zhongkao-yuwen
Audited by Socket on Jul 12, 2026
2 alerts found:
SecurityAnomalyNo clear standalone malware/backdoor is visible in this fragment. However, the module carries significant supply-chain and security risk: it executes a remote synchronization script (feishu-sync.js) and automatically submits detailed user performance data (including wrong student answers) to that external integration. Additionally, it uses innerHTML extensively with embedded JSON fields and user-entered content reflected into HTML without visible sanitization, creating a practical DOM-based XSS attack surface if quiz JSON or inputs can be influenced. Treat this as a medium-to-high security risk component and review both the external FeishuSync script and add output escaping/sanitization.
SUSPICIOUS: 教学出题目的本身正常,但该技能把“生成题目”默认扩展为修改仓库并公开推送到 GitHub Pages,存在不成比例的外部副作用。未见明显窃密、恶意载荷或可验证的凭证转发,因此更像高风险自动发布设计,而非确认恶意。