deserialization-insecure
Insecure deserialization playbook
Install / Use
npx skills add yaklang/hack-skills --skill deserialization-insecureInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Content & MediaSupported Platforms
Our assessment of deserialization-insecure
deserialization-insecure scores 79/100 on our quality scale, 612th of 814 Content & Media skills we index.
We have not analysed the SKILL.md file itself yet, so the content part of this score is an estimate until our crawler reaches it.
With 2,288 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 15 days ago, so deserialization-insecure is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
deserialization-insecure compared with similar skills
All 4 of these similar skills score higher than deserialization-insecure; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| deserialization-insecure (this skill)by yaklang | 79 | 2.3k | 15d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 86.1k | 13d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.1k | today | CLAUDE.md |
| crawl4aiby unclecode | 100 | 84.4k | 4d ago | MCP Server |
| Scraplingby D4Vinci | 100 | 84.4k | today | MCP Server |
Frequently asked questions
- How do I install deserialization-insecure?
- Run
npx skills add yaklang/hack-skills --skill deserialization-insecure. The install tabs above show the steps for each supported agent. - Which AI agents does deserialization-insecure work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is deserialization-insecure safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is deserialization-insecure still maintained?
- The repository was last updated 15 days ago, so deserialization-insecure is actively maintained.
Related Skills
Agent-Reach
86.1kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.1kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
crawl4ai
84.4kOpen-source web crawler and scraper for LLMs and AI agents: any website into clean, LLM-ready Markdown. Run it yourself, or use Crawl4AI Cloud with one key.
Scrapling
84.4k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
