I thank Khan Janny (@Reboot_Ex) who spotted a cross-site-scripting vulnerability on rskey.org and posted it to the Open Bug Bounty Web site. The vulnerability is now fixed (I hope).