LARK / FEISHU WORKFLOW GUIDE

Lark and Feishu Agent Skills: Choose the Right Skill by Task

Lark and Feishu Agent Skills are not one general-purpose package. Each one routes work through a different lark-cli command family. Choose by the resource and action you need—document content, Drive files, structured Base data, Wiki organization, or approvals—instead of installing the entire collection. This is a task-fit guide, not a popularity ranking or runtime benchmark.

Published ORIGINAL · SOURCE-AWARE
01

A quick Lark Skill chooser

Match both the object and the operation. A Wiki page's body is document work; moving its node is Wiki work. A spreadsheet is not the same thing as a Base table. An approval request is not a general task-list item. These distinctions help avoid choosing a Skill that can reach the resource but does not own the requested action.

  • Read or edit a Feishu cloud document or mind note → lark-doc.
  • Find, copy, move, import, export, or inspect cloud files and folders → lark-drive.
  • Query or maintain Base tables, records, views, forms, or dashboards → lark-base.
  • Work with workbook cells, formulas, charts, or spreadsheet imports → lark-sheets.
  • Browse knowledge spaces, manage members, or move Wiki nodes → lark-wiki.
  • Find, inspect, start, or act on an approval workflow → lark-approval.
  • Configure lark-cli authentication or resolve identity and scopes → lark-shared.
02

Documents, Drive files, and Wiki pages have different jobs

lark-doc is the content workflow for Feishu cloud documents: fetch, create or import content, update document blocks, work with attachments, and handle mind notes. It routes document URLs by their resource path and token, so a supported Doubao document URL can still be a document task. Use it for the body of a document—not for general Drive organization, Base records, or Wiki membership.

lark-drive owns cloud-space files and folders: locating resources, copying or moving files, importing and exporting supported formats, and handling Drive-level metadata or permissions. It deliberately separates a native document's content from the file that stores or organizes it. For a Wiki URL that needs to be resolved to its underlying resource, Drive inspection may be part of the route; Wiki node and member changes belong to lark-wiki.

lark-wiki manages knowledge spaces, members, and node hierarchy. It can help organize or move nodes, but editing a document body is delegated to the relevant document Skill. Resolve the exact space, node, identity, and destination before changing hierarchy or access.

03

Choose Base or Sheets by the shape of the data

lark-base is for Feishu Base's structured business objects: tables, fields, records, views, forms, dashboards, workflows, roles, and BaseApp or Workspace structure. lark-sheets is for spreadsheet workbooks: cell values and formulas, formatting, filters, pivots, charts, and supported imports. If you are turning a local spreadsheet or Base snapshot into a cloud resource, start with the documented Drive import route; do not assume that an import and editing the resulting data are the same operation.

Both Skills can change shared business data. Resolve the exact Base, table, worksheet, row range, or field first. Preview small changes where possible, preserve existing structure, and verify the result by reading it back. Removing a form question can affect its underlying field and records, so confirm the specific behavior before making that change.

04

Approval workflows need a human decision boundary

lark-approval handles approval-specific work such as finding pending or completed instances, inspecting their details, searching approval definitions, and starting a native instance. It is not the general Feishu task manager: non-approval tasks belong to lark-task. The available operation depends on the definition, instance state, identity, and tenant permissions.

Reading a request is not the same as deciding it. Approve, reject, transfer, return, withdraw, or start an approval only when the user has explicitly requested that exact consequential action and the target instance or definition is clear. Use current operation references for parameters rather than guessing fields.

05

Treat lark-shared as a foundation, not another task Skill

lark-shared documents lark-cli setup, authentication, user-versus-bot identity, scopes, permissions, notices, and safety rules. A domain Skill may require it as a dependency or direct the Agent to it when authentication or access fails. Check the selected Skill's current dependency metadata and follow its progressive-loading instructions; do not preload every reference file for an unrelated task.

Identity matters: user and bot credentials can see different resources, and a successful request under the wrong identity may still return the wrong view of the workspace. Confirm the intended tenant and identity before relying on results. Keep secrets and authorization data out of logs and public output.

06

Test one task before expanding the install

First confirm that lark-cli is installed and authorized for the intended tenant. Select the single domain Skill that owns the requested resource and read its current SKILL.md plus only the operation references it calls for. Begin with a read-only lookup of a known, non-sensitive resource. Check the returned identity and resource ID before trying a write.

For a write, name the exact destination and expected change, preview when supported, and read the result back. Treat sending messages or email, changing access or membership, deleting or moving shared resources, and approving or rejecting business requests as externally consequential. Stop and ask for an explicit decision when intent or scope is unclear.

This guide was checked against the larksuite/cli source at revision a079fd7a0f2e5f91ef2a45017175ac9b7435ee97 on 2026-09-23. It summarizes the upstream instructions; it is not a runtime compatibility test, security audit, or guarantee that a tenant has enabled every operation.

  • The target tenant, resource, and user-or-bot identity are explicit.
  • The first run is read-only and uses the least scope required.
  • A consequential write has a clear target, preview, and explicit approval.
  • The result is read back and checked; secrets and private content stay out of logs.

NEXT STEP

Install the Skill that owns the task

Check the exact source, dependency, identity, permissions, and write boundary before connecting an Agent to a Feishu tenant.