hunt-deserialization
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches several well-known security tools from GitHub repositories, including the
ysoserialJAR file, thephpggcrepository, and theJNDI-Exploit-Kitrepository. These are documented industry tools for security testing. - [REMOTE_CODE_EXECUTION]: The instructions describe how to download and execute remote JAR files (
ysoserial-all.jar) and clone external repositories for execution. This is part of the intended functionality for a redteaming hunting guide. - [COMMAND_EXECUTION]: The skill contains multiple shell command blocks for environment verification, payload generation (using Python, PHP, and Java), and network interactions using
curlandwgetto interact with a user-specified target and collaborator host.
Audit Metadata