Research: insecure-defaults

Cached research evidence for insecure-defaults (not authority).

Back to catalog page

Detects insecure default configurations causing vulns: hardcoded secrets/fallbacks, default creds (admin/admin), weak crypto (MD5/DES/ECB), permissive access (CORS *), fail-open patterns vs fail-secure. Scans manifests, env handling, auth, third-party integrations. Trail of Bits.

Security/config audit agents.

trust_tier=needs-inspection; status=inspect-then-install; provenance=verified-install-command; risks=Broad applicability leads to context-dependent findings; low direct exec surface but config changes could be sensitive. policy=Inspect source/hooks/dedupe.; evidence=trailofbits/skills batch + https://github.com/trailofbits/skills/plugins/insecure-defaults .

Grouped in npx skills add trailofbits/skills --skill ... insecure-defaults ... status=inspect-then-install; selector=named.

trailofbits/skills.

secrets-management, sast-configuration, semgrep/codeql. General “insecure defaults” instruction.

> Web evidence from repo plugin README.