Sponsor Suno AI Music arrow_forward
Plugin

Insecure Defaults

Detects insecure default configurations including hardcoded credentials, fallback secrets, weak authentication defaults, and dangerous values in production

Type
Plugin
Repository
trailofbits/skills
GitHub stars
7.3k
License
CC-BY-SA-4.0
Repo last updated
Sep 25, 2026
Version
2.0.3
Author
Trail of Bits

What Insecure Defaults is

Insecure Defaults is a plugin published in the trailofbits/skills repository on GitHub, which has about 7.3k stars. The repository describes itself as: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”

A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.

Installing Insecure Defaults adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.

How to install Insecure Defaults

Claude Code

  1. Add the repository as a plugin marketplace: claude plugin marketplace add trailofbits/skills
  2. Install the plugin: claude plugin install insecure-defaults@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
  3. Restart the session if the new skills or commands don't appear straight away.

Claude Cowork

  1. Open Customize → Plugins and choose Add marketplace.
  2. Enter trailofbits/skills (the owner/repo shorthand works for GitHub).
  3. Find Insecure Defaults in the list, click Install, then connect any connectors it needs from its Connectors tab.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from plugins/insecure-defaults/.claude-plugin/plugin.json, shared under the repository's CC-BY-SA-4.0 license. Read the full file on GitHub.

Audits a codebase for insecure default configuration, tracing each candidate before reporting it.

Install

/plugin install insecure-defaults            # marketplace
/plugin install ./plugins/insecure-defaults  # local checkout

Use

/insecure-defaults:audit                      # whole repo
/insecure-defaults:audit src/                 # subtree
/insecure-defaults:audit src/config/app.py    # one file

Argument is a file or a directory. Optional; defaults to ..

Whatever you point at is the target, however test-like it looks: a run scoped to tests/ audits the tests. Exclusions (fixtures, docs, vendored code) apply only outside the scope you named.

Use the command, not the workflow. Invoking insecure-defaults:audit-pipeline directly stops immediately. No fallback: if the corpus can't be read, the run errors rather than guessing.

What it finds

Each category is three files that must agree:

The sweep agent loads both files for its own category and no others. It has to be the agent, not the script: a workflow has no filesystem access. tests/seed-coverage.js checks the three correspond, since nothing at runtime can.

Candidates come in two shapes, judged differently:

  • Configurable: a lookup with a fallback. Only a bug if the app runs with it. env.get('K', 'x') does; env['K'] crashes instead, so it's fine.
  • Unconditional: no configuration anywhere, insecure as written. About half of all findings. A missing env var is _not_ grounds to refute one.

How it runs

Between Discover and Verify: dedup keyed on category:file:line, so the rule id prefixes the path. Two patterns in one category hitting the same line collapse; the _same_ line flagged by two different categories stays as two candidates. hashlib.md5(k) can be a real weak-crypto finding and a false permissive-access match at once, and one merged verdict would have to cover both readings.

Verify then batches by category, ≤16 findings per agent. Each agent reads exactly one corpus and applies one discriminator. A category with more than 16 findings is split across several agents, so no single agent can run past the tool-call cap and return a partial verdict list. Coverage is uncapped; only per-agent size is.

Sweeps collect and don't judge: a sweep only greps, so it files candidates without classifying them and the verifier decides with the file in context. Each verifier starts at refuted: true and stops at the first step that kills a candidate:

  1. Is the file reachable in production?
  2. Is the insecure value the one that runs? Configurable → does it fail-secure instead? Unconditional → this step can't refute it.
  3. Is the value actually insecure?
  4. Does it reach a security decision? Cite the sink.
  5. Does deployment always supply the var? Configurable only, and no answer refutes: every manifest setting it lowers severity, none is the CRITICAL case, and a partial or undetermined answer counts as reachable.

Incomplete trace = refuted. If the corpus can't be found, the run aborts rather than continuing without it.

Each sweep reports whether it could actually read its corpus, and one failure aborts the run.

Patterns

Seed patterns are a floor, not the search.

Recon reports the project's own config wrappers, flagged if they can return a default. Each sweep then derives patterns for the detected stack: framework keys, language idioms (ENV.fetch, System.getProperty(k, d), ${VAR:-default}), and manifest formats (default = in HCL, ENV in a Dockerfile). A codebase reading everything through get_setting("X", "default") barely matches the generic seeds.

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Insecure Defaults?

Insecure Defaults is a plugin for Claude Code and Claude Cowork from the trailofbits/skills repository on GitHub. Detects insecure default configurations including hardcoded credentials, fallback secrets, weak authentication defaults, and dangerous values in production

How do I install Insecure Defaults in Claude Code?

Add the repository as a plugin marketplace: claude plugin marketplace add trailofbits/skills Install the plugin: claude plugin install insecure-defaults@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.

Can I use Insecure Defaults in Claude Cowork?

Open Customize → Plugins and choose Add marketplace. Enter trailofbits/skills (the owner/repo shorthand works for GitHub). Find Insecure Defaults in the list, click Install, then connect any connectors it needs from its Connectors tab.

Is Insecure Defaults safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under CC-BY-SA-4.0. This directory is independent and not affiliated with Anthropic or the resource's authors.