中小学教师智能备课助手
PassAudited by VirusTotal on Mar 31, 2026.
Findings (1)
The skill bundle is classified as suspicious primarily due to a 'Mandatory Rule' in SKILL.md that instructs the AI agent to delete all .py and .js script files after execution, which is a common anti-forensics technique to hide activity. Additionally, teaching_materials.py contains logic to solicit and store plaintext usernames and passwords for multiple external education platforms (e.g., zxxk.com, 21cnjy.com) in a local configuration file (~/.workbuddy/teaching-materials-accounts.json). While no explicit data exfiltration code was found, the combination of credential harvesting and mandatory self-deletion of the tool's logic is highly irregular for a benign teaching assistant.
