Agent skill

Insecure Defaults

by vibeeval in vibeeval/vibecosystem

Detect fail-open configurations, hardcoded secrets, weak authentication defaults, permissive CORS, disabled security features, and other insecure-by-default patterns.

MITAuto-check: notesSecurity

Install Insecure Defaults

skills CLI
$ npx skills add vibeeval/vibecosystem --skill insecure-defaults -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vibeeval/vibecosystem insecure-defaults --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vibeeval/vibecosystem.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/insecure-defaults .claude/skills/insecure-defaults && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
insecure-defaults
GitHub stars
531
Token cost
~1.9k tokens
SKILL.md length
264 words
Files
1
Skills in repo
144
Repo updated
First seen
Licence
MIT

At a glance

Detect fail-open configurations, hardcoded secrets, weak authentication defaults, permissive CORS, disabled security features, and other insecure-by-default patterns.

  • Works in 10 steps: Fail-Open Configurations → Hardcoded Secrets → Weak Authentication Defaults → …
  • Tasks that involve Secrets management
  • SKILL.md covers Detection Categories, Audit Checklist, Rationalizations to Reject and Integration with vibecosystem
  • Needs API_KEY and DB_PASSWORD

What it does

Insecure Defaults is an agent skill from vibeeval/vibecosystem. Detect fail-open configurations, hardcoded secrets, weak authentication defaults, permissive CORS, disabled security features, and other insecure-by-default patterns. Adapted from Trail of Bits. Use during security review or when auditing configuration and initialization code.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Secrets management, Security review and Authentication. The repository describes itself as: AI software team for Claude Code - 138 agents, 295 skills, 73 hooks. Self-learning, multi-agent swarm, autonomous skill evolution. The licence is MIT.

When your agent uses it

  • Tasks that involve Secrets management
  • Tasks that involve Security review
  • Tasks that involve Authentication

Example prompts

  • “/insecure-defaults”

Requirements

  • A credential in API_KEY
  • A credential in JWT_SECRET

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Fail-Open Configurations
  2. Hardcoded Secrets
  3. Weak Authentication Defaults
  4. Permissive CORS
  5. Disabled Security Features
  6. Debug Mode in Production
  7. Overly Permissive File/Directory Permissions
  8. Missing Rate Limiting
  9. Insecure Deserialization
  10. Missing Security Headers

What it can do on your machine

Read from SKILL.md and the folder at commit 3b763b1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY
    • DB_PASSWORD
    • JWT_SECRET
    • ENCRYPTION_KEY
    • SESSION_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Insecure Defaults loads about 1.9k tokens when it runs. Until then it costs about 74 tokens; SKILL.md has 264 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~74
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:130
    chmod 666 /app/.env
  • NoteMentions a .env fileSKILL.md:133
    chmod 600 /app/.env

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vibeeval/vibecosystem at commit 3b763b1, republished under its MIT licence (© vibeeval). 264 words, ~1,877 tokens.

Download SKILL.mdSave it as .claude/skills/insecure-defaults/SKILL.md (or your agent's skills folder).
name
insecure-defaults
description
Detect fail-open configurations, hardcoded secrets, weak authentication defaults, permissive CORS, disabled security features, and other insecure-by-default patterns. Adapted from Trail of Bits. Use during security review or when auditing configuration and initialization code.

Insecure Defaults Detection

Systematic detection of security misconfigurations where the default behavior is insecure. These are the bugs that ship because "it worked in development."

Detection Categories

1. Fail-Open Configurations

Code that defaults to allowing access when a security check fails.

typescript
// BAD: Fail-open -- if auth service is down, everyone gets in
async function checkAuth(token: string): Promise<boolean> {
  try {
    return await authService.verify(token)
  } catch {
    return true  // INSECURE: fails open
  }
}

// GOOD: Fail-closed -- if auth service is down, deny access
async function checkAuth(token: string): Promise<boolean> {
  try {
    return await authService.verify(token)
  } catch {
    return false  // SECURE: fails closed
  }
}

Detection pattern: Look for catch blocks that return truthy/permissive values in auth/authz code.

2. Hardcoded Secrets
typescript
// BAD patterns -- detect ALL of these
const API_KEY = "sk-proj-abc123"
const DB_PASSWORD = "admin123"
const JWT_SECRET = "super-secret-key"
const ENCRYPTION_KEY = Buffer.from("0123456789abcdef")

// GOOD
const API_KEY = process.env.API_KEY
if (!API_KEY) throw new Error('API_KEY environment variable required')

Detection patterns:

  • String literals assigned to variables named *key*, *secret*, *password*, *token*, *credential*
  • Base64-encoded strings in source (potential embedded keys)
  • Bearer followed by a string literal
  • AWS access keys (AKIA...), GitHub tokens (ghp_...), Stripe keys (sk_live_...)
3. Weak Authentication Defaults
typescript
// BAD: Session without secure flags
app.use(session({
  secret: 'keyboard cat',      // Hardcoded secret
  cookie: {}                    // Missing secure, httpOnly, sameSite
}))

// GOOD
app.use(session({
  secret: process.env.SESSION_SECRET,
  cookie: {
    secure: true,               // HTTPS only
    httpOnly: true,             // No JS access
    sameSite: 'strict',         // CSRF protection
    maxAge: 3600000             // 1 hour expiry
  },
  resave: false,
  saveUninitialized: false
}))
4. Permissive CORS
typescript
// BAD: Allow everything
app.use(cors())                          // Defaults to origin: '*'
app.use(cors({ origin: '*' }))          // Explicit wildcard
app.use(cors({ origin: true }))         // Reflect any origin

// GOOD: Explicit allowlist
app.use(cors({
  origin: ['https://app.example.com', 'https://admin.example.com'],
  credentials: true,
  methods: ['GET', 'POST', 'PUT', 'DELETE'],
  allowedHeaders: ['Content-Type', 'Authorization']
}))
5. Disabled Security Features
typescript
// BAD: Disabling security in code (not just config)
app.disable('x-powered-by')  // This one is actually GOOD
// But these are BAD:
process.env.NODE_TLS_REJECT_UNAUTHORIZED = '0'  // Disable TLS verification
helmet({ contentSecurityPolicy: false })          // Disable CSP
app.use(csrf({ ignoreMethods: ['POST'] }))       // Disable CSRF for POST

Detection pattern: Look for false, '0', disable, skip, ignore near security-related configs.

6. Debug Mode in Production
typescript
// BAD: Debug flags that leak info
app.use(errorHandler({ dumpExceptions: true, showStack: true }))
mongoose.set('debug', true)
app.set('env', 'development')  // Hardcoded to dev

// GOOD: Environment-aware
if (process.env.NODE_ENV !== 'production') {
  mongoose.set('debug', true)
}
7. Overly Permissive File/Directory Permissions
bash
# BAD
chmod 777 /app/config
chmod 666 /app/.env

# GOOD
chmod 600 /app/.env
chmod 700 /app/config
8. Missing Rate Limiting
typescript
// BAD: No rate limit on auth endpoints
app.post('/api/login', loginHandler)
app.post('/api/register', registerHandler)
app.post('/api/forgot-password', forgotPasswordHandler)

// GOOD: Rate limited
const authLimiter = rateLimit({
  windowMs: 15 * 60 * 1000,  // 15 minutes
  max: 5,                     // 5 attempts
  message: 'Too many attempts, try again later'
})
app.post('/api/login', authLimiter, loginHandler)
9. Insecure Deserialization
typescript
// BAD: Deserializing untrusted input
const data = JSON.parse(userInput)        // JSON is generally safe
const obj = yaml.load(userInput)           // YAML can execute code!
const result = eval(userInput)             // Never ever

// GOOD
const obj = yaml.load(userInput, { schema: yaml.FAILSAFE_SCHEMA })
10. Missing Security Headers

Required headers for web applications:

typescript
// Minimum security headers
app.use(helmet())  // Sets many headers, but verify:

// Or manually:
app.use((req, res, next) => {
  res.setHeader('X-Content-Type-Options', 'nosniff')
  res.setHeader('X-Frame-Options', 'DENY')
  res.setHeader('X-XSS-Protection', '0')  // Disabled intentionally, CSP replaces it
  res.setHeader('Strict-Transport-Security', 'max-age=31536000; includeSubDomains')
  res.setHeader('Content-Security-Policy', "default-src 'self'")
  res.setHeader('Referrer-Policy', 'strict-origin-when-cross-origin')
  res.setHeader('Permissions-Policy', 'camera=(), microphone=(), geolocation=()')
  next()
})

Audit Checklist

Authentication:
[ ] No hardcoded secrets in source code
[ ] Session cookies have secure, httpOnly, sameSite flags
[ ] JWT secrets are env vars, not constants
[ ] Password hashing uses bcrypt/argon2 (not MD5/SHA1)
[ ] Default admin passwords don't exist

Authorization:
[ ] Fail-closed on error (deny by default)
[ ] No wildcard permissions in defaults
[ ] Role checks can't be bypassed by omitting headers

Network:
[ ] CORS is not wildcard in production
[ ] TLS verification is not disabled
[ ] Rate limiting on auth and sensitive endpoints
[ ] Security headers are set

Configuration:
[ ] Debug mode is off in production
[ ] Stack traces are not exposed to users
[ ] Error messages don't leak internals
[ ] File permissions are restrictive (600/700)

Data:
[ ] No sensitive data in logs
[ ] No PII in URLs/query strings
[ ] Encryption keys are not hardcoded
[ ] Database connections use TLS

Rationalizations to Reject

RationalizationWhy It's WrongRequired Action
"It's just for development"Dev configs ship to prod constantlyUse env-based config switching
"We'll secure it before launch"Deadline pressure skips securitySecure by default NOW
"The firewall protects us"Firewalls have holes, cloud is complexDefense in depth required
"It's an internal API"Internal = one hop from externalTreat as semi-trusted
"Nobody knows this endpoint exists"Security through obscurity failsAuthenticate everything

Integration with vibecosystem

  • security-reviewer agent: Primary consumer -- runs this checklist on every review
  • code-reviewer agent: Flags obvious insecure defaults during general review
  • config-validator agent: Applies these patterns to configuration files
  • verifier agent: Includes insecure default check in final quality gate

Inspired by Trail of Bits insecure-defaults plugin.

© vibeeval, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/insecure-defaults of vibeeval/vibecosystem.

Open the folder on GitHubat commit 3b763b1

Compare with similar skills

Insecure Defaults next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Insecure Defaults compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Insecure Defaults this skillvibeeval/vibecosystem531—~1.9kAutomated safety check: NotesMIT
Securityserithemage/serverless-openclaw196—~633Automated safety check: PassNone
Discover Securityrand/cc-polymath181—~1.9kAutomated safety check: PassMIT
Security PatternsCloudAI-X/claude-workflow-v21.4k—~3.6kAutomated safety check: NotesMIT
Security SecretsIgorWarzocha/Opencode-Workflows122—~1.2kAutomated safety check: NotesNone
Agents Hardenaws/agent-toolkit-for-aws2.8k—~8kAutomated safety check: NotesApache-2.0

Similar skills

  • Security

    serithemage/serverless-openclaw

    References Serverless OpenClaw security model. An agent skill from serithemage/serverless-openclaw.

    196 GitHub stars~633 tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Discover Security

    rand/cc-polymath

    Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management.

    181 GitHub stars~1.9k tokensUpdated 7 mo ago
    SecurityAuto-check passed
  • Security Patterns

    CloudAI-X/claude-workflow-v2

    Implements authentication, authorization, encryption, secrets management, and security hardening patterns.

    1.4k GitHub stars~3.6k tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • Security Secrets

    IgorWarzocha/Opencode-Workflows

    Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows.

    122 GitHub stars~1.2k tokensUpdated 8 mo ago
    SecurityAuto-check: notes
  • Agents Harden

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses when preparing your agent for production — IAM scoping, inbound auth (JWT, SigV4), secrets management, cold start optimization, session lifecycle, rate limiting, input…

    2.8k GitHub stars~8k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Security

    OpenHands/extensions

    Security best practices for secure coding, authentication, authorization, and data protection.

    157 GitHub stars~342 tokensUpdated yesterday
    SecurityAuto-check passed

More from vibeeval/vibecosystem

All 144 skills in this repo
  • Agent Benchmark

    vibeeval/vibecosystem

    Framework for measuring and tracking agent response quality over time.

    531 GitHub stars~2.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Differential Review

    vibeeval/vibecosystem

    Security-focused differential code review with blast radius analysis, risk-adaptive depth (DEEP/FOCUSED/SURGICAL), git history correlation, and structured finding format.

    531 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Factcheck Guard

    vibeeval/vibecosystem

    A skill your agent uses when making any factual claim about the codebase — existence, absence, or behavior.

    531 GitHub stars~2.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Fp Check

    vibeeval/vibecosystem

    Systematic false positive verification for security findings.

    531 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • N8n Workflows

    vibeeval/vibecosystem

    n8n otomasyon workflow'lari. An agent skill from vibeeval/vibecosystem.

    531 GitHub stars~3.3k tokensUpdated 2 mo ago
    Auto-check passed
  • Notepad System

    vibeeval/vibecosystem

    A skill your agent uses when context compression is imminent, when resuming a session, or when preserving critical decisions across long tasks.

    531 GitHub stars~1.7k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Insecure Defaults

What does Insecure Defaults do?

Detect fail-open configurations, hardcoded secrets, weak authentication defaults, permissive CORS, disabled security features, and other insecure-by-default patterns. Insecure Defaults is an agent skill from vibeeval/vibecosystem. Detect fail-open configurations, hardcoded secrets, weak authentication defaults, permissive CORS, disabled security features, and other insecure-by-default patterns.

When should I use Insecure Defaults?

Insecure Defaults fits situations like: tasks that involve Secrets management; tasks that involve Security review; tasks that involve Authentication.

How do I install Insecure Defaults in Claude Code?

Run `npx skills add vibeeval/vibecosystem --skill insecure-defaults -a claude-code`. Or copy the skill folder (skills/insecure-defaults in vibeeval/vibecosystem) into .claude/skills/insecure-defaults in your project. Claude Code loads it when a task matches its description.

How do I install Insecure Defaults in Codex?

Run `npx skills add vibeeval/vibecosystem --skill insecure-defaults -a codex`. Or copy the skill folder (skills/insecure-defaults in vibeeval/vibecosystem) into .agents/skills/insecure-defaults in your project. Codex loads it when a task matches its description.

Can I use Insecure Defaults in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vibeeval/vibecosystem --skill insecure-defaults -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/insecure-defaults, .gemini/skills/insecure-defaults, .github/skills/insecure-defaults and .opencode/skills/insecure-defaults in your project.

What does Insecure Defaults need to run?

Going by SKILL.md and its folder, Insecure Defaults needs credentials named API_KEY, DB_PASSWORD, JWT_SECRET and ENCRYPTION_KEY. Our summary lists: A credential in API_KEY; A credential in JWT_SECRET.

Does Insecure Defaults access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Insecure Defaults safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Insecure Defaults use?

Insecure Defaults is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Insecure Defaults use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Insecure Defaults?

Skills that share tags, products or a category with Insecure Defaults: Security (serithemage/serverless-openclaw, 196 stars), Discover Security (rand/cc-polymath, 181 stars), Security Patterns (CloudAI-X/claude-workflow-v2, 1.4k stars) and Security Secrets (IgorWarzocha/Opencode-Workflows, 122 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Insecure Defaults?

vibeeval (a GitHub user) maintains it in vibeeval/vibecosystem, which has 531 GitHub stars. The repository holds 144 skills in this directory. The repository was last updated on August 8, 2026.

Source: vibeeval/vibecosystem on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.