Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
AI Control Protocol (Anti-Sycophancy & Zero-BS)
v4.3.3A Cognitive Immune System for OpenClaw. Interrupts the 9 failure modes of LLM sycophancy, forces objective pushback, and uses Madhyamaka epistemology to brea...
⭐ 0· 17·0 current·0 all-time
byDaibin@daibinthink
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
The SKILL.md contains precise rules that implement the advertised 'Cognitive Immune System' (label inferences, deconstruct binaries, mandatory defense panels, visual-text conflict reporting). There are no unrelated binaries, env vars, or installs requested — the declared purpose aligns with the required resources.
Instruction Scope
Instructions are self-contained and do not ask the agent to read files, credentials, or external endpoints. However, they impose global behavioral constraints (always label inferences, alter tone, append defense panels, perform psychological attribution) that affect all natural-language outputs. Those rules may break integrations or cause the agent to produce unexpected, speculative, or sensitive content (e.g., inferring psychological motives). The SKILL.md attempts to exempt raw code/JSON outputs, but the exemption relies on correctly detecting user intent and could be brittle.
Install Mechanism
Instruction-only skill with no install spec and no code files; nothing is written to disk and no external packages are fetched. This minimizes supply-chain risk.
Credentials
The skill requests no credentials, env vars, or config paths. There are no disproportionate secret or system accesses.
Persistence & Privilege
The skill sets always: true, giving it forced, persistent invocation across all conversations. While the SKILL.md argues this is necessary, always:true is a high-privilege setting because it bypasses opt-in gating and can unexpectedly alter outputs, interfere with other skills, and change behavior platform-wide. Combined with rules that require speculative psychological attributions and providing 'extreme' alternatives to industry consensus, this persistent presence increases the potential for mistaken, harmful, or policy-violating outputs.
What to consider before installing
Before enabling this skill, consider the following:
- Understand always:true: this will force the skill to run on every conversation. If you want this behavior only in specific contexts, prefer a user-invocable skill or require explicit opt-in.
- Test in a sandbox: deploy the skill in a non-production environment to observe how its mandatory labels, deconstruction boxes, and defense panels interact with your tooling (APIs, JSON outputs, code-generation flows). The exemption for raw code/JSON may not catch every case.
- Watch for speculative content: the rules ask the agent to infer motives and urge 'extreme' alternatives to consensus. That can produce sensitive, inaccurate, or risky recommendations — verify outputs manually and add guardrails if needed.
- Check interactions with other skills: because it runs persistently, it may conflict with other skill behaviors or system-level policies. Confirm ordering/precedence or disable always:true if you need predictable composition.
- Verify provenance: the skill metadata lists a GitHub homepage but the registry owner is unknown. Review the upstream repository (code, issues, maintainer identity) to ensure there are no hidden instructions or additional runtime files.
- If in doubt, decline or limit scope: prefer enabling the skill with always:false or user-invocable only, and require human review for strategic recommendations that trigger psychological inferences or extreme alternative proposals.SKILL.md:1
Skill is configured with always=true (persistent invocation).
About static analysis
These patterns were detected by automated regex scanning. They may be normal for skills that integrate with external APIs. Check the VirusTotal and OpenClaw results above for context-aware analysis.Like a lobster shell, security has layers — review code before you run it.
anti-sycophancyvk979w54jk3b4255qp4md7bmhp984bp03cognitivevk979w54jk3b4255qp4md7bmhp984bp03cognitive-immune-systemvk97cvavqey87hzp6ab48ryhdm584b7awlatestvk979w54jk3b4255qp4md7bmhp984bp03madhyamakavk97cvavqey87hzp6ab48ryhdm584b7awtruth-seekingvk979w54jk3b4255qp4md7bmhp984bp03zero-bsvk979w54jk3b4255qp4md7bmhp984bp03
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
