T09 · Insecure Skill Coding Practices
- Location
scripts/validation/completeness.js:229- Finding
Model-Controlled Property Path Enables Prototype Pollution
- Content
View full analysis
- Remediation
View remediation
{ invoice.header.invoiceNumber = value; }, 'header.invoiceDate': (invoice, value) => { invoice.header.invoiceDate = value; }, 'totals.grossTotal': (invoice, value) => { invoice.totals.grossTotal = value; }, }; function mergeRetryResults(invoice, retryResults, requestedPaths) { const allowed = new Set(requestedPaths); for (const result of retryResults) { if (!allowed.has(result.path)) { continue; } const setter = RETRY_SETTERS[result.path]; if (!setter || result.value == null || result.value === NOT_ON_DOCUMENT) { continue; } setter(invoice, result.value); } } ``` 4. Validate retry values against the expected type and format for each field before assignment. 5. Add tests using paths such as: - `__proto__.polluted` - `constructor.prototype.polluted` - `header.__proto__.polluted` - Valid but unrequested schema paths 6. Treat all model output as attacker-influenced input, even when the prompt requests an exact JSON structure. ]]>
