docs: deserialization skill switches (OOB/timing/scope/runtimes/exec/PHAR) Document the seven project switches for the Insecure Deserialization skill, the three confirmation channels they gate, and the regenerated settings + MCP pages. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
docs: the serialized-object Jev ranking acts Jev's format and reachability are written onto each candidate and the deserialization skill confirms the most reachable first; without Jev the candidates are the signatures' own. TypeSafe Jev, Serialized Object Detection, AI in the Recon Pipeline, Recon Pipeline Workflow, Agent Skills and Mute Rules updated; settings registry regenerated. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs: partial serialized recon reads headers, parameters and form names; 19-slide Jev deck Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs: deserialization skill records confirmations through chain_findings The skill never had a report tool: a confirmation reaches the graph only as a chain_findings entry in output_analysis, filled in the same response that reads the proof. Serialized-Object-Detection (lifecycle and agent steps) and Agent-Skills (steps 5-6) now say so, plus a model note from the live test: deepseek-chat confirmed the sink but never filled the field, deepseek-v4-pro did. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs: serialized-object review fixes The Jev ranking sends evidence only, never the format or the marker label that names it, and its act mode is described as the later change it is. One candidate per sink and format; deser_location is the cookie's, parameter's or header's own name; encoding_layers are the layers peeled to reach the match. The honest ceiling names httpxPaths; the data-sent and budget lines match the code; the scan card's control is listed; the shadow hooks are no longer said to use their answer. Settings registry regenerated. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs: serialized-object Jev ranking; the complete AI in Pipeline hook list TypeSafe Jev gains its serialized-object ranking section and the five Jev-only hooks everywhere the count appears. Serialized Object Detection covers form fields, one candidate per format per value, the honest ceiling of the in-memory corpus, and the Jev ranking. Screenshots regenerated: the AI in Pipeline panel with every hook card, the Jev token card, and the Serialized Object Scan card. MCP API reference and settings registry regenerated. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
docs: serialized object detection + insecure deserialization skill New Serialized-Object-Detection operator guide (detect->confirm model, families, safety, candidate lifecycle, settings, graph query). Adds the Insecure Deserialization built-in skill to Agent-Skills, the serialized_scan source + deser_* props to Attack-Surface-Graph, and nav wiring in Home + _Sidebar. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>