insecure-defaults
Maintained by trailofbits
Detects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production. Use when auditing security, reviewing config management, or analyzing environment variable handling.
- Current version
- Unknown
- License
- Unknown
- Network access
- Unknown / not assessed
- Review status
- Not verified
Problem it solves
This catalog entry helps users find and evaluate insecure-defaults for the task described by its available catalog summary. Confirm the exact scope in the linked original source when one is available.
When to use it
Consider insecure-defaults when its available catalog summary matches the task at hand. When available, review the linked original source before use for precise instructions, requirements, and limitations.
Installation and updates
These commands are displayed for copying only and are never executed on RefHub servers. Review the linked upstream source before running them.
npx skills add trailofbits/skills --skill insecure-defaults -y
Agent compatibility
No compatibility test has been recorded
Do not assume agent compatibility until documented test evidence is available.