Back to skill

Security audit

Dunning-Kruger Effect

Security checks across malware telemetry and agentic risk

Overview

This is a text-only reasoning skill that teaches when to apply a Dunning-Kruger framework and does not request system access or perform actions on the user's environment.

Before installing, understand that this skill may shape an agent's analysis of confidence, hiring, performance, and AI-readiness discussions. It does not add technical access, but users should ensure it is applied to specific evidence-backed cases rather than casual comments about confidence.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The manifest description says to activate when "someone's self-assessed confidence seems disconnected from their actual track record" or when "a hiring or promotion decision is driven by self-presentation," which are subjective and broadly applicable conditions. Although some negative examples are provided, these trigger conditions still lack clear scope boundaries and could cause unintended invocation in many ordinary workplace discussions.

Vague Triggers

Medium
Confidence
91% confidence
Finding
Several listed triggers rely on broad assessments such as a novice "expressing high confidence," hiring decisions based on self-assessment, or mentions of terms like "overconfident" and "doesn't know what they don't know." These conditions are not specific enough to reliably separate true Dunning-Kruger cases from ordinary conversation about confidence, creating risk of over-activation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.