SkillAgentSearch skills...

insecure-defaults

Detect fail-open configurations, hardcoded secrets, weak authentication defaults, permissive CORS, disabled security features, and other insecure-by-default patterns. Adapted from Trail of Bits. Use during security review or when auditing configuration and initialization code.

Install / Use

npx skills add vibeeval/vibecosystem --skill insecure-defaults

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

84/100

Category

Security

Supported Platforms

Universal

Our assessment of insecure-defaults

insecure-defaults scores 84/100 on our quality scale, 807th of 1,052 Security skills we index.

We have not analysed the SKILL.md file itself yet, so the content part of this score is an estimate until our crawler reaches it.

It has 535 GitHub stars, a meaningful sign that others use it.

Maintenance, license and trust

  • The repository was last updated about 2 months ago, so insecure-defaults is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

insecure-defaults compared with similar skills

All 4 of these similar skills score higher than insecure-defaults; compare them before choosing.

SkillScoreStarsUpdatedFormat
insecure-defaults (this skill)by vibeeval8453556d agoSKILL.md
algorithmic-artby anthropics100177.9k11d agoSKILL.md
pptxby anthropics100177.9k11d agoSKILL.md
designby nextlevelbuilder100130.2k12d agoSKILL.md
ui-ux-pro-maxby nextlevelbuilder100130.2k12d agoSKILL.md

Frequently asked questions

How do I install insecure-defaults?
Run npx skills add vibeeval/vibecosystem --skill insecure-defaults. The install tabs above show the steps for each supported agent.
Which AI agents does insecure-defaults work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is insecure-defaults safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is insecure-defaults still maintained?
The repository was last updated about 2 months ago, so insecure-defaults is actively maintained.

Related Skills

View on GitHub
GitHub Stars535
CategorySecurity
Updated1mo ago
Forks44

Languages

C#

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions