feishu-user-plugin

Productivity · tested 2026-08-21 · re-test due 2026-11-21 · by the Hlido desk, not the vendor

In short: A remarkably deep Feishu/Lark MCP server (85 tools, three auth layers) whose headline trick — sending messages as the actual user, not a bot — is also its biggest risk.

4 PASS · 0 FAIL of 4 public-surface claims

Quick answer

feishu-user-plugin scores 71/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-08-21). STEADY (71) for an unusually deep, well-documented Feishu/Lark MCP server (85 tools, three auth layers, real-time events, MIT) that clearly reflects real use, with a genuinely differentiated user-identity send capability Pricing: Open source (free entry point documented).

feishu-user-plugin is one of the most feature-complete Feishu/Lark MCP servers on the public surface: 85 tools across IM, docs, Bitable (multi-dimensional tables), wiki, drive, calendar, tasks v2, OKR and a real-time-events websocket, with nine slash-command MCP prompts, MIT-licensed and Node 18+. Its differentiator is explicit and technically interesting: because Feishu's official open API has no send_as_user permission (bot tokens always mark messages sender_type: 'app'), this plugin uses a cookie + protobuf path to send text/images/files/rich-post as the user themselves. Three independent auth layers (LARK_COOKIE for user-identity sends, official app ID/secret for the 70+ bot-API tools, and user OAuth UAT for P2P reads) is a thoughtful design, and details like read_doc_markdown ('saves ~60% token'), 10-minute chat-ID caching, and cross-profile retry on specific error codes show a maintainer who has actually used it. The catch is the same as the headline feature: the user-identity path depends on a copied browser cookie and an unofficial protobuf route, which is inherently fragile (cookies expire, protocols change) and lives in a grey area versus Feishu's official API and terms. For a developer inside the Feishu/Lark ecosystem this is a powerful, agent-native tool; the cookie-based user-impersonation layer should be adopted with eyes open.

Why STEADY

STEADY (71) for an unusually deep, well-documented Feishu/Lark MCP server (85 tools, three auth layers, real-time events, MIT) that clearly reflects real use, with a genuinely differentiated user-identity send capability. Not higher because its defining feature relies on a copied cookie + an unofficial protobuf path that is fragile and sits in a terms-of-service grey zone, and because breadth this large can't be verified for reliability from the surface. Not FADING because the tool inventory, auth design and honest engineering detail are substantial and specific.

Public-surface checklist

What we saw

4 screenshots captured by the Hlido engine during the reviewed run (run-2d6f30cd173e0f56-ethanqc-github-io). Our own captures — not vendor marketing material.

feishu-user-plugin — run screenshot 1 (home.png)
home.png
feishu-user-plugin — run screenshot 2 (page_content.png)
page_content.png
feishu-user-plugin — run screenshot 3 (pageen_html.png)
pageen_html.png
feishu-user-plugin — run screenshot 4 (pageen_html.png)
pageen_html.png

What it does well

What it fails at

Red flags

Best for

  • Developers and teams inside the Feishu/Lark ecosystem who want deep, agent-driven automation via MCP
  • Use cases that specifically need messages to appear from the real user rather than a bot
  • Power users who want docs/Bitable/wiki/calendar/tasks/OKR all reachable from one MCP server

Not recommended for

  • Organisations that require strictly official-API, terms-compliant integrations (avoid the cookie/protobuf user-send path)
  • Anyone outside the Feishu/Lark ecosystem
  • Deployments that can't tolerate periodic re-auth when the copied cookie expires

Pricing & access

Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-08-21.

Related agents

Agent relevance

API CLI MCP Webhook Behavioral-testable

Agentic-Commerce Readiness 76/100 · COMMERCE-READY

Independent readiness for agent delegation & transaction. How it’s scored · check live

MCP server with 85 tools and nine slash-command prompts across Claude Code, Codex, Cursor, Windsurf, VS Code and Claude Desktop; real-time events over websocket. npx setup/oauth flow. Directly testable given Feishu credentials, though the user-identity path depends on a copied cookie.

Agent-friendly score: 8/10

Evidence

scorecard.json · transparency passport · registry · methodology

More: compare agents · best of · developer tools · incident registry

Verdict by Hlido Editor, our automated editorial system · Method: public-surface-tier-1+editorial-narrative-v2 · Methodology version 2026.05 · Next review due 2026-11-21

How this page was produced. The scores, claim verdicts and evidence come from automated hands-on testing of the product’s public surface. The written analysis is drafted by an AI system, and pages publish without a person reviewing each one. Hlido publishes this record and answers for it — tell us if anything here is wrong and we will correct it.

Embed this trust badge

Hlido trust score

Live, always-current independent score — free to embed on your site or README. No vendor pays for placement.

Markdown

[![Hlido trust score](https://hlido.eu/badge/ethanqc-feishu-user-plugin.svg)](https://hlido.eu/check/?agent=ethanqc-feishu-user-plugin)

HTML

<a href="https://hlido.eu/check/?agent=ethanqc-feishu-user-plugin"><img src="https://hlido.eu/badge/ethanqc-feishu-user-plugin.svg" alt="Hlido trust score"></a>