weread-fulltext
文档声明「零注入零写入」但代码实际使用 page.evaluate() 执行 JS 并写入大量文件,存在文档-行为差异;依赖无版本锁定存在供应链风险。
为什么得出这个结论
0/4 个维度触发声明资源与推断能力基本一致。
提取到 3 个一般风险产物,需要结合上下文判断。
没有形成明确的恶意路径。
依赖结构存在,但暂未看到明显高危告警。
风险分是怎么被拉高的
SKILL.md 声称「零注入零写入」,但代码使用 page.evaluate() 执行 JS 并写入多处文件
requirements.txt 中 playwright>=1.40 和 rapidocr-onnxruntime>=1.3 使用开放版本范围
登录态写入本地 JSON 文件,虽为正常功能但文档未明确说明
page.evaluate() 内 fetch 请求携带 credentials:'include',虽目标为 weread.qq.com 但方式存在理论风险
最关键的证据
文档声明「零注入」但实际使用 page.evaluate() 执行 JS
SKILL.md 声称「零注入零写入」,但 capture_page() 函数使用 page.evaluate() 执行 JS 代码 querySelectorAll('canvas').map(...) 来获取画布数据。这是通过 Playwright 的合法 JS 注入机制。
scripts/export_fulltext.py:59 文档声明「零写入」但代码实际写入多个文件
SKILL.md 采集层声明「零写入」,但实际代码写入:PNG截图(spreads_dir)、manifest.jsonl、run_meta.json、chapters_official.json、登录态文件 weread_state.json 等多个文件。
scripts/export_fulltext.py:98 依赖包无版本锁定
requirements.txt 使用开放版本范围 playwright>=1.40 和 rapidocr-onnxruntime>=1.3,依赖更新可能导致行为变化或引入漏洞。
scripts/requirements.txt:1 未声明的登录态持久化
代码将登录态保存到本地 profile/weread_state.json 文件,文档未明确说明此持久化行为。
scripts/export_fulltext.py:356 声明能力 vs 实际能力
SKILL.md 明确说明输出 Markdown 和报告 SKILL.md 说明使用 Playwright 自动化 仅访问 weread.qq.com 域名 代码中无 subprocess 或 shell 执行 可疑产物与外联
https://weread.qq.com scripts/export_fulltext.py:29
https://weread.qq.com/api/user/notebook scripts/export_fulltext.py:122
https://weread.qq.com/web/book/chapterInfos scripts/export_fulltext.py:147
依赖与供应链
| 包名 | 版本 | 来源 | 漏洞 | 备注 |
|---|---|---|---|---|
| playwright | >=1.40 | pip | 否 | 开放版本范围,建议锁定 |
| rapidocr-onnxruntime | >=1.3 | pip | 否 | 开放版本范围,建议锁定 |
文件构成
scripts/export_fulltext.py scripts/requirements.txt