claude-skill-antivirus 在扫描本地技能目录时,无法分析可执行文件:它仅读取 ,却忽略了 目录中的 Python 源代码、字节码及其他产物。 攻击者可以分发包含恶意代码的非清单文件(即未被 列出的文件),这些文件虽然含有未分析的可执行载荷,但系统仍会对其做出“安全”判定,并给出 100/100 的满分信任评分。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| claude-world | claude-skill-antivirus | ≤ 2.1.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| claude-world | claude-skill-antivirus | 0 ~ 2.1.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet