agentsclimarketplace

Run3 logic neutralization

Skill cxcscmu/SkillLearnBench/skills/b3-teacher-feedback-gemini-3.1-flash-lite-preview/fix-security-bug/run3_logic-neutralization

Neutralizing malicious logic by modifying class deserialization behaviors.From its SKILL.md

Install
npx -y skills add cxcscmu/SkillLearnBench --skill run3_logic-neutralization

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

SKILL.md

0.9 KB, 161 tokens by cl100k_base, as published. Nobody here has run it

When the JavaScriptConfig is deserialized, the ObjectMapper calls methods annotated with @JsonProperty or fields matched by default. To neutralize the "" key:

  1. Identify the specific constructor or setter in JavaScriptConfig.java that handles the "" key.
  2. Replace or wrap the mapping logic to strictly reject empty keys.
  3. If JavaScriptConfig uses a builder pattern, ensure the build() method enforces a non-null, non-empty state for configuration properties, effectively preventing an attacker from toggling the enabled state via malformed input.
  4. Verify there are no other JsonSetter methods or custom deserializers in the processing module that permit empty string property names, which could be used as an alternative vector.

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.