sharp-edges

Identify insecure defaults and security-footgun patterns across APIs, configurations, and cryptographic interfaces.

11|13|Updated Mar 25, 2026
One-click install
npx skills add https://github.com/MetalLegBob/drfraudsworth --skill sharp-edges-metallegbob
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: sharp-edges
Source: https://github.com/MetalLegBob/drfraudsworth/tree/main/.claude/skills/sharp-edges
Command: npx skills add https://github.com/MetalLegBob/drfraudsworth --skill sharp-edges-metallegbob

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

sharp-edges identifies security-footgun patterns that undermine secure-by-default behavior across APIs, configurations, and cryptographic interfaces, helping teams surface and remediate design flaws early.

Core Features & Use Cases

  • Detects common security footguns include insecure defaults, API usability pitfalls, and dangerous configuration patterns.
  • Provides actionable guidance with cross-language references and concrete examples to improve secure design.
  • Use cases include API design reviews, library audits, and configuration validation across teams and projects.

Quick Start

Start a targeted review pass on your codebase focusing on known footgun patterns and request remediation recommendations.

Frequently Asked Questions about sharp-edges

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What are API security footguns and how do they affect secure-by-default design?

API security footguns are insecure defaults and usability pitfalls in configurations and cryptographic interfaces that undermine secure-by-default behavior. They expose applications to risk by making dangerous patterns the path of least resistance for developers.

How do I review my API design for insecure defaults and dangerous configuration patterns?

To review API design for insecure defaults, run a targeted codebase pass focusing on known footgun patterns across APIs, configurations, and cryptographic interfaces. Request remediation recommendations to guide your team toward secure-by-default decisions.

Can I use this security pattern analysis for library audits across different programming languages?

Yes, you can use this security pattern analysis for library audits across different programming languages and platforms. It provides cross-language references and concrete examples to help surface and remediate design flaws early.

What is the best way to identify cryptographic interface flaws during a code review?

The best way to identify cryptographic interface flaws is to apply a structured metadata model that enforces validation and governance requirements during code reviews. This surfaces insecure defaults and guides secure-by-default decisions effectively.

When should I perform a configuration validation check for security footguns?

You should perform configuration validation for security footguns during API design reviews and library audits. Applying this analysis early helps teams surface insecure defaults and dangerous configuration patterns before they reach production.

Why does my secure-by-default API design still exhibit dangerous configuration patterns?

Secure-by-default API design can still exhibit dangerous configuration patterns due to hidden security footguns in cryptographic interfaces and schemas. Identifying these flaws requires a structured analysis that enforces strict validation and governance requirements.