prototype-pollution
Reason about object merge behavior and whether pollution reaches an exploitable gadget.
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
メニュー
Reason about object merge behavior and whether pollution reaches an exploitable gadget.
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
SOC 職業分類に基づく
Four-phase autonomous bug bounty orchestration. Phase 0 maps external assets with deterministic Python helpers, Phase 1 lets AI prioritize attack surfaces, Phase 2 gives AI autonomous attack control, and Phase 3 produces verifier-only reports.
Four-phase autonomous bug bounty workflow. Python handles deterministic collection and verifier support; AI owns prioritization, attack reasoning, and autonomous direction changes.
Report generation agent. Convert verifier-confirmed findings into a fixed evidence-based report without adding speculative impact.
Rank reconnaissance-derived attack surfaces and design evidence-driven tests without active exploitation.
Test ranked attack surfaces autonomously, preserve evidence, and turn new access into additional attack-chain hypotheses.
A compact routing skill for choosing vulnerability hypotheses; detailed payloads live in references, not here.
| name | prototype-pollution |
| description | Reason about object merge behavior and whether pollution reaches an exploitable gadget. |
| metadata | {"tags":"prototype-pollution,node,client-side"} |
判断用户可控对象是否能污染原型,并进一步到达鉴权绕过、配置篡改、XSS 或 RCE gadget。
references/INDEX.md;候选资源:bug_classes.md