deserialization-insecure

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an insecure-deserialization exploit playbook, but that stated purpose is itself an offensive security capability set for an AI agent. It teaches active exploitation, uses known callback/exfiltration endpoints, and enables command-execution payload generation across many ecosystems. I do not see confirmed malware or a real load-time pre-execution payload in the provided text, but the skill is still high risk and unsuitable for general agent use.

Confidence: 93%Severity: 91%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:15 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fdeserialization-insecure%2F@a3fb4dd26aa3cafeb61e723737eed103750a484e64c8cc5859716a1f59b87206
Security Audit — socket — deserialization-insecure