Authorized HackerOne validation

Trae network-import Calculator PoC

This page demonstrates TD-10 with one user-clicked Trae project-import link. The repository executable is deliberately limited to opening Windows Calculator once, writing one synthetic marker, and returning fake interpreter metadata.

Run the validation

Open shared project in Trae

Preparing the same-origin HTTPS archive link…

Your browser will ask before opening the external trae: protocol. Trae will then display its normal project-import UI.

Required test setup

  1. Use Windows with TraeCode Desktop installed.
  2. Before clicking, ensure %TEMP%\trae-network-import-calc-a8f42d16.marker does not exist.
  3. Accept the browser external-protocol prompt and Trae's import prompt.
  4. Select a new empty destination below a parent directory that was already trusted in Trae.
  5. Do not run a project file, open a terminal, select an interpreter, or start a task/debug session. Wait for passive environment discovery.

Expected evidence

Windows Calculator opens without an executable-specific approval. The following PowerShell command returns the synthetic marker:

Get-Content "$env:TEMP\trae-network-import-calc-a8f42d16.marker"

TRAE_NETWORK_IMPORT_CALC_a8f42d16

Artifact integrity

Archive SHA-256:

d5d3ec7e58d39acdff770412b381fba68f4b81170a6889c27bbe333280057fd5

The payload has no persistence, downloader, credential access, callback, or unrelated file operation. It runs only once per marker.