Install the "hunt-deserialization" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-deserialization into .claude/skills/hunt-deserialization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-deserialization", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill hunt-deserialization -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "hunt-deserialization" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-deserialization into .agents/skills/hunt-deserialization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-deserialization", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill hunt-deserialization -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "hunt-deserialization" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-deserialization into .cursor/skills/hunt-deserialization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-deserialization", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill hunt-deserialization -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "hunt-deserialization" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-deserialization into .gemini/skills/hunt-deserialization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-deserialization", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill hunt-deserialization -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "hunt-deserialization" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-deserialization into .github/skills/hunt-deserialization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-deserialization", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill hunt-deserialization -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "hunt-deserialization" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/hunt/hunt-deserialization into .opencode/skills/hunt-deserialization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-deserialization", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Works in 2 steps: Locate serialized data (decode base64,… → Java
Security work in your project
SKILL.md covers Wiki, Confirmation gate, Attack surface signals and Methodology, plus 4 more sections
Calls java and python3
What it does
Hunt Deserialization is an agent skill from Encod3d-Sec/TORCH. Insecure deserialization hunting across Java / .NET / PHP / Python / Ruby / Node. Gadget-chain RCE, OOB-gated blind detection, magic-byte fingerprinting. Wiki-first, FIND schema output.
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security. It works with Java, PHP, Python and Ruby. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.
When your agent uses it
Security work in your project
Example prompts
“/hunt-deserialization”
Requirements
Python 3
Workflow steps
2 steps, taken from the first numbered list in SKILL.md.
1Locate serialized data (decode base64, match magic bytes above).
2Java
What it can do on your machine
Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
java
python3
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Hunt Deserialization loads about 1.7k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 734 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~52
When it runs· the whole SKILL.md, loaded when a task matches
~1.7k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Assumes hunt-core for the scope gate, two-account rule, confirmation gate, enumeration limits, stop conditions, wiki protocol, FIND output, and Deadends. Do not re-derive any of that here.
Blind deserialization RCE claims require an OOB HIT. No exceptions. The first payload is always
a benign OOB probe, never a command: Java URLDNS / JRMPClient force a DNS/TCP callback with zero
code-exec risk, proving the sink deserializes attacker data before you fire a gadget.
NOT confirmation: a deserialization error, a type error, a stack trace, a 500, or the blob
merely being accepted. Any of these alone means the parser saw your bytes, not that you control
execution.
IS confirmation: an OOB callback from the gadget to your unique Collaborator / interactsh
subdomain, or a demonstrated effect - command execution, a file read, an SSRF fetch - reproduced in
a clean session per hunt-core. A time-delay gadget that reliably toggles counts as the effect.
Blind cases need the OOB HIT.
When you plant the OOB probe (URLDNS/JRMPClient or any blind payload), append a row to
targets/<eng>/oob.md: | <token> | <sink url+param> | deser | <date> | waiting | | (columns:
token | sink | class | planted | status | source, token = your unique interactsh label). The
recon-capture hook auto-correlates incoming callbacks to flip the row to HIT and SessionStart
surfaces HITs; the HIT row is the gate to scaffold the FIND. Do NOT claim a blind deserialization
finding without a HIT row.
Attack surface signals
Fingerprint serialized blobs by magic bytes / shape:
Sink locations: cookies (session, auth, state, viewstate), hidden form fields,
Authorization, API JSON with type hints, message queues, cache, file upload of .ser/.pickle.
Rank before firing a gadget. Not all sinks are equal:
ASP.NET __VIEWSTATE - if MAC is off or the machineKey leaked, straight to RCE; check first.
Session / auth cookies carrying a serialized blob - attacker-controlled every request, no
prior access needed to reach the sink.
.ser/.pickle file uploads and phar:// sinks - the parser runs on your bytes by design.
API JSON with type hints ($type, _class, polymorphic deserializers) - Jackson / fastjson
default-typing, .NET TypeNameHandling.
Message-queue / cache payloads - internal, often unauthenticated, frequently no look-ahead
filter.
Show full SKILL.md (376 more words)Show less
Methodology
Locate serialized data (decode base64, match magic bytes above).
No ysoserial jar on the box? (the tooling VM often lacks it; the jitpack build download returns an
empty/9-byte stub.) BUILD the gadget yourself against the target's gadget lib from Maven Central, then
compile with --release <target-JRE-major> and run with the right --add-opens. Full recipe +
modern-JDK (17/21) gotchas (class-version mismatch, InaccessibleObjectException, CC5's String-typed
BadAttributeValueExpException.val on JDK 21 -> use CC6) in [[deserialization]] "Build the gadget yourself".
3. .NET:ysoserial.exe -f BinaryFormatter -g TypeConfuseDelegate -c "cmd"; ViewState via ysoserial.net -p ViewState --generator=... --validationkey=....
4. PHP: craft POP chain from app's __wakeup/__destruct/__toString; phpggc Framework/RCE1 system id. Look for unserialize() on user input, phar:// (deser via filesystem funcs).
5. Python:pickle.loads on user data -> __reduce__ returning (os.system, ("cmd",)). yaml.load (unsafe) -> !!python/object/apply:os.system.
6. Ruby: Marshal.load / unsafe YAML.load -> universal gadget chains (Gem::...).
7. Node:node-serialize_$$ND_FUNC$$_ IIFE; funcster, serialize-javascript sinks.
8. Distill when confirmed (per hunt-core): reusable gadget chain or framework sink -> python3 scripts/wiki-stage.py --kind technique --slug <slug> --target-page techniques/web/insecure-deserialization.md.
Chaining
A deserialization sink is usually the RCE itself, not a step toward one: a working gadget executes
your command in-process. When the classpath yields only a partial primitive - URLDNS / JRMPClient
SSRF, a file-read gadget, a JNDI lookup - drive the follow-on through hunt-rce (JNDI/LDAP to code
exec, log4shell-style) or the relevant sink skill rather than forcing a command gadget the
look-ahead filter blocks.
Evasion
Look-ahead deserialization filters (ValidatingObjectInputStream, ObjectInputFilter, Jackson
allowlists) reject known gadget classes by name. When a confirmed sink rejects CC1-7: switch to a
gadget library actually on the classpath (Spring, Hibernate5, C3P0, ROME, MozillaRhino), try a
different serialization format the same endpoint accepts (XML / JSON / YAML vs binary), nest the
payload (SignedObject wrapping), or - .NET - swap the formatter (LosFormatter, SoapFormatter,
Json.NET TypeNameHandling). Fingerprint the exact library version before sweeping blind.
Severity
CRITICAL - command execution or an OOB code callback from the gadget.
HIGH - file-read or SSRF-only gadget (no command exec).
MEDIUM - DoS-only gadget.
Rated on demonstrated impact per hunt-core, not the theoretical maximum of the class.
Deadends
Stop after the bounded OOB gadget sweep (per hunt-core / CLAUDE.md: ~30-40 payloads, zero
callbacks) or when the sink deserializes but no gadget on the classpath executes:
Append: - [ ] deser on <host> <param> -- Java sink confirmed (URLDNS hit) but CC1-7/Spring/
Hibernate no exec (hardened classpath / look-ahead filter)
Record which gadget libraries and formats you tried, not just that it failed.
Hunt Deserialization next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Scan a source tree for dynamic-code-execution APIs that an attacker can hijack: Python eval / exec / compile, JavaScript eval / Function() / setTimeout(string), Ruby eval / instanceeval / classeval…
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…
Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.
Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.
Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.
Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.
Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.
Insecure deserialization hunting across Java / .NET / PHP / Python / Ruby / Node. Hunt Deserialization is an agent skill from Encod3d-Sec/TORCH.NET / PHP / Python / Ruby / Node.
When should I use Hunt Deserialization?
Hunt Deserialization fits situations like: security work in your project.
How do I install Hunt Deserialization in Claude Code?
Run `npx skills add Encod3d-Sec/TORCH --skill hunt-deserialization -a claude-code`. Or copy the skill folder (skills/hunt/hunt-deserialization in Encod3d-Sec/TORCH) into .claude/skills/hunt-deserialization in your project. Claude Code loads it when a task matches its description.
How do I install Hunt Deserialization in Codex?
Run `npx skills add Encod3d-Sec/TORCH --skill hunt-deserialization -a codex`. Or copy the skill folder (skills/hunt/hunt-deserialization in Encod3d-Sec/TORCH) into .agents/skills/hunt-deserialization in your project. Codex loads it when a task matches its description.
Can I use Hunt Deserialization in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill hunt-deserialization -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-deserialization, .gemini/skills/hunt-deserialization, .github/skills/hunt-deserialization and .opencode/skills/hunt-deserialization in your project.
What does Hunt Deserialization need to run?
Going by SKILL.md and its folder, Hunt Deserialization needs the command-line tools its instructions call (java and python3). Our summary lists: Python 3.
Does Hunt Deserialization access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is Hunt Deserialization safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Hunt Deserialization use?
Hunt Deserialization is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Hunt Deserialization use?
About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Hunt Deserialization?
Skills that share tags, products or a category with Hunt Deserialization: Detecting Eval Exec Usage (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Detecting Insecure Deserialization (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Deserialization Testing (NeoTheCapt/RedteamAgent, 142 stars) and Security Review (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Hunt Deserialization?
Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.
Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.