home/categories/security/trailofbits-skills-plugins-insecure-defaults-skills-insecure-defaults-skill-md
securitytesting-security

insecure-defaults

Detects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production. Use when auditing security, reviewing config management, or analyzing environment variable handling.

trailofbits
maintainer
trailofbits
更新于 1/28/2026
星标
4466
分支
385
quick start

Installation and usage

Detects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production. Use when auditing security, reviewing config management, or analyzing environment variable handling.

安装
$ install --globalskills.sh
使用

安装后,您可以通过在终端运行以下命令来使用此技能:

skills use insecure-defaults