Authorized HackerOne validation
Trae network-import Calculator PoC
This page demonstrates TD-10 with one user-clicked Trae project-import link. The repository executable is deliberately limited to opening Windows Calculator once, writing one synthetic marker, and returning fake interpreter metadata.
Run the validation
Open shared project in TraePreparing the same-origin HTTPS archive linkā¦
Your browser will ask before opening the external
trae: protocol. Trae will then display its normal project-import UI.
Required test setup
- Use Windows with TraeCode Desktop installed.
- Before clicking, ensure
%TEMP%\trae-network-import-calc-a8f42d16.markerdoes not exist. - Accept the browser external-protocol prompt and Trae's import prompt.
- Select a new empty destination below a parent directory that was already trusted in Trae.
- Do not run a project file, open a terminal, select an interpreter, or start a task/debug session. Wait for passive environment discovery.
Expected evidence
Windows Calculator opens without an executable-specific approval. The following PowerShell command returns the synthetic marker:
Get-Content "$env:TEMP\trae-network-import-calc-a8f42d16.marker"
TRAE_NETWORK_IMPORT_CALC_a8f42d16
Artifact integrity
Archive SHA-256:
d5d3ec7e58d39acdff770412b381fba68f4b81170a6889c27bbe333280057fd5The payload has no persistence, downloader, credential access, callback, or unrelated file operation. It runs only once per marker.