuto-check passed
  • Lark Contact

    appleweiping/WEIPING_WIKI

    飞书 / Lark 通讯录,用于按姓名 / 邮箱把员工解析成 openid,以及按 openid 反查员工的姓名 / 部门 / 邮箱 / 联系方式。当用户说出某人姓名而下一步需要发消息 / 加群 / 排日程时,先用本 skill 把姓名换成 ID;当输出里出现 openid 需要展示成姓名给用户看,或用户直接询问某人的部门 / 邮箱 / 联系方式时,用本 skill…

    119 GitHub starsUsed in 1 repo~403 tokens
    Productivity & AutomationAuto-check passed
  • Lark Whiteboard

    appleweiping/WEIPING_WIKI

    飞书画板:查询和编辑飞书云文档中的画板。支持导出画板为预览图片、导出原始节点结构、使用 DSL(转成 OpenAPI 格式)、PlantUML/Mermaid 格式更新画板内容。

    119 GitHub stars~1.2k tokensUpdated 1 mo ago
    Productivity & AutomationAuto-check passed

More from holon-run/uxc

All 62 skills in this repo
  • Context7 MCP Skill

    holon-run/uxc

    Query up-to-date library documentation and code examples using Context7 MCP.

    116 GitHub stars~564 tokensUpdated 23 days ago
    Auto-check passed
  • Deepwiki MCP Skill

    holon-run/uxc

    Ask questions and read documentation about any GitHub repository using DeepWiki MCP.

    116 GitHub stars~700 tokensUpdated 23 days ago
    Auto-check passed
  • Operate Linear workspace issues, projects, and teams through Linear GraphQL API using UXC.

    116 GitHub stars~1.8k tokensUpdated 23 days ago
    Auto-check passed
  • Operate Notion Public API through UXC with a curated OpenAPI schema for search, block traversal, page reads, content writes, and data source/database inspection.

    116 GitHub stars~2.3k tokensUpdated 23 days ago
    Auto-check passed
  • Operate Alchemy Prices API reads through UXC with a curated OpenAPI schema, path-templated API-key auth, and read-first guardrails.

    116 GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Uxc

    holon-run/uxc

    Discover and call remote schema-exposed interfaces with UXC.

    116 GitHub stars~1.8k tokensUpdated 23 days ago
    Auto-check passed

Questions about Feishu Openapi Skill

What does Feishu Openapi Skill do?

Operate Feishu or Lark IM APIs through UXC with a curated OpenAPI schema, tenant-token bearer auth, and chat/message guardrails. Feishu Openapi Skill is an agent skill from holon-run/uxc. Operate Feishu or Lark IM APIs through UXC with a curated OpenAPI schema, tenant-token bearer auth, and chat/message guardrails.

When should I use Feishu Openapi Skill?

Feishu Openapi Skill fits situations like: tasks that involve Messaging and chat bots; tasks that involve OpenAPI specifications.

How do I install Feishu Openapi Skill in Claude Code?

Run `npx skills add holon-run/uxc --skill feishu-openapi-skill -a claude-code`. Or copy the skill folder (skills/feishu-openapi-skill in holon-run/uxc) into .claude/skills/feishu-openapi-skill in your project. Claude Code loads it when a task matches its description.

How do I install Feishu Openapi Skill in Codex?

Run `npx skills add holon-run/uxc --skill feishu-openapi-skill -a codex`. Or copy the skill folder (skills/feishu-openapi-skill in holon-run/uxc) into .agents/skills/feishu-openapi-skill in your project. Codex loads it when a task matches its description.

Can I use Feishu Openapi Skill in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add holon-run/uxc --skill feishu-openapi-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/feishu-openapi-skill, .gemini/skills/feishu-openapi-skill, .github/skills/feishu-openapi-skill and .opencode/skills/feishu-openapi-skill in your project.

What does Feishu Openapi Skill need to run?

Going by SKILL.md and its folder, Feishu Openapi Skill needs Python and a shell for the scripts in its folder, the command-line tools its instructions call (curl) and credentials named FEISHU_APP_SECRET and FEISHU_TENANT_ACCESS_TOKEN. Our summary lists: Python 3; A Bash shell; A credential in FEISHU_APP_SECRET; A credential in FEISHU_TENANT_ACCESS_TOKEN.

Does Feishu Openapi Skill access the network?

SKILL.md names 2 domains. In commands or code: open.feishu.cn and open.larksuite.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Feishu Openapi Skill safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Feishu Openapi Skill use?

Feishu Openapi Skill is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Feishu Openapi Skill use?

About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 52k tokens, read only when the agent opens those files.

What are the alternatives to Feishu Openapi Skill?

Skills that share tags, products or a category with Feishu Openapi Skill: Lark Openapi Explorer (appleweiping/WEIPING_WIKI, 119 stars), Specfusion (LiangNiang/OpenMantis, 110 stars), Feishu (codewhale-hq/Codewhale, 41k stars) and Lark Contact (rongxinzy/RongxinAI, 154 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Feishu Openapi Skill?

holon-run (a GitHub organization) maintains it in holon-run/uxc, which has 116 GitHub stars. The repository holds 62 skills in this directory. The repository was last updated on September 15, 2026.

Source: holon-run/uxc on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.