LaunchKit · 2026

Setup & Installation

npx skills add https://github.com/trailofbits/skills --skill insecure-defaults
or paste the link and ask your coding assistant to install it
https://github.com/trailofbits/skills/tree/main/plugins/insecure-defaults
View on GitHub

What This Skill Does

Detects fail-open security vulnerabilities where applications run insecurely due to missing or weak configuration. Focuses on distinguishing exploitable defaults (app runs with a weak secret) from fail-secure patterns (app crashes without proper config). Covers hardcoded credentials, weak crypto, permissive access controls, and debug features left enabled.

Manual code review misses fail-open patterns because the code looks correct at a glance — this skill traces the actual runtime path to confirm whether a missing env var causes a crash or silently falls back to a weak default.

When to use it

  • Auditing JWT secret handling to catch fallback values like `|| 'default'` in production auth code
  • Scanning Dockerfiles and IaC templates for missing environment variables that trigger insecure runtime behavior
  • Reviewing environment variable handling to separate fail-open from fail-secure patterns before a deployment
  • Checking crypto usage for MD5, SHA1, or ECB in password hashing and token signing contexts
  • Tracing CORS wildcard and permission 0777 defaults to confirm whether they reach production endpoints