Skip to main content

exploit-deserialization

Insecure deserialization — RCE via malicious serialized objects in Java (ysoserial), PHP (PHPGGC), .NET (ysoserial.net), and Python (pickle). Covers gadget chain selection, payload generation, and injection into cookies, POST bodies, ViewState, and API endpoints.

Jump to install

Source facts

Repository
PurpleAILAB/Decepticon
Last source activity
June 2, 2026 at 18:57
Detected SKILL.md language
English
Stars
5,128
Forks
990

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.