钉钉知识库和文档管理操作。当用户提到"钉钉文档"、"知识库"、"新建文档"、"查看文档目录"、"读取文档内容"、"写入文档"、"更新文档"、"文档成员"、"dingtalk doc"、"knowledge base"时使用此技能。支持:创建知识库、查询知识库列表、新建文档/文件夹、读取/写入文档正文内容、管理成员权限等全部文档类操作。
This skill manages DingTalk knowledge bases and documents through DingTalk's official open-platform APIs. It solves the problem of programmatically working with DingTalk Wiki workspaces and documents: creating knowledge bases, listing workspaces and nodes, creating documents and folders, reading and writing document body content, and managing document member permissions. It is a strategy guide plus a helper script and API reference, triggered by mentions of DingTalk docs, knowledge bases, or related document operations in Chinese or English.
The skill centers on a task-first workflow: identify the operation, validate only the configuration keys that specific task needs, collect any missing values in a single prompt, then obtain a token and operator ID via the bundled dt_helper.sh script. Credentials (AppKey, AppSecret, user ID, and a derived unionId operator ID) are stored and read through the helper, with an explicit rule that credentials must never be printed in full (only a masked prefix is shown when confirming). API calls are issued against api.dingtalk.com endpoints for workspaces, nodes, documents, content blocks, and members; the reference documents read, overwrite, append, create, delete, and member-management operations along with error codes and required app permissions.
It targets developers and operators integrating DingTalk document automation into agent workflows, particularly in Chinese-language enterprise environments. The design shows security-conscious handling: official tooling, cached access tokens with a --nocache refresh on 401, and credential masking. Note that some operations are destructive by nature, such as full-document overwrite (marked irreversible) and document deletion, so care is warranted when invoking those against real content.
It needs a DingTalk AppKey and AppSecret, the current user's enterprise userId, and a unionId operator ID (auto-derived from the userId via the helper's --to-unionid conversion). These are stored and read through the dt_helper.sh script.
The dt_helper.sh script fetches and time-caches the token. If an API returns 401 because a token was revoked early, you rerun the token command with --nocache to force a fresh token.
No. The skill explicitly forbids printing credentials in full; when confirming, it shows only the first four characters followed by a mask, and tokens are obtained through the helper rather than echoed.
Listing knowledge bases and nodes, creating documents and folders, reading block-structured content, overwriting or appending content, deleting documents, and adding, updating, or removing document members with viewer or editor roles.
Yes. The overwrite-content endpoint fully replaces a document's body and is documented as non-undoable, and document deletion removes the node, so confirm the target before running them.
Quick Setup:
.claude/skills/Repository
breath57/dingtalk-skills