trailofbits/skills
insecure-defaults
Detects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production. Use when auditing…
Installation
npx skills add https://github.com/trailofbits/skills
Similar popular skills
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
>- Insecure deserialization playbook. Use when Java, PHP, or Python applications deserialize un…
2.9K installs>- Source control and artifact exposure (.git, .svn, .hg, backups, .env). Use when recon finds …
2.9K installsInsecure file upload playbook. Use when testing upload validation, storage paths, processing pi…
2.8K installsAlso in this package
Other skills from trailofbits/skills · top by installs.
npx skills add https://github.com/trailofbits/skills
More details
Agent compatibility
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
Repository health
main
History
- First seen on skills.sh
- First recorded snapshot · 6,512 installs