Skill Wiki v0.1.0
anti-pattern @community/anti-pattern-eval-user-input

Eval User Input

Passing user-controlled strings directly to dynamic code evaluators — JavaScript eval(), Function constructor, Python exec()/eval(), Ruby eval/instance_eval, PHP eval() — resulting in arbitrary code execution.

Skill
@community
Domain
security
Version
1.0.0
Quality
4.0
Edges
4 out · 3 in
Tokens
66/381/696
$ prime install @community/anti-pattern-eval-user-input

Projection

Always in _index.xml · the agent never has to ask for this.

EvalUserInput [anti-pattern] v1.0.0

Passing user-controlled strings directly to dynamic code evaluators — JavaScript eval(), Function constructor, Python exec()/eval(), Ruby eval/instance_eval, PHP eval() — resulting in arbitrary code execution.

Source

prime-system/examples/frontend-design/primes/compiled/@community/anti-pattern-eval-user-input/atom.yaml

Compiled at 2026-05-07