- User-pasted JD text / files
- CSV / JSON / JSONL job list import into Job Warehouse
- Public RSS / Atom feeds the user configures
- Public company career / listing HTML pages (rate-limited, identifiable User-Agent)
- Public ATS JSON APIs (Greenhouse / Lever / Ashby / SmartRecruiters board specs)
- Public remote job APIs the user opts into (
discover --source feeds: Remotive / Arbeitnow; configurablecontent/feeds.yml) - Local session files the user exports themselves (
session import) - User-exported job-board HTML parsed via
session scout-html --i-accept-tos-risk(no login automation) - Curated interview stems shipped in
assets/questions/*.jsonlplus user-imported JSONL (import-questions --source local)
- Login cookies / CDP automation against major job boards (Boss Zhipin, 拉勾, LinkedIn, …)
- Bulk scraping behind authentication walls (including Boss salary CDP / font bypass)
- Auto-submit applications
- Bulk Levels.fyi / OfferShow reverse-engineered crawlers — use user gateway or
comp ingest-live(seedocs/comp_live.md) - Sending OpenTelemetry traces to a remote endpoint (opt-in via env)
- Third-party Crawl4AI / JobSpy / Oxylabs as runtime dependencies (patterns may be ported first-party)
- Vendoring unlicensed 面经 dumps (e.g. 0voice/interview_internal_reference) or bulk LeetCode solution trees
Authenticated list parsing may run only when all of the following hold:
- User passes
--i-accept-tos-risk(or setsCOMPASS_ACCEPT_TOS_RISK=1). - Session material is user-provided (
content/sessions/*.storage_state.json) — Compass does not log in for you. - Code path stays under
collectors/experimental//compass_core.auth_collect(fixture HTML preferred in CI).
Real-time salary (comp lookup --live / comp refresh) may call user-configured OfferShow-compatible HTTP APIs or generic COMPASS_COMP_LIVE_URL.
- Official OfferShow / OfferHero are WeChat mini-programs; the vendor asks third parties not to bulk-scrape. Compass does not ship a WeChat reverse-engineered crawler.
- Preferred paths: configure your own gateway, or
comp ingest-livefrom a capture you exported for personal use. - Local JD salary bands (
--sources jobs) do not need network.
Compass will not implement credential stuffing, captcha farms, or ToS-bypass services.
- Collectors must refuse known login-required deep scrape targets by default (see
collectors/blocklist.json). - Never store API keys or session files in git commits under
content/. - Evidence gate: do not invent work history; mark unverifiable claims
UNVERIFIED. - Job Warehouse / MCP
jobs.searchreads local data only — not a hosted third-party 18万岗 dump. - APM: default spans stay in
logs/spans.jsonl; OTLP only whenOTEL_EXPORTER_OTLP_ENDPOINTorCOMPASS_OTEL=1. - Job intel: never present single-source or implausible salary/hours/reputation claims as facts; mark
UNVERIFIED/rejected(seedocs/intel.md).
Experimental auto-apply adapters may live under collectors/experimental/ but must stay disabled unless the user explicitly opts in and accepts ToS risk. They are out of main path.