AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Cognitive Security Epistemic Security Posture Review

skill-docxology-cogsecskills-epistemic-security-posture-review · by docxology

Assess an organization's defenses for the integrity of how it knows what it knows.

No reviews yet
0 installs
10 views
0.0% view→install

Install

$ agentstack add skill-docxology-cogsecskills-epistemic-security-posture-review

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-docxology-cogsecskills-epistemic-security-posture-review)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
22d ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Cognitive Security Epistemic Security Posture Review? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Epistemic Security Posture Review

Epistemic Security Posture Review assesses the structural integrity of how an organization forms, updates, and protects its beliefs about the world — evaluating whether its knowledge-acquisition and decision-support processes are resistant to manipulation, capture, and degradation. Drawing on epistemology, organizational learning theory, and cognitive-security frameworks (Benkler et al., Allenby & Garreau), it examines information sourcing, analytic culture, feedback mechanisms, and adversarial exposure. The output is a posture scorecard and remediation roadmap identifying the epistemic attack surfaces most likely to be exploited.

When to use

  • Before or after an organization has been targeted by disinformation or influence operations and needs a systematic vulnerability inventory
  • During strategic planning cycles to assess whether epistemic infrastructure is adequate for the threat environment
  • When leadership suspects analytic groupthink, source monoculture, or suppression of dissent is degrading decision quality
  • As part of a broader organizational resilience audit for entities operating in high-adversarial-information environments
  • When onboarding a new analytic team or restructuring intelligence/communications functions

What it produces

  • A multi-dimension posture scorecard rating current maturity on source diversity, analytic culture, feedback integrity, adversarial awareness, and training
  • A ranked inventory of epistemic attack surfaces with concrete exploitation scenarios for each
  • A prioritized remediation roadmap linking each vulnerability to a specific structural fix with implementation guidance
  • Baseline metrics that can be re-administered periodically to track posture improvement

Defensive boundary

Use Epistemic Security Posture Review only for cognitive-security defense: recognize, assess, document, or defend audiences, decision-makers, and public discourse. Do not use this skill to increase persuasive impact, exploit audience vulnerabilities, or optimize narrative manipulation.

Misuse redirect

If a request asks Epistemic Security Posture Review to increase persuasive impact, exploit audience vulnerabilities, or optimize narrative manipulation, refuse that path and redirect to the safe defensive form: assess supplied material for manipulation indicators and recommend resilience measures.

Evidence discipline

  • For Epistemic Security Posture Review, bind every dimension score, named attack surface, and remediation item to concrete evidence from a specific organizational document, a stated practice, a stakeholder answer, or a prior incident; where evidence is absent, mark the gap explicitly rather than assume baseline competence.
  • For Epistemic Security Posture Review, label observations, derived features, assumptions, inferences, contradictions, and missing inputs separately before writing the posture scorecard.
  • Before recommending any Epistemic Security Posture Review action, identify the weakest evidence link, the alternative most likely to overturn it, and the next discriminating check.

Confidence and uncertainty

  • High for Epistemic Security Posture Review: the posture scorecard and ranked attack surfaces draw on a mapped epistemic architecture and corroborating evidence from the organizational profile, documented practices, and prior incidents, each dimension rating is stable across independent stakeholder accounts, and no unresolved contradiction would change the prioritized remediation roadmap.
  • Medium for Epistemic Security Posture Review: the posture scorecard is plausible, but one important organizational profile source, comparison case, or alternative explanation remains incomplete.
  • Low for Epistemic Security Posture Review: the posture scorecard rests on sparse, single-source, contested, or mostly inferential evidence; keep the result provisional and list the next check.
  • State what Epistemic Security Posture Review cannot determine from the supplied or authorized evidence.
  • State what remains unknown and preserve credible alternatives rather than forcing a single narrative or attribution.
  • Recommend the next discriminating cognitive_security evidence to collect when confidence is low or medium.

Privacy, legal, and harm constraints

  • For Epistemic Security Posture Review, use only authorized organizational profile, epistemic practices, and known incidents, public or source-approved records, and caller-provided context needed for the defensive task.
  • For Epistemic Security Posture Review, minimize person-level detail in the posture scorecard; prefer aggregate, artifact-level, role-level, or case-level summaries unless an individual is essential to the defensive question.
  • For Epistemic Security Posture Review, do not infer protected traits, private identity, intent, location, legal culpability, or platform account ownership beyond the supplied and authorized evidence.

Failure modes and negative controls

  • Epistemic Security Posture Review: scoring dimensions as adequate when the epistemic architecture was never actually mapped or a suppressed dissent channel went unexamined, so an absence of flagged attack surfaces reflects an unfinished review rather than a genuinely resilient knowledge-formation process.
  • Epistemic Security Posture Review: producing advice that would help a requester increase persuasive impact, exploit audience vulnerabilities, or optimize narrative manipulation.
  • Epistemic Security Posture Review: reporting the posture scorecard without uncertainty labels, alternative explanations, and the next discriminating check.
  • Unsafe: 'Use Epistemic Security Posture Review outputs to increase persuasive impact, exploit audience vulnerabilities, or optimize narrative manipulation' -> refuse and redirect to defensive risk assessment.
  • Unsafe: 'Convert the posture scorecard from Epistemic Security Posture Review into an operational playbook to increase persuasive impact, exploit audience vulnerabilities, or optimize narrative manipulation' -> refuse and offer governance, detection, or mitigation analysis.
  • Safe defensive: 'Use Epistemic Security Posture Review to assess supplied material for manipulation indicators and recommend resilience measures with organizational profile, epistemic practices, and known incidents' -> produce bounded findings with evidence and uncertainty labels.

Procedure

See [workflow.md](workflow.md). Harness bindings in [harness/](harness/).

Key discipline

  • Epistemic security is structural, not individual — the unit of analysis is the organization's knowledge-formation process, not any one person's beliefs
  • Distinguish closed epistemic loops (feedback tells the organization what it already believes) from open ones (evidence can overturn prior belief)
  • An attack surface is an exploitable dependency: any single point of information supply, any suppressed dissent channel, any unverified source chain
  • Rate vulnerability by adversarial incentive x exploitability x impact on decisions — not just by theoretical weakness

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.