deserialization-insecure

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as an expert-level technical reference and instructional guide for security professionals. It does not contain any instructions that override safety filters or perform malicious actions against the user environment.
  • [COMMAND_EXECUTION]: The skill provides numerous command-line examples for security assessment tools such as ysoserial, phpggc, nmap, and ysoserial.net. These are intended as templates for manual execution by a researcher against target systems and are not autonomously executed by the agent on the host system.
  • [CREDENTIALS_UNSAFE]: Mentions a list of publicly known default cryptographic keys for Apache Shiro (CVE-2016-4437). These are included for the purpose of identifying known vulnerabilities in target applications and do not represent a leak of the user's or the author's private or sensitive credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines procedures for analyzing untrusted data, such as binary blobs and serialized objects. While this activity represents a theoretical surface for indirect prompt injection, it is a standard component of the security analysis domain the skill serves. The instructions focus on fingerprinting and technical analysis rather than executing commands contained within the analyzed data.
  • Ingestion points: User-supplied binary data or encoded objects for deserialization analysis (e.g., Section 5 'Detection Methodology').
  • Boundary markers: Absent; the skill relies on manual identification of magic bytes.
  • Capability inventory: Generation and execution of tool payloads (ysoserial, phpggc) based on analyzed input.
  • Sanitization: Not applicable; the data is intended for forensic analysis and exploit generation rather than direct system processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 01:24 PM
Security Audit — agent-trust-hub — deserialization-insecure