audit
Audit a file, directory, or whole repo for insecure default configuration: fallback secrets, default credentials, fail-open switches, weak crypto, permissive access, debug leakage. Parallel sweeps collect candidates, then a refuting verifier traces each one to the security decision it reaches before
- 0
- Installs
- —
- Rating
- —
- Success rate
- 1
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 76083dade648df63… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
audit.md
Insecure defaults audit
1. Check the corpus is there.
ls -1 ${CLAUDE_PLUGIN_ROOT}/references
Must list *.md files. If it errors or lists none, stop and say so. Don't search
elsewhere, don't guess, don't run the audit anyway.
2. Run it. Workflow tool:
name: "insecure-defaults:audit-pipeline"
args: { scope: "$1" or ".", pluginRoot: "${CLAUDE_PLUGIN_ROOT}" }
Pass the ${CLAUDE_PLUGIN_ROOT} value as printed above; it's already the real path.
3. Print the result, by status:
findings,no-findings-confirmed: printreport.no-candidates: the sweeps ran and matched nothing, which is a real result. There is noreport; printnote, including its point that this is not proof of absence.report-failed: the audit completed but the write-up died. Printnote, then presentfindings,refutedandcoverageyourself.- anything else: the audit didn't complete, so it isn't a clean result. Print
noteand say the run failed.
Files
1- audit.md
75883127cb1.4 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from trailofbits/skills7
Searches Burp Suite project files for security analysis
Detects timing side-channels in cryptographic code
Performs security-focused differential review of code changes
Identifies state-changing entry points in smart contracts
Safely analyzes and cleans up local git branches and worktrees, categorizing them as merged, squash-merged, superseded, or active work before deleting anything.
Scans Android APKs for Firebase security misconfigurations
Creates Semgrep rules with test-first methodology
Related security skillsscan passed
Audit dependencies for security vulnerabilities, license compliance, and update recommendations
Security scan of the legacy system with a reviewable remediation patch (OWASP, CWE, CVEs, secrets, injection)
Scan dependencies for vulnerabilities and generate supply chain security evidence
Interactive setup wizard for better-auth authentication. Guides through database, framework, OAuth providers, and plugin configuration.
Display Better Auth available authentication providers and their configuration