为漫画站增加双页阅读、翻译等优化体验的增强功能的油猴脚本
The userscript has a remote code execution exposure in its Hitomi integration. No npm install-time attack surface was identified.
Package source references a known benign dynamic code generation pattern.
ComicReader.umd.jsView on unpkg · L17Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
ComicRead-AdGuard.user.jsView on unpkgThe userscript downloads JavaScript from a dynamically selected host and passes the response directly to eval.
ComicRead-AdGuard.user.jsView on unpkg · L17266The manifest contains ordinary development scripts and no npm lifecycle hook.
package.jsonView on unpkg · L113This report applies to @hymbz/comic-read-script@12.15.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references a known benign dynamic code generation pattern.
ComicReader.umd.jsView on unpkg · L17Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
ComicRead-AdGuard.user.jsView on unpkgThe userscript downloads JavaScript from a dynamically selected host and passes the response directly to eval.
ComicRead-AdGuard.user.jsView on unpkg · L17266The manifest contains ordinary development scripts and no npm lifecycle hook.
package.jsonView on unpkg · L113