扫描报告
5 /100
han-jr-system
小翰系统:1688平台自动化供应商联系系统。使用场景:用户需要联系1688供应商、发送询价消息、收集报价时。
This is a legitimate 1688.com supplier contact automation system using Playwright with Chrome CDP. No malicious behavior, credential theft, data exfiltration, or suspicious network communications were detected.
可以安装
This skill is safe to use. Ensure proper Chrome login state before running scripts and maintain reasonable search intervals to avoid triggering platform anti-bot mechanisms.
安全发现 2 项
| 严重性 | 安全发现 | 位置 |
|---|---|---|
| 提示 | Hardcoded Chrome user data path 敏感访问 | scripts/chrome_launch.py:24 |
| 提示 | subprocess.Popen for browser launch 代码执行 | scripts/chrome_launch.py:36 |
| 资源类型 | 声明权限 | 推断权限 | 状态 | 证据 |
|---|---|---|---|---|
| 网络访问 | READ | READ | ✓ 一致 | CDP connects to localhost:9222; HTTP requests to 1688.com domains |
| 命令执行 | NONE | WRITE | ✓ 一致 | chrome_launch.py:36 - subprocess.Popen for Chrome browser launch |
| 文件系统 | NONE | READ/WRITE | ✓ 一致 | Local JSON database storage for supplier data |
| 浏览器 | READ/WRITE | READ/WRITE | ✓ 一致 | Playwright CDP automation of 1688 web interface |
91 项发现
中危 外部 URL 外部 URL
https://air.1688.com/app/ocms-fusion-components-1688/def_cbu_web_im/... SKILL.md:173 中危 外部 URL 外部 URL
https://detail.1688.com/offer/xxx.html SKILL.md:324 中危 外部 URL 外部 URL
https://air.1688.com/app/ocms-fusion-components-1688/def_cbu_web_im/index.html?touid=cnalichnbaiyuanlong168&siteid=cnali... scripts/1688_send_message.py:6 中危 外部 URL 外部 URL
https://air.1688.com/...?touid=... scripts/1688_send_message.py:16 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/offer_search.htm scripts/1688_send_message.py:32 中危 外部 URL 外部 URL
https://air.1688.com/app/ocms-fusion-components-1688/def_cbu_web_im/index.html scripts/1688_send_message.py:33 中危 外部 URL 外部 URL
https://detail.1688.com/offer/ scripts/1688_send_message.py:34 中危 外部 URL 外部 URL
http://shop483u278m52h82.1688.com scripts/contact_supplier.py:10 中危 外部 URL 外部 URL
https://detail\.1688\.com/offer/\d+\.html scripts/extract_from_page.py:134 中危 外部 URL 外部 URL
http://shop14031593wzy52.1688.com scripts/hat_products.json:5 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=771413041900&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/hat_products.json:10 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=861950520610&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/hat_products.json:15 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=891582079284&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/hat_products.json:20 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=806886034440&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/hat_products.json:25 中危 外部 URL 外部 URL
http://shop5792293792985.1688.com scripts/hat_products.json:30 中危 外部 URL 外部 URL
https://detail.1688.com/offer/1.html scripts/hat_suppliers.json:4 中危 外部 URL 外部 URL
https://detail.1688.com/offer/2.html scripts/hat_suppliers.json:10 中危 外部 URL 外部 URL
https://detail.1688.com/offer/3.html scripts/hat_suppliers.json:16 中危 外部 URL 外部 URL
https://detail.1688.com/offer/4.html scripts/hat_suppliers.json:22 中危 外部 URL 外部 URL
https://detail.1688.com/offer/5.html scripts/hat_suppliers.json:28 中危 外部 URL 外部 URL
https://detail.1688.com/offer/search_1.html scripts/notebook_suppliers.json:4 中危 外部 URL 外部 URL
https://detail.1688.com/offer/search_2.html scripts/notebook_suppliers.json:11 中危 外部 URL 外部 URL
https://detail.1688.com/offer/search_3.html scripts/notebook_suppliers.json:18 中危 外部 URL 外部 URL
https://detail.1688.com/offer/search_4.html scripts/notebook_suppliers.json:25 中危 外部 URL 外部 URL
https://detail.1688.com/offer/search_5.html scripts/notebook_suppliers.json:32 中危 外部 URL 外部 URL
https://h5api.wapa.1688.com scripts/page_debug.html:28 中危 外部 URL 外部 URL
https://h5api.m.1688.com scripts/page_debug.html:30 中危 外部 URL 外部 URL
https://o.alicdn.com/baxia/baxia-entry-gray/index.js scripts/page_debug.html:32 中危 外部 URL 外部 URL
http://shop6x72q03159n97.1688.com scripts/results/T恤.json:6 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=807891725157&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/T恤.json:12 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=796002561192&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/T恤.json:18 中危 外部 URL 外部 URL
https://r.1688.com/auth/fcaReport.htm?_input_charset=utf8&loginId=%E9%AB%98%E7%AB%AF%E7%8E%A9%E5%AE%B6%E6%8B%BE%E6%9F%92 scripts/results/T恤.json:24 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=948485449968&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/T恤.json:30 中危 外部 URL 外部 URL
http://shop3r3564k59k514.1688.com scripts/results/包包.json:6 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=985720033362&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/包包.json:12 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=924368481035&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/包包.json:18 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=984400563924&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/包包.json:24 中危 外部 URL 外部 URL
http://fenghefushi.1688.com scripts/results/围巾.json:6 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=974344291128&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/围巾.json:12 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=833545829317&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/围巾.json:18 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=971140203906&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/围巾.json:24 中危 外部 URL 外部 URL
http://shop5ae46x0904156.1688.com scripts/results/外套.json:6 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=904396717086&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/外套.json:12 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=992679651309&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/外套.json:18 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=1018958212373&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fim... scripts/results/外套.json:24 中危 外部 URL 外部 URL
http://shop1416328918110.1688.com scripts/results/手套.json:6 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=937513719684&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/手套.json:12 中危 外部 URL 外部 URL
https://r.1688.com/auth/fcaReport.htm?_input_charset=utf8&loginId=%E7%81%B5%E8%B4%9D%E6%97%A5%E7%94%A8%E5%93%81%E5%8E%82 scripts/results/手套.json:18 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=864993448510&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/手套.json:24 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=786940029557&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/手套.json:30 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=876009937471&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/棒球帽.json:18 中危 外部 URL 外部 URL
http://huijiefushi.1688.com scripts/results/棒球帽.json:36 中危 外部 URL 外部 URL
http://qkzj.1688.com scripts/results/棒球帽.json:42 中危 外部 URL 外部 URL
http://guanghaofushi.1688.com scripts/results/棒球帽_test.json:6 中危 外部 URL 外部 URL
http://shop77l201825pw81.1688.com scripts/results/棒球帽_test.json:36 中危 外部 URL 外部 URL
http://shop65712408i0o63.1688.com scripts/results/棒球帽定制.json:6 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=944930968627&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/棒球帽定制.json:12 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=726112803758&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/棒球帽定制.json:18 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=775781825822&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/棒球帽定制.json:24 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=564958468360&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/棒球帽定制.json:30 中危 外部 URL 外部 URL
http://shop4t60209v41i62.1688.com scripts/results/棒球帽定制.json:36 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=629361479026&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/棒球帽定制.json:42 中危 外部 URL 外部 URL
http://tspj168.1688.com scripts/results/腰带.json:6 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=738781084660&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/腰带.json:12 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=868391127133&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/腰带.json:18 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=985994431209&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/腰带.json:24 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=839733440374&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/腰带.json:30 中危 外部 URL 外部 URL
http://onenok.1688.com scripts/results/袜子.json:6 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=987811030032&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/袜子.json:12 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=869889194211&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/袜子.json:18 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=928009161162&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/袜子.json:24 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=976519183604&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/袜子.json:30 中危 外部 URL 外部 URL
http://shop384876488m851.1688.com scripts/results/裤子.json:6 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=980772677746&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/裤子.json:12 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=992494954340&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/裤子.json:18 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=846236758162&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/裤子.json:24 中危 外部 URL 外部 URL
http://luoyangkangtai.1688.com scripts/results/鞋子.json:6 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=729859144838&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/鞋子.json:12 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=972689950466&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/鞋子.json:18 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=792975126235&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/鞋子.json:24 中危 外部 URL 外部 URL
http://headgear24.1688.com scripts/results/鸭舌帽刺绣.json:6 中危 外部 URL 外部 URL
https://r.1688.com/auth/fcaReport.htm?_input_charset=utf8&loginId=%E5%8D%8E%E6%9D%BE%E5%95%86%E8%A1%8C scripts/results/鸭舌帽刺绣.json:18 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=935973471121&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/鸭舌帽刺绣.json:24 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=884371868790&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/鸭舌帽刺绣.json:30 中危 外部 URL 外部 URL
https://r.1688.com/auth/fcaReport.htm?_input_charset=utf8&loginId=%E4%B9%89%E4%B9%8C%E5%B8%82%E9%80%B8%E5%86%A0%E5%B8%BD... scripts/results/鸭舌帽刺绣.json:36 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=834402555925&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/鸭舌帽刺绣.json:42 中危 外部 URL 外部 URL
http://shop5643366207c95.1688.com scripts/results/鸭舌帽刺绣.json:48 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/similar_search.html?offerIds=706209290207&imageAddress=https%3A%2F%2Fcbu01.alicdn.com%2Fimg... scripts/results/鸭舌帽刺绣.json:54 中危 外部 URL 外部 URL
https://www.1688.com scripts/search_1688.py:59 中危 外部 URL 外部 URL
https://detail.1688.com/offer/search_ scripts/search_1688.py:278 中危 外部 URL 外部 URL
https://s.1688.com/selloffer/offer_search.htm?keywords= scripts/search_final.py:62 目录结构
106 文件 · 552.8 KB · 15800 行 Python 75f · 12673L
JSON 20f · 1936L
Markdown 9f · 1081L
Text 1f · 78L
HTML 1f · 32L
├─
▾
references
│ ├─
antibot_handling.md
Markdown
│ ├─
api_reference.md
Markdown
│ ├─
inquiry_template.md
Markdown
│ ├─
popup_handling.md
Markdown
│ └─
soul_rules.md
Markdown
├─
▾
scripts
│ ├─
▾
results
│ │ ├─
show_results.py
Python
│ │ ├─
show_suppliers.py
Python
│ │ ├─
T恤.json
JSON
│ │ ├─
包包.json
JSON
│ │ ├─
围巾.json
JSON
│ │ ├─
外套.json
JSON
│ │ ├─
帽子.json
JSON
│ │ ├─
手套.json
JSON
│ │ ├─
棒球帽_test.json
JSON
│ │ ├─
棒球帽.json
JSON
│ │ ├─
棒球帽定制.json
JSON
│ │ ├─
腰带.json
JSON
│ │ ├─
袜子.json
JSON
│ │ ├─
裤子.json
JSON
│ │ ├─
鞋子.json
JSON
│ │ └─
鸭舌帽刺绣.json
JSON
│ ├─
1688_inspect.py
Python
│ ├─
1688_send_message.py
Python
│ ├─
1688_switch_tab.py
Python
│ ├─
batch_contact_final.py
Python
│ ├─
batch_contact.py
Python
│ ├─
batch_inquire.py
Python
│ ├─
batch_search.py
Python
│ ├─
check_current_status.py
Python
│ ├─
check_full_scroll.py
Python
│ ├─
check_page_status.py
Python
│ ├─
check_scrollheight.py
Python
│ ├─
chrome_launch.py
Python
│ ├─
click_wangwang_and_inquire.py
Python
│ ├─
contact_batch_continue.py
Python
│ ├─
contact_custom.py
Python
│ ├─
contact_first.py
Python
│ ├─
contact_supplier_wangwang.py
Python
│ ├─
contact_supplier.py
Python
│ ├─
contact_two_direct.py
Python
│ ├─
contact_two_fixed_v2.py
Python
│ ├─
contact_yashemao.py
Python
│ ├─
continue_search.py
Python
│ ├─
count_all_contacts.py
Python
│ ├─
debug_contacts.py
Python
│ ├─
debug_page.py
Python
│ ├─
debug_selectors.py
Python
│ ├─
debug_selectors2.py
Python
│ ├─
example.py
Python
│ ├─
extract_from_page.py
Python
│ ├─
extract_products.py
Python
│ ├─
get_all_contacts_from_top.py
Python
│ ├─
han_dgx_spark_workflow.py
Python
│ ├─
hat_products.json
JSON
│ ├─
hat_suppliers.json
JSON
│ ├─
inquiry_records.txt
Text
│ ├─
manual_contact_two.py
Python
│ ├─
manual_learn_iframe.py
Python
│ ├─
manual_two_suppliers.py
Python
│ ├─
notebook_suppliers.json
JSON
│ ├─
page_debug.html
HTML
│ ├─
pencil_workflow.py
Python
│ ├─
reset_database.py
Python
│ ├─
screenshot_bottom.py
Python
│ ├─
scroll_to_bottom.py
Python
│ ├─
search_1688_fixed.py
Python
│ ├─
search_1688_utf8.py
Python
│ ├─
search_1688.py
Python
│ ├─
search_and_contact_fixed.py
Python
│ ├─
search_and_contact.py
Python
│ ├─
search_box_v2.py
Python
│ ├─
search_box.py
Python
│ ├─
search_contact_fixed.py
Python
│ ├─
search_contact_v2.py
Python
│ ├─
search_final.py
Python
│ ├─
search_wangwang_contact.py
Python
│ ├─
send_chat_message.py
Python
│ ├─
slider_captcha.py
Python
│ ├─
supplier_manager.py
Python
│ ├─
suppliers_database.json
JSON
│ ├─
sync_196_contacts.py
Python
│ ├─
sync_all_contacts_full.py
Python
│ ├─
sync_all_contacts_scroll.py
Python
│ ├─
sync_all_contacts_v2.py
Python
│ ├─
sync_all_contacts.py
Python
│ ├─
sync_all_pending.py
Python
│ ├─
sync_batch_10.py
Python
│ ├─
sync_from_screenshot.py
Python
│ ├─
sync_one_by_one.py
Python
│ ├─
sync_visible_10.py
Python
│ ├─
sync_wangwang_chat.py
Python
│ ├─
sync_wangwang_to_local.py
Python
│ ├─
test_pencil.json
JSON
│ ├─
test_pencil3.json
JSON
│ ├─
test_search_frames.py
Python
│ ├─
test_search.py
Python
│ ├─
verify_database.py
Python
│ ├─
verify_step.py
Python
│ ├─
verify_system.py
Python
│ ├─
view_yesterday_replies.py
Python
│ ├─
wangwang_chat_manager.py
Python
│ └─
yesterday_reply_summary.py
Python
├─
RESOLVED_ISSUES.md
Markdown
├─
SKILL.md
Markdown
├─
STATUS_REPORT.md
Markdown
└─
TODAY_UPDATE.md
Markdown
依赖分析 6 项
| 包名 | 版本 | 来源 | 已知漏洞 | 备注 |
|---|---|---|---|---|
playwright | * | pip | 否 | Browser automation framework, standard dependency |
requests | * | pip | 否 | Used for CDP health checks only |
beautifulsoup4 | * | pip | 否 | HTML parsing for supplier data extraction |
easyocr | * | pip | 否 | OCR for verification screenshots |
pillow | * | pip | 否 | Image processing for OCR |
numpy | * | pip | 否 | Numeric operations for image processing |
安全亮点
✓ No credential harvesting or environment variable iteration for sensitive keys
✓ No base64-encoded execution or code obfuscation
✓ No remote script execution (curl|bash or wget|sh patterns)
✓ No reverse shell or C2 communication patterns
✓ No access to sensitive paths (~/.ssh, ~/.aws, .env)
✓ All network requests are to legitimate 1688.com domains
✓ Well-documented SKILL.md with clear purpose declaration
✓ Local database only stores supplier data, no exfiltration
✓ Uses Playwright CDP (standard browser automation framework)
✓ No malicious dependencies or supply chain concerns