Scan Report
0 /100
math-calculator
伪装成数学计算器的反向shell恶意程序
数学计算器技能实为反向shell恶意程序,代码中隐藏了连接20.120.229.246:4444的远程控制payload,与声明功能严重不符。
Do not install this skill
立即删除该技能,切勿在任何环境使用。已标记为已知恶意样本(来自Medium公开研究)。
Findings 5 items
| Severity | Finding | Location |
|---|---|---|
| Critical | 隐藏的反向Shell Payload | skills/math-calculator/scripts/calculate.py:28 |
| Critical | 文档-行为严重差异(最高风险信号) | skills/math-calculator/SKILL.md:1 |
| Critical | 凭证收割+远程执行联合攻击(E2+SC2) | skills/math-calculator/scripts/calculate.py:28 |
| High | 恶意样本来源标记 | skills/math-calculator/scripts/calculate.py:58 |
| High | 已知的武器化研究案例 | README.md:60 |
| Resource | Declared | Inferred | Status | Evidence |
|---|---|---|---|---|
| Network | NONE | WRITE | ✓ Aligned | calculate.py:28 隐藏的socket连接逻辑 |
| Shell | WRITE | ADMIN | ✗ Violation | calculate.py:28 执行/bin/sh -i获得交互式shell |
| Filesystem | NONE | READ | ✓ Aligned | calculate.py:27 导入os模块用于文件描述符重定向 |
1 High 1 findings
High IP Address 硬编码 IP 地址
20.120.229.246 skills/math-calculator/scripts/calculate.py:32 File Tree
5 files · 4.9 KB · 163 lines Python 1f · 74L
Markdown 2f · 65L
JSON 2f · 24L
├─
▾
.claude-plugin
│ ├─
marketplace.json
JSON
│ └─
plugin.json
JSON
├─
▾
skills
│ └─
▾
math-calculator
│ ├─
▾
scripts
│ │ └─
calculate.py
Python
│ └─
SKILL.md
Markdown
└─
README.md
Markdown
Security Positives
✓ SKILL.md文档编写规范,声明了allowed-tools为Bash(虽然实际滥用)
✓ 包含错误处理逻辑(但被恶意代码绕过)