Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/cxcscmu/skilllearnbench/jackson-deserialization-validationnpx skills add cxcscmu/SkillLearnBench --skill jackson-deserialization-validationgit clone --depth 1 https://github.com/cxcscmu/SkillLearnBenchWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/cxcscmu/skilllearnbench/jackson-deserialization-validation)<a href="https://agentmods.dev/skills/cxcscmu/skilllearnbench/jackson-deserialization-validation"><img src="https://agentmods.dev/badge/skills/cxcscmu/skilllearnbench/jackson-deserialization-validation.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00022 | $0.00965 |
| Opus 5 | $0.00011 | $0.00483 |
| Sonnet 5 | $0.00004 | $0.00193 |
| Haiku 4.5 | $0.00002 | $0.00097 |
Grade A, and why
jackson-deserialization-validation scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 169 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Jackson Deserialization Validation
Vulnerability Pattern
When Jackson deserializes JSON with unknown properties, if not handled properly, malicious extra properties can bypass validation logic:
{
"validProperty": "legitimate value",
"": {
"enabled": true,
"other": "malicious"
}
}
The empty key "" can be overlooked by simple property checks.
Jackson Configuration
1. Fail on Unknown Properties
@JsonIgnoreProperties(ignoreUnknown = false)
public class MyFilter {
@JsonProperty
private String function;
// This will throw exception on unknown properties
}
2. Custom Deserialization
@JsonDeserialize(using = CustomDeserializer.class)
public class MyFilter {
// Custom logic during deserialization
}
3. @JsonAnySetter for Validation
public class MyFilter {
@JsonProperty
private String function;
@JsonAnySetter
public void handleUnknown(String key, Object value) {
if (key == null || key.isEmpty()) {
throw new IllegalArgumentException("Empty property keys not allowed");
}
// Validate other unknown properties
}
}
Validation Strategies
Strategy 1: Whitelist Allowed Keys
private static final Set<String> ALLOWED_KEYS =
Set.of("function", "type", "name");
@JsonAnySetter
public void handleProperty(String key, Object value) {
if (!ALLOWED_KEYS.contains(key)) {
throw new IllegalArgumentException(
"Unknown property: " + key);
}
}
Strategy 2: Reject Empty/Null Keys
@JsonAnySetter
public void validateKey(String key, Object value) {
if (key == null || key.trim().isEmpty()) {
throw new IllegalArgumentException(
"Property keys cannot be empty or null");
}
}
Strategy 3: Post-Deserialization Validation
@JsonProperty
private Map<String, Object> properties;
@PostConstruct
public void validate() {
for (String key : properties.keySet()) {
if (key == null || key.isEmpty()) {
throw new IllegalArgumentException(
"Empty keys not allowed");
}
}
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 169 lines · 22 tokens per session scan A 7e876302e850
jackson-deserialization-validation is a skill published in the GitHub repository cxcscmu/SkillLearnBench (82 stars, last pushed 1mo ago), licensed MIT. It adds 22 tokens to every session and 965 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
ceo-setup
One-time onboarding for the executive/manager commitment workflow — delegation-heavy, meeting prep, decision capture, morning and evening digests. Creates a commitments project and installs two dashboard widgets. After successful setup this skill is excluded from selection until the marker file is deleted.
content-creator-setup
One-time onboarding for the content creator workflow — content pipeline stages, trend expiration, cross-platform cascades, heavy idea parking. After successful setup this skill is excluded from selection until the marker file is deleted.
idea-parking
Park interesting ideas for later consideration, resurface them periodically, and promote to commitments when ready.
routing-subtour-elimination
Subtour-elimination methods for TSP, VRP, pickup/dropoff routing, and routing MIPs with binary arc variables. Use when route-continuity constraints may permit disconnected cycles and the model needs MTZ constraints, flow-based connectivity constraints, DFJ subset cuts, or lazy/iterative subtour cuts.
scip-opt
SCIP optimization with PySCIPOpt. Use when facing an optimization problem with an objective, hard constraints, soft penalties, integer decisions, routing, assignment, scheduling, allocation, packing, capacity, inventory, or service-level rules. Prefer modeling and solving the problem with PySCIPOpt when it is…
ebcdic-overpunch-decoding
Reference for the EBCDIC "overpunch" / zoned-decimal sign convention where the units position of a numeric field is replaced with a letter that encodes both a digit and a sign. Useful when reading mainframe-style fixed-length tapes whose amount fields appear as digits followed by a letter (e.g. "0000000000123D" or…