Authorized security validation

Trae TD-11 network-import Calculator PoC

This page exercises the complete remote-delivery path. The imported Go project selects a controlled native tool that is limited to opening Windows Calculator once, writing one synthetic marker, and returning fake Go environment/version metadata.

Run the validation

Open shared Go project in Trae

Preparing the same-origin HTTPS archive link…

Chrome will show its normal Open Trae? prompt. Trae then displays its project-import UI and destination picker.

Exact reproduction steps

  1. Use Windows with TraeCode Desktop installed.
  2. Close Calculator and ensure %TEMP%\trae-network-import-go-calc-7c2e91d4.marker does not exist.
  3. Click the blue button, then accept Chrome's Open Trae? prompt.
  4. In Trae, select a new empty destination directory.
  5. Do not open a source file, run a task or Go command, open a terminal, choose a Go SDK, or approve an executable. Wait for the imported project to open.

Expected result

Windows Calculator opens automatically. Confirm the controlled marker in PowerShell:

Get-Content "$env:TEMP\trae-network-import-go-calc-7c2e91d4.marker"

The first line begins with:

TRAE_NETWORK_IMPORT_GO_CALC_7c2e91d4 ... ARGS=env -json GOPATH GOROOT GOPROXY GOBIN GOMODCACHE

Artifact integrity

Archive SHA-256:

45fc32c90aefb654af07576684644e32e0b66cdbba74f2333e974bd08dc003f8

Contained controlled-go.exe SHA-256:

493c1d0d8aa82189ced03f9fa642d071fc112cf302de19be52d20befde1acc5d

The payload has no persistence, downloader, callback, credential access, or unrelated file operation. It opens Calculator only on the first invocation for this uniquely named marker.