Back to skill

Security audit

微信读书全文导出 Weread Fulltext

Security checks for vulnerabilities and agentic risk

Overview

This skill can copy whole books from a logged-in WeRead account, but its browser automation, saved login state, and account-risk behavior are not clearly scoped enough for automatic trust.

Review this carefully before installing. Use only for content you are authorized to export, understand that it stores a reusable WeRead login state and full book artifacts locally, and prefer a separate account/profile plus pinned dependencies if you proceed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill description claims 'zero injection' and frames the process as passive capture, but the analyzed behavior includes in-page JavaScript evaluation, authenticated API access, and substantial local artifact creation. That mismatch is dangerous because users may consent under a materially incomplete understanding of what the skill does, including access to internal APIs and collection of potentially sensitive account-linked content.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill advertises browser-driven collection and export behavior but does not declare any explicit tool scope or permissions, even though its documented workflow clearly requires network access and local file writes. Missing scope declarations make the skill less auditable and increase the chance that a caller authorizes broader capabilities than expected, especially for a workflow involving authenticated reading-session data and export artifacts.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly recommends small-account use, one-book-at-a-time operation, and human-like pacing to reduce detection while exporting full-book content from a protected platform. These are classic stealth and anti-detection signals, and in this context they support large-scale unauthorized extraction of copyrighted or access-controlled material rather than a normal user-safety feature.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/export_fulltext.py (reported line 147)May include surrounding context.

python
chapters = page.evaluate(
        """async (bookId) => {
            try {
                const r = await fetch('https://weread.qq.com/web/book/chapterInfos', {
                    method: 'POST', credentials: 'include',
                    headers: {'Content-Type': 'application/json'},
                    body: JSON.stringify({bookId: String(bookId)})

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The dependency is specified with only a lower bound, so future installs may pull in newer major or minor versions with unreviewed behavior or known supply-chain issues. In a skill that automates browser interaction and exports protected reading content, dependency drift increases the risk of breakage or accidental introduction of malicious or vulnerable transitive code.

Content

Scanner excerpt · scripts/requirements.txt (reported line 1)May include surrounding context.

text
playwright>=1.40
rapidocr-onnxruntime>=1.3

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The OCR package is also unpinned, allowing installation of any newer release that satisfies the minimum version. This creates supply-chain exposure because a compromised or breaking upstream release could be silently adopted in future environments, especially significant here because OCR libraries often include native/runtime components and broad transitive dependencies.

Content

Scanner excerpt · scripts/requirements.txt (reported line 2)May include surrounding context.

text
playwright>=1.40
rapidocr-onnxruntime>=1.3

Static analysis

No suspicious patterns detected.