Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md pip install -r scripts/requirements.txt
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent local tool for generating a WeRead reading-history page, with manageable privacy and session-storage risks users should understand.
Install only if you are comfortable using browser automation with your WeRead account. Keep the saved profile state and exported JSON/HTML private, avoid committing them to repositories or synced folders, and consider pinning dependencies before repeated or shared use.
Referenced artifact was not completely inspected
pip install -r scripts/requirements.txt
The skill clearly describes capabilities that read local files, write output files, and access the network, but it does not declare any explicit tool scope or permissions boundary. That mismatch is dangerous because an agent or runtime may grant broader access than users expect, reducing transparency and increasing the chance of unintended file access, data exfiltration, or unsafe automation against a logged-in account.
The script persists Playwright storage state to a local JSON file, which can contain reusable authenticated session cookies or tokens for the user's WeRead account. If that file is stored insecurely, committed to a repo, synced to cloud storage, or read by another local user/process, an attacker could hijack the session without needing the user's QR login.
The dependency specifier playwright>=1.40 is unpinned, so installs may resolve to different versions over time. That creates supply-chain and reproducibility risk: a future compromised or incompatible release could be pulled into the skill without review.
playwright>=1.40
Pillow>=10.0
Pillow>=10.0 is unpinned, which means dependency resolution may select any newer release, including versions with newly introduced vulnerabilities or behavioral changes. In this skill, Pillow likely processes images/screenshots, so a vulnerable image library can increase exposure to malicious image parsing bugs and denial-of-service issues.
playwright>=1.40
Pillow>=10.0
The manifest references Pillow without pinning to a known-safe release, and Pillow has a history of security advisories including image parsing and resource-consumption issues. Because this skill generates HTML and screenshots and may handle external image content such as book covers, the lack of version pinning makes it impossible to verify whether deployment will use a patched release.
The script can export detailed reading-history metadata to JSON, including titles, authors, categories, note counts, completion state, and activity timestamps. While this is not code execution, it creates a privacy-sensitive local artifact that may reveal personal interests and behavior if exposed through shared folders, backups, or accidental publication.
No suspicious patterns detected.