ClawHub Malicious AI Skill - Python Pickle Deserialization RCE

Detects Python processes that combine potentially dangerous pickle deserialization (pickle.loads) with network-fetching libraries (urllib, requests, socket) and decoding methods (b64decode, fromhex). This pattern is consistent with backdoors or remote access tools (RATs) that fetch encoded payloads over the network and execute them directly in memory via deserialization.