Agent skill

Feishu Auth Request

by Ninglo in Ninglo/remotelab

飞书调用缺权限时,区分 Bot 应用权限、用户 OAuth 和资源访问权限;为缺少的 Bot scope 生成单独的权限申请页。适用于 99991672、permissionviolations 或用户要求申请应用权限。

MITAuto-check passedBackend & APIs

Install Feishu Auth Request

skills CLI
$ npx skills add Ninglo/remotelab --skill feishu-auth-request -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Ninglo/remotelab feishu-auth-request --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Ninglo/remotelab.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/feishu-auth-request .claude/skills/feishu-auth-request && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
feishu-auth-request
GitHub stars
108
Token cost
~456 tokens
SKILL.md length
105 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

飞书调用缺权限时,区分 Bot 应用权限、用户 OAuth 和资源访问权限;为缺少的 Bot scope 生成单独的权限申请页。适用于 99991672、permissionviolations 或用户要求申请应用权限。

  • Tasks that involve Messaging and chat bots
  • SKILL.md covers 缺 Bot 应用权限, 缺用户 OAuth 权限 and 回到原任务验收
  • Reaches open.feishu.cn
  • Tasks that involve OAuth and OpenID Connect

What it does

Feishu Auth Request is an agent skill from Ninglo/remotelab. 飞书调用缺权限时,区分 Bot 应用权限、用户 OAuth 和资源访问权限;为缺少的 Bot scope 生成单独的权限申请页。适用于 99991672、permissionviolations 或用户要求申请应用权限。

Its SKILL.md is about 460 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Messaging and chat bots and OAuth and OpenID Connect. It works with Feishu (Lark). The repository describes itself as: AI workbench for super-individuals — orchestrate agents, recover context, and ship agentic-native apps. The licence is MIT.

When your agent uses it

  • Tasks that involve Messaging and chat bots
  • Tasks that involve OAuth and OpenID Connect

Example prompts

  • “/feishu-auth-request”

What it can do on your machine

Read from SKILL.md and the folder at commit 138c2aa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • open.feishu.cn

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Feishu Auth Request loads about 456 tokens when it runs. Until then it costs about 33 tokens; SKILL.md has 105 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~33
When it runs · the whole SKILL.md, loaded when a task matches
~456

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Ninglo/remotelab at commit 138c2aa, republished under its MIT licence (© Ninglo). 105 words, ~456 tokens.

Download SKILL.mdSave it as .claude/skills/feishu-auth-request/SKILL.md (or your agent's skills folder).
name
feishu-auth-request
description
飞书调用缺权限时,区分 Bot 应用权限、用户 OAuth 和资源访问权限;为缺少的 Bot scope 生成单独的权限申请页。适用于 99991672、permission_violations 或用户要求申请应用权限。

飞书权限申请

先按 lark-shared 选已有的 lark-cli profile,核对 app ID、原操作应使用 Bot 还是用户身份、实际报错要求的精确 scope。资源本身拒绝访问(ACL)时,不能当作缺 scope。

缺 Bot 应用权限

把仅包含所需 scope 的飞书专用申请页发给应用所有者或管理员:

text
https://open.feishu.cn/page/scope-apply?clientID=<app_id>&scopes=<URL-encoded,comma-separated-scopes>

例如,要为应用 cli_xxx 申请 application:application:patch:

text
https://open.feishu.cn/page/scope-apply?clientID=cli_xxx&scopes=application%3Aapplication%3Apatch

多个 scope 用英文逗号连接后整体做 URL 编码。这个页面让所有者确认新增应用权限,并处理相应版本提交;需审核的权限仍要等审核。直接在当前对话发链接,不换成开发者后台扫码登录或用户 OAuth 链接。若页面提示 scope 不支持、身份不符或申请失败,以页面实际结果为准。

旧版 CLI 若给出 /app/<app_id>/auth,那是开发者后台入口,不能替代上述 Bot 权限申请页。

所有者确认后,用同一 Bot profile 读回应用配置和租户授权状态:

bash
lark-cli --profile <name> api GET /open-apis/application/v6/applications/<app_id> --as bot --params '{"lang":"zh_cn"}'
lark-cli --profile <name> api GET /open-apis/application/v6/scopes --as bot

确认目标 scope 的 token_types 包含 tenant,且租户的 grant_status=1,再重试原 Bot 操作。新增 scope、提交版本、审核通过、业务成功是四件事,不互相代替。

POST /open-apis/application/v6/scopes/apply 是另一种接口,只能申请应用已配置、租户尚未授权的权限。先用 GET /open-apis/application/v6/scopes 查到本次目标确实待授权时才调用。返回 212002 unauthorized scopes were empty 不妨碍用专用页面新增 Bot scope;不要反复提交空申请。

缺用户 OAuth 权限

仅当原操作本来就应以用户身份执行时,先查 auth status --json --verify 和 auth check。确实缺用户 scope,再按当前 CLI 的 auth login --help 发起最小范围的 auth login --scope <scope> --no-wait --json,交付验证链接,用户同意后完成同一次授权。用户 OAuth 不会补齐 Bot scope;不能为了绕过 Bot 权限报错悄悄切换到个人 token。

回到原任务验收

权限生效不等于回调已配置、事件已订阅或功能已成功。继续完成原操作和必要的独立版本变更,再核验实际结果。card.action.trigger 要回读回调配置,并用新发的卡片测试;旧卡片不能用于验收。

只用当前应用获授权的 profile,不输出 token 或 app secret,不扩大到其他应用,不把“链接已打开”说成“权限已批准”。

© Ninglo, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/feishu-auth-request of Ninglo/remotelab.

Open the folder on GitHubat commit 138c2aa

Compare with similar skills

Feishu Auth Request next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Feishu Auth Request compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Feishu Auth Request this skillNinglo/remotelab108—~456Automated safety check: PassMIT
Paper Feishu Digestchtc66/academic-skills360—~348Automated safety check: PassMIT
SpecfusionLiangNiang/OpenMantis110—~2.1kAutomated safety check: NotesApache-2.0
Caspian Connect DiscordTryCaspian/caspian-sdk973—~376Automated safety check: NotesApache-2.0
Google Chatsanjay3290/ai-skills431—~1.2kAutomated safety check: PassApache-2.0
Feishu Openapi Skillholon-run/uxc116—~2.3kAutomated safety check: PassMIT

Similar skills

  • Paper Feishu Digest

    chtc66/academic-skills

    monitor recent arxiv papers and produce a chinese digest when the user needs a filtered paper watchlist, a ranked update for agent or rag related topics, or an optional feishu webhook push from…

    360 GitHub stars~348 tokensUpdated 6 mo ago
    Backend & APIsAuto-check passed
  • Specfusion

    LiangNiang/OpenMantis

    企业微信 飞书 钉钉 淘宝 小红书 抖音电商 微信小程序 微信小店 拼多多 有赞 微信支付 支付宝 京东 SHEIN 得物 火山引擎 阿里云百炼 泛微 北森 API文档搜索。

    110 GitHub stars~2.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Caspian Connect Discord

    TryCaspian/caspian-sdk

    Connect Caspian Discord for OpenCode (install OAuth or BYO bot token), enable discord in caspian.json channels, and tell the user to restart.

    973 GitHub stars~376 tokensUpdated 1 mo ago
    Backend & APIsAuto-check: notes
  • Google Chat

    sanjay3290/ai-skills

    Interact with Google Chat - send, read, edit, delete and react to messages, share images and files, reply in threads, and manage spaces and DMs.

    431 GitHub stars~1.2k tokensUpdated 27 days ago
    Backend & APIsAuto-check passed
  • Operate Feishu or Lark IM APIs through UXC with a curated OpenAPI schema, tenant-token bearer auth, and chat/message guardrails.

    116 GitHub stars~2.3k tokensUpdated 23 days ago
    Backend & APIsAuto-check passed
  • Auth Tool Cloudbase

    LeoYeAI/openclaw-master-skills

    Use CloudBase Auth tool to configure and manage authentication providers for web applications - enable/disable login methods (SMS, Email, WeChat Open Platform, Google, Anonymous, Username/password…

    2.2k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check passed

More from Ninglo/remotelab

  • Social Publish

    Ninglo/remotelab

    根据用户明确的发布指令,将会话里的文字和配图适配并发布到已绑定的小红书和 X,保存逐平台回执、避免重复发布,处理一次性账号绑定和发布失败。普通聊天、只写草稿或只查资料时不发布。

    108 GitHub stars~744 tokensUpdated today
    Auto-check passed

Works with

Questions about Feishu Auth Request

What does Feishu Auth Request do?

飞书调用缺权限时,区分 Bot 应用权限、用户 OAuth 和资源访问权限;为缺少的 Bot scope 生成单独的权限申请页。适用于 99991672、permissionviolations 或用户要求申请应用权限。. Feishu Auth Request is an agent skill from Ninglo/remotelab.

When should I use Feishu Auth Request?

Feishu Auth Request fits situations like: tasks that involve Messaging and chat bots; tasks that involve OAuth and OpenID Connect.

How do I install Feishu Auth Request in Claude Code?

Run `npx skills add Ninglo/remotelab --skill feishu-auth-request -a claude-code`. Or copy the skill folder (skills/feishu-auth-request in Ninglo/remotelab) into .claude/skills/feishu-auth-request in your project. Claude Code loads it when a task matches its description.

How do I install Feishu Auth Request in Codex?

Run `npx skills add Ninglo/remotelab --skill feishu-auth-request -a codex`. Or copy the skill folder (skills/feishu-auth-request in Ninglo/remotelab) into .agents/skills/feishu-auth-request in your project. Codex loads it when a task matches its description.

Can I use Feishu Auth Request in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Ninglo/remotelab --skill feishu-auth-request -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/feishu-auth-request, .gemini/skills/feishu-auth-request, .github/skills/feishu-auth-request and .opencode/skills/feishu-auth-request in your project.

What does Feishu Auth Request need to run?

SKILL.md names no scripts, command-line tools or credentials: Feishu Auth Request is instructions for the agent only.

Does Feishu Auth Request access the network?

SKILL.md names 1 domain. In commands or code: open.feishu.cn; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Feishu Auth Request safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Feishu Auth Request use?

Feishu Auth Request is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Feishu Auth Request use?

About 456 tokens (SKILL.md is roughly 1.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Feishu Auth Request?

Skills that share tags, products or a category with Feishu Auth Request: Paper Feishu Digest (chtc66/academic-skills, 360 stars), Specfusion (LiangNiang/OpenMantis, 110 stars), Caspian Connect Discord (TryCaspian/caspian-sdk, 973 stars) and Google Chat (sanjay3290/ai-skills, 431 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Feishu Auth Request?

Ninglo (a GitHub user) maintains it in Ninglo/remotelab, which has 108 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 8, 2026.

Source: Ninglo/remotelab on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.