Back to skill

Security audit

Representativeness Heuristic

Security checks across malware telemetry and agentic risk

Overview

This is a benign markdown coaching skill for recognizing representativeness bias, with only a minor over-activation risk from broad trigger wording.

Installers should expect this skill to intervene in conversations about hiring, investing, startups, or other profile-based probability judgments. Review the broad activation wording if you want narrower behavior, but no security-impacting authority or persistence was found.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The description says to activate for "any judgment where a vivid profile drives a probability estimate without an explicit base rate," which is a very broad natural-language condition rather than a tightly scoped invocation trigger. Although examples and some negative conditions are provided, this catch-all phrase could still cause unintended activations across common conversations involving people, products, or decisions.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.