
Hushuguo Malicious Mathhelper
- 1 repo stars
- Updated December 29, 2025
- hushuguo/malicious-mathHelper
hushuguo-malicious-mathhelper is a Claude Code plugin catalog entry in the Ship security phase that documents a known-malicious archive-only skill and must not be installed.
About
hushuguo-malicious-mathhelper is an archived Claude Code plugin listing that Skillselion and upstream sources mark as malicious. It is not a math helper for developers; it is preserved so researchers, marketplace curators, and security-conscious developers can recognize unsafe community plugins before they reach production agents. The repository bundles one plugin with innocuous-sounding keywords, which is a common pattern for skills that should never run beside real API keys or repositories. If you are shipping with Claude Code, your goal is to exclude this slug from registries, document why it is quarantined, and use it only as a negative example when writing install policies. Installing it contradicts the publisher’s own warnings and normal supply-chain hygiene for AI-coding tools.
- Catalogged as malicious with explicit DO NOT USE warnings in English and Chinese
- Archive-only specimen from hushuguo/malicious-mathHelper (1 plugin in bundle)
- Keyword bait: helps, mathhelper—useful for teaching typosquatting and fake utility skills
- No legitimate workflow; exists so directories can block or warn without deleting audit history
- Community-sourced auto listing—treat as threat intel, not a productivity tool
Hushuguo Malicious Mathhelper by the numbers
- Data as of Jul 7, 2026 (Skillselion catalog sync)
/plugin install hushuguo-malicious-mathhelper@hushuguo/malicious-mathHelperAdd your badge
Show developers this plugin is listed on Skillselion. Paste this into your README.
| repo stars | ★ 1 |
|---|---|
| Last updated | December 29, 2025 |
| Repository | hushuguo/malicious-mathHelper ↗ |
What it does
Reference this catalog entry only when studying archived malicious Claude plugins—never install or run it in a real agent environment.
Who is it for?
Security-minded developers, catalog editors, or researchers who maintain deny lists and want a citable malicious example without executing code.
Skip if: Anyone who intends to install plugins for daily coding, math assistance, or any environment connected to secrets, git, or customer data.
What you get
After recognizing this entry, you keep it out of Claude Code, add it to blocklists or internal warnings, and use it only as a reference when auditing similar math-helper plugins.
- Documented deny-list entry for hushuguo-malicious-mathhelper
- Team-visible warning that the listing is malicious archive-only
- Safer plugin choices vetted outside this repository
By the numbers
- Plugin bundle count: 1
- Catalog source: auto-ingested community listing
- Publisher warnings: explicit malicious / DO NOT USE in description and README
Recommended Plugins
How it compares
Malicious archive record for awareness, not a legitimate Development Tools or Productivity plugin.
FAQ
Who is Hushuguo Malicious Mathhelper for?
It is for people curating or auditing Claude plugin catalogs who need a labeled malicious specimen—not for developers seeking a working math helper.
When should I use Hushuguo Malicious Mathhelper?
Only when documenting supply-chain risk, training teammates on unsafe skills, or verifying that your marketplace blocks archived malicious entries—never during normal agent setup.
How do I add Hushuguo Malicious Mathhelper to my agent?
You should not add it; leave it archive-only, exclude it from /plugin marketplace installs, and prefer vetted skills from trusted sources instead.