Skip to content
Security
Skill

/security-misconfiguration

This skill should be used when the user asks about "security misconfiguration", "default credentials", "debug mode", "security headers", "exposed endpoints", "TLS configuration", or needs to find configuration-related vulnerabilities during whitebox security review.

From plugin
vuln-scout
2435 skills9 agents15 commands
Install
$ npx -y skills add allsmog/vuln-scout --skill security-misconfiguration --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/security-misconfiguration

Context preview

The summary Claude sees to decide when to auto-load this skill.

This skill should be used when the user asks about "security misconfiguration", "default credentials", "debug mode", "security headers", "exposed endpoints", "TLS configuration", or needs to find configuration-related vulnerabilities during whitebox security review.

SKILL.md

security-misconfiguration.SKILL.md
name: Security Misconfiguration
description: This skill should be used when the user asks about "security misconfiguration", "default credentials", "debug mode", "security headers", "exposed endpoints", "TLS configuration", or needs to find configuration-related vulnerabilities during whitebox security review.
version: 1.0.0

Security Misconfiguration (OWASP A05)

Purpose

Provide detection patterns for security misconfiguration vulnerabilities including default credentials, debug mode exposure, missing security headers, and insecure TLS settings.

OWASP Top 10 Mapping

**Category**: A05 - Security Misconfiguration

**CWEs**:

  • CWE-16: Configuration
  • CWE-209: Information Exposure Through Error Messages
  • CWE-215: Information Exposure Through Debug Information
  • CWE-548: Information Exposure Through Directory Listing
  • CWE-756: Missing Custom Error Page

When to Use

Activate this skill when:

  • Reviewing application configuration files
  • Checking for exposed debug/admin endpoints
  • Auditing security header implementation
  • Verifying TLS/SSL configuration
  • Looking for default or weak credentials

---

Debug Mode Enabled

Detection Patterns

Python (Django/Flask)

# Django debug mode
grep -rniE "DEBUG\s*=\s*True" --include="*.py" --include="settings.py"

# Flask debug mode
grep -rniE "app\.debug\s*=\s*True|FLASK_DEBUG|debug=True" --include="*.py"

# Environment files
grep -rniE "DEBUG=1|DEBUG=true|DEBUG=True" --include="*.env" --include=".env*"

Java (Spring)

# Spring DevTools / Debug
grep -rniE "spring\.devtools|management\.endpoints\.web\.exposure|actuator" --include="*.properties" --include="*.yaml" --include="*.yml"

# Exposed actuator endpoints
grep -rniE "exposure\.include.*\*|exposure\.include.*health,info,env" --include="*.properties" --include="*.yaml"

PHP

# Display errors
grep -rniE "display_errors.*On|display_errors.*1|error_reporting.*E_ALL" --include="*.php" --include="php.ini"

# Laravel debug
grep -rniE "APP_DEBUG=true|'debug'.*=>.*true" --include="*.env" --include="*.php"

Go

# Gin debug mode
grep -rniE "gin\.SetMode.*gin\.DebugMode|GIN_MODE=debug" --include="*.go" --include="*.env"

# pprof enabled
grep -rniE "net/http/pprof|/debug/pprof" --include="*.go"

TypeScript/Node.js

# Debug environment
grep -rniE "NODE_ENV.*development|DEBUG=\*|debug.*true" --include="*.ts" --include="*.js" --include="*.env"

---

Default Credentials

Detection Patterns

# Common default passwords
grep -rniE "password.*['\"]admin['\"]|password.*['\"]123456['\"]|password.*['\"]password['\"]|password.*['\"]root['\"]|password.*['\"]test['\"]" --include="*.go" --include="*.py" --include="*.java" --include="*.ts" --include="*.php"

# Default usernames with passwords
grep -rniE "admin.*admin|root.*root|user.*password|test.*test" --include="*.go" --include="*.py" --include="*.java" --include="*.ts" --include="*.php" --include="*.env" --include="*.yaml"

# Database defaults
grep -rniE "postgres.*postgres|mysql.*root|mongodb.*admin" --include="*.env" --include="*.yaml" --include="*.properties"

Common Default Credentials to Check

| Service | Username | Password | |---------|----------|----------| | PostgreSQL | postgres | postgres | | MySQL | root | (empty) | | MongoDB | admin | admin | | Redis | (none) | (none) | | RabbitMQ | guest | guest | | Elasticsearch | elastic | changeme | | Jenkins | admin | admin | | Grafana | admin | admin |

---

Exposed Admin/Debug Endpoints

Detection Patterns

# Admin routes
grep -rniE "[\"\'/]admin|[\"\'/]_admin|[\"\'/]administrator" --include="*.go" --include="*.py" --include="*.java" --include="*.ts" --include="*.php"

# Debug/Dev endpoints
grep -rniE "[\"\'/]debug|[\"\'/]_debug|[\"\'/]dev|[\"\'/]test" --include="*.go" --include="*.py" --include="*.java" --include="*.ts" --include="*.php"

# Internal endpoints
grep -rniE "[\"\'/]internal|[\"\'/]private|[\"\'/]system" --include="*.go" --include="*.py" --include="*.java" --include="*.ts" --include="*.php"

# Monitoring endpoints
grep -rniE "[\"\'/]metrics|[\"\'/]health|[\"\'/]status|[\"\'/]actuator|[\"\'/]swagger|[\"\'/]graphql" --include="*.go" --include="*.py" --include="*.java" --include="*.ts" --include="*.php"

Framework-Specific Endpoints

| Framework | Endpoint | Risk | |-----------|----------|------| | Spring Boot | /actuator/* | Env vars, heap dump | | Django | /admin/ | Admin panel | | Rails | /rails/info | Version disclosure | | Laravel | /telescope | Debug info | | Express | /graphql | Introspection | | Go pprof | /debug/pprof | Memory/CPU profiling |

---

Missing Security Headers

Detection Patterns

# Look for header setting code
grep -rniE "Content-Security-Policy|X-Frame-Options|X-Content-Type-Options|Strict-Transport-Security|X-XSS-Protection" --include="*.go" --include="*.py" --include="*.java" --include="*.ts" --include="*.php"

# Middleware/interceptor configuration
grep -rniE "helmet|securityHeaders|addHeader|setHeader.*security" --include="*.go" --include="*.py" --include="*.java" --include="*.ts" --include="*.php"

Required Security Headers

| Header | Value | Purpose | |--------|-------|---------| | Content-Security-Policy | `default-src 'self'` | Prevent XSS | | X-Frame-Options | `DENY` | Prevent clickjacking | | X-Content-Type-Options | `nosniff` | Prevent MIME sniffing | | Strict-Transport-Security | `max-age=31536000` | Force HTTPS | | X-XSS-Protection | `1; mode=block` | XSS filter (legacy) | | Referrer-Policy | `strict-origin-when-cross-origin` | Control referrer | | Permissions-Policy | `geolocation=()` | Limit browser features |

---

TLS/SSL Misconfiguration

Detection Patterns

# Insecure TLS versions
grep -rniE "SSLv2|SSLv3|TLSv1\.0|TLSv1\.1|ssl\.PROTOCOL_SSLv|TLS_RSA_" --include="*.go" --include="*.py" --include="*.java" --include="*.ts" --include="*.php"

# Disabled certificate verificati
Read more
Ships withvuln-scout

AI-powered whitebox penetration testing plugin for Claude Code. 9 languages, 22 skills, 7 autonomous agents. STRIDE threat modeling, OWASP 2025 coverage, polyglot monorepo support.

Get the whole plugin

Other skills on vuln-scout.