Skill Trust Decision

weread-fulltext

文档声明「零注入零写入」但代码实际使用 page.evaluate() 执行 JS 并写入大量文件,存在文档-行为差异;依赖无版本锁定存在供应链风险。

Install decision first Source: ClawHub Scanned: 19 hr ago
Files 3
Artifacts 3
Violations 0
Findings 4

Why this conclusion was reached

0/4 dimensions flagged
Pass
Declared vs actual capability

Declared resources and inferred behavior are broadly aligned.

Review
Hidden execution and egress

3 lower-risk artifacts were extracted and still need context.

Pass
Attack chain and severe findings

There is no explicit malicious chain in the report.

Pass
Dependencies and supply chain hygiene

Dependencies are present but no obvious high-risk issue stands out.

What drove the risk score up

文档声明与实际行为不符 +20

SKILL.md 声称「零注入零写入」,但代码使用 page.evaluate() 执行 JS 并写入多处文件

依赖无版本锁定 +12

requirements.txt 中 playwright>=1.40 和 rapidocr-onnxruntime>=1.3 使用开放版本范围

浏览器存储状态持久化 +5

登录态写入本地 JSON 文件,虽为正常功能但文档未明确说明

JS fetch 带凭证跨域 +5

page.evaluate() 内 fetch 请求携带 credentials:'include',虽目标为 weread.qq.com 但方式存在理论风险

Most important evidence

Medium Doc Mismatch

文档声明「零注入」但实际使用 page.evaluate() 执行 JS

SKILL.md 声称「零注入零写入」,但 capture_page() 函数使用 page.evaluate() 执行 JS 代码 querySelectorAll('canvas').map(...) 来获取画布数据。这是通过 Playwright 的合法 JS 注入机制。

scripts/export_fulltext.py:59
更新 SKILL.md 说明使用 Playwright page.evaluate() 进行画布捕获,或改为使用 Playwright 原生的 screenshot API
Medium Doc Mismatch

文档声明「零写入」但代码实际写入多个文件

SKILL.md 采集层声明「零写入」,但实际代码写入:PNG截图(spreads_dir)、manifest.jsonl、run_meta.json、chapters_official.json、登录态文件 weread_state.json 等多个文件。

scripts/export_fulltext.py:98
更正文档说明采集层实际写入截图和元数据文件
Medium Supply Chain

依赖包无版本锁定

requirements.txt 使用开放版本范围 playwright>=1.40 和 rapidocr-onnxruntime>=1.3,依赖更新可能导致行为变化或引入漏洞。

scripts/requirements.txt:1
锁定具体版本如 playwright==1.40.0 和 rapidocr-onnxruntime==1.3.15
Low Priv Escalation

未声明的登录态持久化

代码将登录态保存到本地 profile/weread_state.json 文件,文档未明确说明此持久化行为。

scripts/export_fulltext.py:356
在文档中明确说明登录态保存位置和用途

Declared capability vs actual capability

Filesystem Pass
Declared WRITE
→
Inferred WRITE
SKILL.md 明确说明输出 Markdown 和报告
Browser Pass
Declared WRITE
→
Inferred WRITE
SKILL.md 说明使用 Playwright 自动化
Network Pass
Declared READ
→
Inferred READ
仅访问 weread.qq.com 域名
Shell Pass
Declared NONE
→
Inferred NONE
代码中无 subprocess 或 shell 执行

Suspicious artifacts and egress

Medium External URL
https://weread.qq.com

scripts/export_fulltext.py:29

Medium External URL
https://weread.qq.com/api/user/notebook

scripts/export_fulltext.py:122

Medium External URL
https://weread.qq.com/web/book/chapterInfos

scripts/export_fulltext.py:147

Dependencies and supply chain

PackageVersionSourceKnown vulnNotes
playwright >=1.40 pip No 开放版本范围,建议锁定
rapidocr-onnxruntime >=1.3 pip No 开放版本范围,建议锁定

File composition

3 files · 579 lines
Python 1 files · 514 linesMarkdown 1 files · 63 linesText 1 files · 2 lines
Files of concern · 2
scripts/export_fulltext.py Python · 514 lines
文档声明「零注入」但实际使用 page.evaluate() 执行 JS · 文档声明「零写入」但代码实际写入多个文件 · 未声明的登录态持久化 · https://weread.qq.com · https://weread.qq.com/api/user/notebook · https://weread.qq.com/web/book/chapterInfos
scripts/requirements.txt Text · 2 lines
依赖包无版本锁定
Other files · SKILL.md

Security positives

所有网络请求仅指向 weread.qq.com 官方域名,无外部 IP 连接
无凭证收割行为,仅访问自己的微信读书账号
无反向 shell、base64 解码执行等恶意模式
OCR 完全本地执行,无云端传输
代码结构清晰,有完整错误处理和日志输出
文档诚实声明了未验证范围和限制
使用 SHA-256 作为图片缓存键,防篡改验证