wgpsec/aboutsecurity
prototype-pollution-exploit
JavaScript 原型链污染漏洞利用方法论。当目标为 Node.js 应用、使用 lodash/jQuery/深拷贝函数、接收 JSON 输入时使用。覆盖 Server-side(RCE/权限绕过)和 Client-side(XSS/DOM 操控)两种场景
Installation
npx skills add https://github.com/wgpsec/aboutsecurity
Similar popular skills
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
Build multiple genuinely different versions of a UI piece you describe, rendered behind a visua…
77.5K installs构建一次性原型来回答一个设计问题。适用于用户想验证某个 state model 或 logic 是否感觉对,或探索 …
4.8K installs>- Prototype pollution testing for JavaScript stacks. Use when user input is merged into object…
2.9K installs>- Advanced prototype pollution playbook — server-side RCE, client-side gadgets, filter bypasse…
2.9K installsBuild a playable prototype in about an hour to answer one question — is it fun? — with greybox …
2.2K installsAlso in this package
Other skills from wgpsec/aboutsecurity · top by installs.
npx skills add https://github.com/wgpsec/aboutsecurity
More details
Agent compatibility
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
Repository health
master
History
- First seen on skills.sh
- First recorded snapshot · 17 installs