exploiting-prototype-pollution-in-javascript
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a technical guide for security professionals. All provided commands and code snippets are instructional templates for testing external target applications.
- [COMMAND_EXECUTION]: The skill documents the use of
curlfor interacting with web APIs andppfuzz/nucleifor automated scanning. These are standard security tools, and the examples use neutral placeholder domains (e.g.,target.com). - [REMOTE_CODE_EXECUTION]: While the skill contains payloads intended to demonstrate RCE (e.g., via EJS or Pug template engines), these are presented as data to be sent to a target system during a security audit and do not execute within the skill's own environment.
Audit Metadata