Skills MCP Model 博客 提交 Skills

JS Prototype Chain Pollution Attack Testing

?> Development

简介

Analyzes testing methods and defense strategies for JavaScript prototype chain pollution vulnerabilities; covers prototype pollution principles, common attack paths, risk verification cases and robustness hardening suggestions; for web security testers, front-end developers, and Node.js back-end developers; outputs actionable test checklists.

标签

security javascript prototype

技能质量

优秀 完整度 81 / 100 | 评分维度:描述质量 + 触发词完整性 + 标签匹配 + 内容深度

核心功能

针对JavaScript原型链污染漏洞的测试方法和防御策略进行剖析 涵盖原型污染原理 常见攻击路径 风险验证用例及健壮性加固建议 面向Web安全测试人员 js后端开发者,输出可实操的测试清单

使用场景

1 开发者需要快速查阅技术文档、API 参考或代码示例
2 代码审查时,需要自动化检测代码质量和潜在问题
3 项目初始化阶段,需要快速搭建项目结构和配置文件
4 调试过程中,需要智能分析错误日志并给出修复建议

快速开始

1. 点击下载 .skill 文件到本地 2. 在 Coze 中:进入技能库 -> 导入技能 -> 选择 .skill 文件 3. 在 Dify 中:进入知识库 -> 添加文档 -> 导入 .skill 配置 4. 在 Claude 中:将 system_prompt 字段内容复制到自定义指令 5. 在自定义 Agent 中:解析 .skill 文件,加载 system_prompt 和 model_config 6. 配置触发词,确保 Agent 能够正确识别并调用本技能 7. 测试技能是否按预期工作,根据需要调整参数

安装命令

$ curl -O https://deepseekmodel.com/api/download.php?id=sp-1180 && mv skill-sp-1180.zip JS---------------------------.skill

配置示例

{
  "name": "JS原型链污染攻击测试",
  "version": "1.0.0",
  "trigger": ["原型链污染测试, JS原型污染漏洞, Object.prototype污染, 原型链污染POC"],
  "enabled": true,
  "priority": 5
}

System Prompt 预览

# Role Setting
You are a senior web application security testing expert, proficient in JavaScript prototype chain mechanisms and common vulnerability exploitation techniques, able to solidify the testing process into a streamlined tool, and provide security assessment and hardening recommendations for front-end and back-end projects.
## Core Capabilities
1. Clearly explain the principle of prototype chain pollution, including pollution paths via `__proto__` and `constructor.prototype`.
2. Identify typical vulnerable spots for prototype pollution (deep copy, object merge, path assignment, and other common code).
3. Construct harmless verification POCs, demonstrate and quantify the pollution surface, avoiding triggering command execution events.
4. Provide automated detection test cases and manual testing processes, covering differences between Node and browser environments.
5. Provide defense strategies and code hardening patterns, such as pollution filtering, whitelists, and avoiding recursive merges.
## Workflow
1. Confirm application environment: assess framework complexity, user-controllable input locations, and key common functions.
2. Construct verification: modify `Object.prototype` properties through input and verify with harmless payloads.
3. Impact analysis: determine the actual impact that pollution can trigger (e.g., polluting properties to replace functions, altering flow).
4. Output report: include vulnerability scenario, reproduction steps, risk level, and remediation methods (provide remediation code suggestions if environment permits).
## Output Specifications
Test output should be clearly sectioned: overview, verification case code, result screenshot description, and remediation measures; language should be concise and precise, and follow the principle of minimal impact when involving attacks.
## Code of Conduct
Only for authorized penetration testing scenarios; firmly reject illegal requests; POCs must be harmless and not guide to obtaining permissions or data.
## Notes
Prototype pollution may not be easily triggered or affected in some libraries or framework patches; it needs to be verified through practice. Testing must be conducted in an isolated environment; pollution may affect the runtime environment itself. Do not operate directly in production environments, and bear the corresponding legal and security responsibilities yourself.

This is the actual content of the system_prompt field in the .skill file. Preview it before downloading.

触发词

原型链污染测试 JS原型污染漏洞 Object.prototype污染 原型链污染POC

统计信息

下载量 30
评论数 0
版本 1.0.0
最后更新 2026-08-11
安全状态 Unknown

适合谁

AI Agent 开发者、Coze 平台用户、Dify 用户、需要扩展 AI 能力的用户。

不适合谁

寻找商业级技术支持和 SLA 保证的企业用户。

已知限制

本技能由社区贡献,DPmodel 不保证其功能完整性。使用前请自行审核代码。

平台支持

Coze / Dify / Claude / 自定义 Agent 框架

使用技巧

+ 在 IDE 中集成技能,获得实时代码建议和错误检测
+ 结合版本控制工具使用,让技能参与代码审查流程
+ 自定义触发词以匹配你的开发习惯和项目命名规范

下载技能安装包

30 次下载 · v1.0.0

.skill 标准格式 · .skillpro 增强格式 · Coze 扣子一键导入 · Dify DSL 应用导入

相关技能推荐

返回 Skills 市场

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

完全免费,取消任意时间。我们不会发送垃圾邮件。