1point3acres-toolkitSAFE
一亩三分地自动签到 + 每日答题:在你自己电脑的 Chrome 里、用你自己的登录完成,不经过第三方;也是给 Claude Code / Codex 用的 MCP 服务。1point3acres daily check-in & quiz automation, local-only, plus an MCP server for AI assistants.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
本机自动签到、答题,并核对大米到账。
在你自己的电脑上、用你自己的账号完成,不经过任何第三方。
[](https://pypi.org/project/1point3acres-toolkit/) [](https://github.com/vivian-labs/1point3acres-toolkit/actions/workflows/consistency.yml) [](LICENSE)
它每天做什么 · 怎么工作 · 安全与隐私 · 快速开始 · 常见问题 · 给开发者
每天自动帮你完成一亩三分地(1point3acres)的 签到 和 每日答题,成功以当天两项奖励记录为准。电脑可用、登录和网站验证正常、答案能够确定时可自动完成;异常会保留真实状态。它不是把账号交给某个服务器代跑,而是在你电脑上开一个专用的 Chrome,用你自己的登录,按网站流程点按钮,点完还会去积分页确认大米真的到账。
支持 macOS 和 Windows,只需要装好 Chrome 和 Python 3.12。签到答题之外,它还能采集面经、离线搜索、发帖回复,并能接给 Claude Code、Codex 这类 AI 助手用。这些是附加功能,不装不影响签到答题。
[!NOTE] 本文讲「它是怎么做的」;具体命令、参数和排错步骤都在 使用说明。
最近更新
- 1.3.0:发布与自动更新串联。 版本号提升并合并到
main后,通过完整 CI 才会自动上传 PyPI;核对上传文件后,才创建对应的 GitHub Release。定时任务使用uvx ...@latest时,下次启动即可获取已发布新版;旧 MCP 首次升级启动器需要重连。普通代码提交不会单独发包,发布结果以 发布工作流 为准。 - 修复签到、答题按钮和后台输入。 提交按钮改为浏览器原生输入,解决网页拒绝 JavaScript 合成点击的问题;后台窗口保持页面焦点,避免输入和验证回调暂停,同时不抢桌面焦点。这不保证自动化无法被网站识别。
- 离线日记语料与全年去重。 从带来源说明的离线语料中选择现代文字或诗句,避开过去 365 天重复及高度相似内容;语料耗尽时留空。可配置风格,也可关闭随机心情和公开短句。见 语料说明。
- CLI / MCP 业务代码自动更新。 启动器只使用 main 上通过 CI 的提交;CLI 在业务命令前检查,常驻 MCP 在空闲时切换后台进程。包含 Windows 标准输入输出修复;离线诊断不触发更新。
- 离线版本诊断。 命令行
info和 MCP 工具runtime_info可以核对磁盘源码、当前进程加载的版本与调度配置,发现更新后仍在运行的旧进程。见 更新与维护。 - Windows 定时任务。 仓库版提供
计划.ps1,支持预览、安装、查看状
e10973afeab0OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add 1point3acres-toolkit -- uvx 1point3acres-toolkit==1.3.1
Exposed tools (3)
2 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
collect_company | read | 为指定公司做一次有界的面经采集并存入本地资料库(写本机数据库,不改变站点状态)。发现来源二选一:不给 listing 时用站内搜索(query 默认为公司名);listing 为本站 /bbs/tag/<标签>.html 公司标签页。公司归属按证据而不按请求:标签页的行归属该公司(company_match=tag);搜索命中只有标题含公司名才归属(title),否则记录保存为未标注公司并报 unconfirmed,由人决定是否用 save_thread 加标签。每个结果带 discovery 来源、company_match 与处理状态;重复 tid 去重;部分失败时整批不报 complet |
organize_thread | read | 把资料库里已保存的一个帖子整理成可复习的轮次与题目条目,纯本地、不访问站点、不修改原记录。thread 为 tid 或本站帖子地址,必须已用 save_thread 或采集入库,否则 thread_not_in_library。每条轮次/题目都带来源 pid 与原文摘录(逐字),attribution 区分 author(楼主本人)与 reply(网友),certainty 标出带推测语气的句子(speculated),不把网友推测写成楼主经历。提取是规则式的(method=rule_based_review_required),需要人工核对;没有轮次/题目/岗位/级别或正文受限时列入 mis |
save_thread | write | 把一个指定帖子保存进本地资料库,之后可用 interviews_search 查询、由现有导出读取。get_thread_detail 只返回快照不入库;这是显式的保存动作,写本机数据库、不改变站点状态。thread 为 tid 或本站帖子地址。company 可选,是调用方声明的公司元数据(company_source=caller),不填则保持未标注(null);记录已有标签时不填不会抹掉标签。已保存且分页完整的记录默认直接复用(reused=true)不再读取,refresh=true 强制重读并遵守既有版本保留规则:不完整刷新不覆盖更完整旧版。每页都以同一事务落库,中断后 resume |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (9)
if local.get(f'http://127.0.0.1:{port}/json/version', timeout=1).ok:for value in ['', ' ', 'abc', '-1', '../../etc/passwd',
PY="$DIR/../../work/cf-probe-venv/bin/python"
PY="$DIR/../../work/cf-probe-venv/bin/python"
return base64.b64decode(self._cdp(mycdp.page.capture_screenshot(format_='png')))
body = base64.b64decode(body).decode('utf-8')return {'mime': response['mime'], 'data': base64.b64decode(response['data'])}data = base64.b64decode(body) if encoded else body.encode('utf-8')outputs/一亩三分地本地工具/journal-corpus.json
Gates applied: no_behavioural_pass.
e10973afeab0full audit observations/trust-audit/mcp-server/vivian-labs__1point3acres-toolkit.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | e10973afeab0 | SAFE | B | 89 | first audit |
Questions
What is the 1point3acres-toolkit MCP server?
一亩三分地自动签到 + 每日答题:在你自己电脑的 Chrome 里、用你自己的登录完成,不经过第三方;也是给 Claude Code / Codex 用的 MCP 服务。1point3acres daily check-in & quiz automation, local-only, plus an MCP server for AI assistants.
What tools does 1point3acres-toolkit expose?
3 in total: 2 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is 1point3acres-toolkit safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does 1point3acres-toolkit need?
No credential environment variables were found in its source, so it appears to need none.
How does 1point3acres-toolkit run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as 1point3acres-toolkit.
How current is this page?
The grade is for one exact copy of the source (e10973afeab0), read on 2026-10-07. The repository is watched and re-audited when it changes.