prototype-pollution

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a static analysis and educational resource for identifying prototype pollution vulnerabilities. All instructions and patterns are consistent with its stated purpose.
  • [SAFE]: The provided grep and semgrep patterns are intended for local code analysis and do not include any malicious payloads or command injection vectors.
  • [SAFE]: The JavaScript templates in the PoC skeleton are educational examples designed to illustrate vulnerability concepts (DoS, auth bypass) and do not contain hardcoded credentials, exfiltration logic, or unauthorized remote execution commands.
  • [SAFE]: No obfuscation, prompt injection, or persistence mechanisms were detected in the skill files or metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 05:07 PM
Security Audit — agent-trust-hub — prototype-pollution