deserialization-insecure
Maintained by yaklang
Insecure deserialization playbook. Use when Java, PHP, or Python applications deserialize untrusted data via ObjectInputStream, unserialize, pickle, or similar mechanisms that may lead to RCE, file access, or privilege escalation.
- Current version
- Unknown
- License
- Unknown
- Network access
- Unknown / not assessed
- Review status
- Not verified
Problem it solves
This catalog entry helps users find and evaluate deserialization-insecure for the task described by its available catalog summary. Confirm the exact scope in the linked original source when one is available.
When to use it
Consider deserialization-insecure when its available catalog summary matches the task at hand. When available, review the linked original source before use for precise instructions, requirements, and limitations.
Installation and updates
These commands are displayed for copying only and are never executed on RefHub servers. Review the linked upstream source before running them.
npx skills add yaklang/hack-skills --skill deserialization-insecure -y
Agent compatibility
No compatibility test has been recorded
Do not assume agent compatibility until documented test evidence is available.