phy-deserialization-auditUnsafe deserialization vulnerability scanner (OWASP A08:2021). Detects Python pickle/yaml/eval, Java ObjectInputStream/XStream/XMLDecoder, PHP unserialize, R...
Install via ClawdBot CLI:
clawdbot install phy041/phy-deserialization-auditGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://canlah.aiAudited Sep 5, 2026 · audit v1.0
Generated Sep 5, 2026
A security consultant conducts a comprehensive audit of a client's web application to identify insecure deserialization vulnerabilities in Python, Java, PHP, Ruby, Node.js, and Go codebases before deployment.
Development teams integrate this scanner into their CI/CD pipeline to catch deserialization vulnerabilities early in the development process, ensuring code is secure before production release.
A DevOps team uses the scanner to audit cloud-native applications built with multiple languages (e.g., microservices) for deserialization issues, reducing risk of remote code execution in containerized environments.
A bank's security team performs a targeted review of legacy and modern applications handling sensitive financial data, focusing on deserialization attack vectors to meet regulatory compliance and protect customer assets.
An e-commerce company assesses its payment processing and user profile modules for insecure deserialization flaws that could lead to data breaches, ensuring secure online transactions and customer trust.
Offer the scanner for free to individual developers and small teams, with premium features (e.g., advanced reporting, CI integration, multi-project support) via subscription tiers for larger organizations.
Provide the scanner as part of a managed security audit service where experts analyze results and deliver detailed reports, remediation guidance, and compliance documentation for clients.
Open-source the core scanner to build community trust and adoption, monetize through paid support, custom feature development, and integration services for enterprise clients.
💬 Integration Tip
Integrate as a pre-commit hook or CI job to automatically scan code changes for deserialization risks.
Scored Sep 5, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...