zhongkao-yuwen

Warn

Audited by Socket on Jul 12, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
references/html-template.md

No clear standalone malware/backdoor is visible in this fragment. However, the module carries significant supply-chain and security risk: it executes a remote synchronization script (feishu-sync.js) and automatically submits detailed user performance data (including wrong student answers) to that external integration. Additionally, it uses innerHTML extensively with embedded JSON fields and user-entered content reflected into HTML without visible sanitization, creating a practical DOM-based XSS attack surface if quiz JSON or inputs can be influenced. Treat this as a medium-to-high security risk component and review both the external FeishuSync script and add output escaping/sanitization.

Confidence: 66%Severity: 78%
AnomalyLOW
SKILL.md

SUSPICIOUS: 教学出题目的本身正常,但该技能把“生成题目”默认扩展为修改仓库并公开推送到 GitHub Pages,存在不成比例的外部副作用。未见明显窃密、恶意载荷或可验证的凭证转发,因此更像高风险自动发布设计,而非确认恶意。

Confidence: 83%Severity: 68%
Audit Metadata
Analyzed At
Jul 12, 2026, 11:29 AM
Package URL
pkg:socket/skills-sh/xingyun-new%2Fskills-xiaosimen%2Fzhongkao-yuwen%2F@a2f20d7617cee2110a5c4751fd8fc30ed8c168ece9d14e2d2bc3ee709ef82358
Security Audit — socket — zhongkao-yuwen