Phy Deserialization Audit

Unsafe deserialization vulnerability scanner (OWASP A08:2021). Detects Python pickle/yaml/eval, Java ObjectInputStream/XStream/XMLDecoder, PHP unserialize, Ruby Marshal.load, Node.js eval/new Function/vm, Go gob with interface{}. Traces HTTP input sources to dangerous sinks, classifies CRITICAL/HIGH/MEDIUM, outputs CWE/CVE mappings and per-language fix snippets. Zero competitors on ClawHub.

LeoYeAI Updated

File contents

LeoYeAI/openclaw-master-skills/tree/main/skills/phy-deserialization-audit commit 6fb607e952

Frequently asked questions

npx skillmds@latest add leoyeai-openclaw-master-skills/phy-deserialization-audit