本文へ移動
cccskills
無料GitHub で公開

prototype-pollution

Detect prototype pollution via object merge/clone/assign operations where __proto__ or constructor.prototype keys can modify Object.prototype.

インストール方法を見る

含まれるファイル(4)

  • SKILL.md3.0 KB
  • references/false-positive-indicators.md945 B
  • references/poc-skeleton.md1.7 KB
  • references/sinks.md1.3 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Prototype Pollution Detection

When to Use

Audit merge/clone/deep-assign utilities, query string parsers, JSON parsers, config mergers, and any package that recursively sets object properties from untrusted input.

Key insight: Only ~50% acceptance rate. Must demonstrate REAL impact beyond just polluting prototype.

Process

Step 1: Find Object Manipulation Sinks

grep -rn "Object\.assign\|Object\.defineProperty\|Object\.create" .
grep -rn "merge\|extend\|deepMerge\|deepExtend\|deepAssign\|mixin" .
grep -rn "clone\|deepClone\|cloneDeep\|deepCopy" .
grep -rn "set\|setPath\|setValue\|lodash\.set\|_.set" .
grep -rn "\[.*\]\s*=" . --include="*.js"  # Bracket notation assignment

Step 2: Check for Recursive Property Setting

Look for patterns where object keys from user input are used as property paths:

// VULNERABLE: recursive merge without key filtering
function merge(target, source) {
  for (const key in source) {
    if (typeof source[key] === 'object') {
      target[key] = merge(target[key] || {}, source[key]);
    } else {
      target[key] = source[key];
    }
  }
}

Step 3: Check Key Filtering

grep -rn "__proto__\|constructor\|prototype" . | grep -i "filter\|block\|skip\|ignore\|reject"
grep -rn "Object\.create(null)" .  # Null prototype objects are safe
grep -rn "hasOwnProperty\|Object\.keys\|Object\.entries" .

Step 4: Assess Impact

Prototype pollution alone is often not enough. Look for impact:

  • DoS: Polluted property causes TypeError crash (toString, valueOf)
  • Property injection: Polluted property affects security logic (isAdmin, role, auth)
  • Gadget chains: Polluted property reaches dangerous sink (eval, template)
  • Method clobbering: toString/valueOf overwritten causing crash

Dangerous Keys

KeyEffectImpact
__proto__Sets properties on Object.prototypeAll objects affected
constructor.prototypeSame effect via constructor chainAll objects affected
constructorOverwrites constructor referenceType confusion
toStringOverwrites string conversionTypeError on string operations
valueOfOverwrites value conversionTypeError on comparisons
hasOwnPropertyOverwrites property checkLogic bypass

CVSS Guidance

  • Proto pollution + RCE gadget chain: CRITICAL 9.8
  • Proto pollution + auth bypass: HIGH 8.1
  • Proto pollution + DoS (crash): HIGH 7.5
  • Proto pollution with no demonstrated impact: MEDIUM 5.3 (often rejected)

References

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

You are helping a penetration tester exploit misconfigured Active Directory

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

You are helping a penetration tester enumerate an Active Directory domain and

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

You are helping a penetration tester establish persistent access in Active

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

You are helping a penetration tester exploit ADCS through template/CA access

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

You are helping a penetration tester establish persistence through AD CS

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

You are helping a penetration tester exploit misconfigured AD CS certificate

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

ajtazer のスキルをすべて見る

このスキルの問題を報告する