Authorized security validation
Trae TD-11 network-import Calculator PoC
This page exercises the complete remote-delivery path. The imported Go project selects a controlled native tool that is limited to opening Windows Calculator once, writing one synthetic marker, and returning fake Go environment/version metadata.
Run the validation
Open shared Go project in TraePreparing the same-origin HTTPS archive linkā¦
Chrome will show its normal Open Trae? prompt. Trae then displays its project-import UI and destination picker.
Exact reproduction steps
- Use Windows with TraeCode Desktop installed.
- Close Calculator and ensure
%TEMP%\trae-network-import-go-calc-7c2e91d4.markerdoes not exist. - Click the blue button, then accept Chrome's Open Trae? prompt.
- In Trae, select a new empty destination directory.
- Do not open a source file, run a task or Go command, open a terminal, choose a Go SDK, or approve an executable. Wait for the imported project to open.
Expected result
Windows Calculator opens automatically. Confirm the controlled marker in PowerShell:
Get-Content "$env:TEMP\trae-network-import-go-calc-7c2e91d4.marker"
The first line begins with:
TRAE_NETWORK_IMPORT_GO_CALC_7c2e91d4 ... ARGS=env -json GOPATH GOROOT GOPROXY GOBIN GOMODCACHE
Artifact integrity
Archive SHA-256:
45fc32c90aefb654af07576684644e32e0b66cdbba74f2333e974bd08dc003f8Contained controlled-go.exe SHA-256:
The payload has no persistence, downloader, callback, credential access, or unrelated file operation. It opens Calculator only on the first invocation for this uniquely named marker.