| name | insecure-defaults |
| description | Detects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production. Use when auditing security, reviewing config management, or analyzing environment variable handling. |
| source_skill_id | trailofbits-skills-plugins-insecure-defaults-skills-insecure-defaults-skill-md |
| category | Security, compliance & risk |
| source_mirror | ../../../../../skills/by-category/security-compliance-risk/security-reference/insecure-defaults/SKILL.md |
| benchmark_status | artifact_gated |
insecure-defaults
Use this skill when the task matches the description above or the source path clearly applies. Start with this concise entrypoint; open ../../../../../skills/by-category/security-compliance-risk/security-reference/insecure-defaults/SKILL.md only when implementation details, commands, assets, or references are needed.
Workflow
- Confirm the task matches this skill's scope.
- Read the local source mirror if more detail is required.
- Follow repository-level
AGENTS.md; use one AI session only.
- Keep claims tied to files, commands, citations, or benchmark artifacts.
Verification
- Source mirror:
../../../../../skills/by-category/security-compliance-risk/security-reference/insecure-defaults/SKILL.md
- Source commit:
e8cc5baf9329ccb491bfa200e82eacbac83b1ead
- Static benchmark results: see
docs/benchmark-results.md
- Runtime artifacts recorded by this entrypoint:
0
- Assigned scenarios:
skill-proof-trailofbits-skills-plugins-insecure-defaults-skills-insecure-defaults-skill-md, security-compliance-and-risk-owasp-benchmark, security-compliance-and-risk-owasp-juice-shop, security-compliance-and-risk-kubernetes-examples
Do not claim this skill passed a runtime benchmark until a validated artifact exists.