deserialization-insecure
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent as an insecure-deserialization exploit playbook, but that stated purpose is itself an offensive security capability set for an AI agent. It teaches active exploitation, uses known callback/exfiltration endpoints, and enables command-execution payload generation across many ecosystems. I do not see confirmed malware or a real load-time pre-execution payload in the provided text, but the skill is still high risk and unsuitable for general agent use.
Confidence: 93%Severity: 91%
Audit Metadata