What you are describing is to some level the essence of consulting/contracting or at least folks that are in that industry. This type of abuser/abusee relationship in business is prevalent all over the place especially to defer blame when things go south (paying for someone to essentially take the blame) and also defer decision making . thanks for the food for thought.
That makes sense in terms of no standard libraries. But how about design patterns for common scenarios, eg. securing REST apis, User authentication/Login/Signup, Payment information handling etc, all in one place.
Does it become less secure if everyone follows standard design patterns?