exploiting-deserialization
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as an educational and procedural guide for authorized security testing of deserialization sinks. It includes format recognition tables and language-specific exploitation techniques.
- [COMMAND_EXECUTION]: Includes command-line examples for utilizing security tools like
ysoserialandphpggc. These are presented as manual steps for the user or agent to perform during a security assessment. - [DATA_EXFILTRATION]: Discusses blind detection techniques using out-of-band (OOB) interactions, such as DNS lookups via placeholder domains (e.g.,
oast.example), which is a standard industry practice for confirming vulnerabilities without direct output.
Audit Metadata