Back to skill

Security audit

Authority Bias

Security checks across malware telemetry and agentic risk

Overview

This is a text-only decision-coaching skill about authority bias, with no executable behavior or hidden data access.

Installers should treat this as a reasoning aid, not an authority itself. It is appropriate for prompting evidence checks and dissent structures, but users should still verify cited claims and avoid relying on the skill alone for legal, medical, financial, or safety-critical decisions.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
1. Identify: two authorities — the confident LLM answer and the lab-leader pronouncement; narrow question = is *this* answer / *this* timeline correct
2. Expertise vs. positional: fluency and fame are positional signals; neither is calibrated domain expertise on the instant question, and the leader is commercially interested
3. Examine reasoning: does a citation open / a number reconcile / a benchmark exist — or is confidence filling the evidentiary gap (fabricated-citation sanctions as the canonical failure)
4. Dysfunction check: "the AI said so" with no verification; strategy anchored to one quoted timeline; suppressed junior observations
5. Cialdini defense: Q1 and Q2 both default to N — discount the signal, demand the evidence, verify before relying
6. Structural counter: human-in-the-loop fact verification, source logging, independent disinterested experts, timeline premortems
Confidence
22% confidence
Finding
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.