mirror of
https://github.com/AgentSeal/codeburn.git
synced 2026-04-30 16:09:39 +00:00
Three PoC fixtures (tool name, bash command, model name) reproduce the audit's HIGH-1 attack. Tests assert Object.prototype.calls stays undefined after parsing. They fail against current parser.ts -- Task 3 will close the pollution sink with Object.create(null). |
||
|---|---|---|
| .. | ||
| security | ||