web-deserialization
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation and technique guides for identifying Insecure Deserialization (CWE-502), including markers for various serialization formats such as Java, .NET, PHP, and Python.
- [SAFE]: All command examples and payload templates are intended for use with established external security tools in an authorized testing context, following industry best practices for verification.
- [SAFE]: Analysis of the skill files found no evidence of prompt injection, data exfiltration, obfuscation, or malicious persistence mechanisms targeting the agent's environment.
Audit Metadata