web-deserialization

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and technique guides for identifying Insecure Deserialization (CWE-502), including markers for various serialization formats such as Java, .NET, PHP, and Python.
  • [SAFE]: All command examples and payload templates are intended for use with established external security tools in an authorized testing context, following industry best practices for verification.
  • [SAFE]: Analysis of the skill files found no evidence of prompt injection, data exfiltration, obfuscation, or malicious persistence mechanisms targeting the agent's environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 11:02 PM
Security Audit — agent-trust-hub — web-deserialization