prototype-pollution-advanced
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill provides documentation and reference materials for educational and security auditing purposes. It does not include any scripts or automated tasks that execute on the local system.
- [SAFE]: Although the skill documents functional Remote Code Execution (RCE) and Cross-Site Scripting (XSS) payloads (e.g., using
child_process.execSync), these are static examples intended for testing target applications and do not execute within the skill's own context. - [NO_CODE]: The skill consists entirely of markdown documentation and does not include any python scripts, node.js modules, or binary executables.
- [SAFE]: No evidence of credential harvesting, unauthorized data exfiltration, or persistence mechanisms was found in the skill's instructions or metadata.
Audit Metadata