prototype-pollution-advanced
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONOBFUSCATIONDATA_EXFILTRATION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill documents numerous payloads for achieving code execution through prototype pollution gadgets in popular server-side template engines such as EJS, Pug, Handlebars, and Nunjucks. Evidence includes payloads targeting properties like
outputFunctionName,block, and AST nodes. - [COMMAND_EXECUTION]: The playbook outlines techniques for injecting shell commands into Node.js applications by polluting global prototype properties like
shell,argv0, andNODE_OPTIONS, which are subsequently inherited bychild_processfunctions. - [OBFUSCATION]: The instructions describe common filter bypass techniques used by attackers, including Unicode null byte escapes (
\u0000) in JSON keys, the use ofconstructor.prototypeas an alternative path to__proto__, and bracket notation variants. - [DATA_EXFILTRATION]: The skill mentions detection methodologies using response differentials, where an attacker modifies HTTP headers (like
Content-Type) or status codes (e.g., settingstatusto 555) via prototype pollution to confirm successful injection.
Audit Metadata