Run3 logic neutralization
Neutralizing malicious logic by modifying class deserialization behaviors.From its SKILL.md
npx -y skills add cxcscmu/SkillLearnBench --skill run3_logic-neutralizationAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
SKILL.md
0.9 KB, 161 tokens by cl100k_base, as published. Nobody here has run it
When the JavaScriptConfig is deserialized, the ObjectMapper calls methods annotated with @JsonProperty or fields matched by default. To neutralize the "" key:
- Identify the specific constructor or setter in
JavaScriptConfig.javathat handles the""key. - Replace or wrap the mapping logic to strictly reject empty keys.
- If
JavaScriptConfiguses a builder pattern, ensure thebuild()method enforces a non-null, non-empty state for configuration properties, effectively preventing an attacker from toggling theenabledstate via malformed input. - Verify there are no other
JsonSettermethods or custom deserializers in theprocessingmodule that permit empty string property names, which could be used as an alternative vector.
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.