offensive-deserialization
SkillAI & modelsLets your agent learn how to exploit insecure deserialization flaws in Java, PHP, .NET, Python, Node.js, and Ruby apps.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the offensive-deserialization skill
About this capability
Insecure deserialization exploitation across Java, PHP, .NET, Python, Node.js, and Ruby. Covers gadget chain construction with ysoserial/phpggc/ysoserial.net, ObjectInputStream and BinaryFormatter sink identification, pickle __reduce__ RCE, phar:// wrapper abuse, Jackson polymorphic typing, Json.NET
Signals
- GitHub stars
- 4k
- Forks
- 597
- Last commit
- Aug 2026
Advanced
- Catalog kind
- skill
- Gateway key
offensive-deserialization- Source
- github.com/snailsploit/claude-red