weread-fulltext
文档声明「零注入零写入」但代码实际使用 page.evaluate() 执行 JS 并写入大量文件,存在文档-行为差异;依赖无版本锁定存在供应链风险。
Why this conclusion was reached
0/4 dimensions flaggedDeclared resources and inferred behavior are broadly aligned.
3 lower-risk artifacts were extracted and still need context.
There is no explicit malicious chain in the report.
Dependencies are present but no obvious high-risk issue stands out.
What drove the risk score up
SKILL.md 声称「零注入零写入」,但代码使用 page.evaluate() 执行 JS 并写入多处文件
requirements.txt 中 playwright>=1.40 和 rapidocr-onnxruntime>=1.3 使用开放版本范围
登录态写入本地 JSON 文件,虽为正常功能但文档未明确说明
page.evaluate() 内 fetch 请求携带 credentials:'include',虽目标为 weread.qq.com 但方式存在理论风险
Most important evidence
文档声明「零注入」但实际使用 page.evaluate() 执行 JS
SKILL.md 声称「零注入零写入」,但 capture_page() 函数使用 page.evaluate() 执行 JS 代码 querySelectorAll('canvas').map(...) 来获取画布数据。这是通过 Playwright 的合法 JS 注入机制。
scripts/export_fulltext.py:59 文档声明「零写入」但代码实际写入多个文件
SKILL.md 采集层声明「零写入」,但实际代码写入:PNG截图(spreads_dir)、manifest.jsonl、run_meta.json、chapters_official.json、登录态文件 weread_state.json 等多个文件。
scripts/export_fulltext.py:98 依赖包无版本锁定
requirements.txt 使用开放版本范围 playwright>=1.40 和 rapidocr-onnxruntime>=1.3,依赖更新可能导致行为变化或引入漏洞。
scripts/requirements.txt:1 未声明的登录态持久化
代码将登录态保存到本地 profile/weread_state.json 文件,文档未明确说明此持久化行为。
scripts/export_fulltext.py:356 Declared capability vs actual capability
SKILL.md 明确说明输出 Markdown 和报告 SKILL.md 说明使用 Playwright 自动化 仅访问 weread.qq.com 域名 代码中无 subprocess 或 shell 执行 Suspicious artifacts and egress
https://weread.qq.com scripts/export_fulltext.py:29
https://weread.qq.com/api/user/notebook scripts/export_fulltext.py:122
https://weread.qq.com/web/book/chapterInfos scripts/export_fulltext.py:147
Dependencies and supply chain
| Package | Version | Source | Known vuln | Notes |
|---|---|---|---|---|
| playwright | >=1.40 | pip | No | 开放版本范围,建议锁定 |
| rapidocr-onnxruntime | >=1.3 | pip | No | 开放版本范围,建议锁定 |
File composition
scripts/export_fulltext.py scripts/requirements.txt