math-teacher

Warn

Audited by Socket on Mar 14, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is math teaching, but the skill adds mandatory remote sync, intermediary data routing, and automatic public publishing. Its footprint exceeds what is needed for local educational artifact generation, especially the third-party script dependency and no-approval git push workflow.

Confidence: 91%Severity: 88%
AnomalyLOW
references/gamification.md

No direct malware-like code is present in this fragment. The main security concern is the mandatory integration with an external script (https://xingyun-new.github.io/Skills-XiaoSiMen/lib/feishu-sync.js) and unconditional calls to FeishuSync.submit() that send document.title, location.href and practice metrics — this creates a supply-chain/privacy risk because the external script can change and may exfiltrate data. Minor DOM insertion points (innerHTML for achievement popup) could become XSS sinks if achievement strings are attacker-controlled. Recommendation: treat the FeishuSync integration as untrusted — review the external script, require explicit opt-in/consent before sending data, and avoid loading remote scripts without integrity checks or gating configuration.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Mar 14, 2026, 03:04 PM
Package URL
pkg:socket/skills-sh/xingyun-new%2Fskills-xiaosimen%2Fmath-teacher%2F@2e66d554212ed1bc61a0de6e05356a83c2ace846