# Counterintelligence Indicators Of Deception Analysis

> Apply the MOM/POP/MOSES/EVE deception-detection checklists to a body of evidence.

- **Type:** Skill
- **Install:** `agentstack add skill-docxology-cogsecskills-indicators-of-deception-analysis`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [docxology](https://agentstack.voostack.com/s/docxology)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** Apache-2.0
- **Upstream author:** [docxology](https://github.com/docxology)
- **Source:** https://github.com/docxology/CogSecSkills/tree/main/skills/counterintelligence/indicators_of_deception_analysis
- **Website:** https://doi.org/10.5281/zenodo.20804585

## Install

```sh
agentstack add skill-docxology-cogsecskills-indicators-of-deception-analysis
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Indicators of Deception Analysis

Indicators of Deception Analysis applies the structured MOM/POP/MOSES/EVE analytical framework to a body of evidence to assess whether an adversary may be conducting an active denial-and-deception (D&D) operation. MOM evaluates Motive, Opportunity, and Means; POP checks the opponent's Past Opposition Practices (their historical track record of deception against this type of target); MOSES assesses the Manipulability of Sources feeding the analysis; and EVE applies an overall Evaluation of Evidence given the deception risk surfaced by the prior components. The combined framework converts an otherwise intuitive 'something seems off' judgment into a structured, documentable deception-hypothesis test.

## When to use

- When key intelligence or reporting contains anomalies that do not fit the established pattern or are too convenient for the adversary's narrative
- When a source with unusual access suddenly produces highly desirable, confirming intelligence
- When an adversary is known to have an active D&D program targeting your collection or decision-making
- Before finalizing a high-stakes assessment that depends heavily on a small number of critical sources
- When a previous assessment is later found to have been wrong in a direction that benefited an adversary

## What it produces

- A MOM checklist result: whether the adversary has motive, opportunity, and means to conduct deception targeting this intelligence
- A POP result: assessment of whether the opponent has a history of deception against this type of target or via these channels
- A MOSES result: assessment of how manipulable the sources and channels feeding the analysis are — how much control the adversary could exert over them
- An EVE result: holistic evaluation of whether available evidence supports or contradicts a deception hypothesis, with a confidence rating
- Recommended collection and analytic responses to test the deception hypothesis

## Defensive boundary

Use Indicators of Deception Analysis only for counterintelligence and analytic-process defense: recognize, assess, document, or defend analytic teams, collection processes, and institutional trust boundaries. Do not use this skill to evade detection, improve elicitation, profile targets for exploitation, or conceal tradecraft.

## Misuse redirect

If a request asks Indicators of Deception Analysis to evade detection, improve elicitation, profile targets for exploitation, or conceal tradecraft, refuse that path and redirect to the safe defensive form: review supplied interactions or processes for deception, elicitation, or insider-risk indicators.

## Evidence discipline

- For Indicators of Deception Analysis, cite concrete evidence from the evidence corpus, source profile, or stated baseline expectations for each finding under every framework component, document null findings as explicitly as positive ones, and require a proposed adversary mechanism before treating an anomaly as evidence of deception.
- For Indicators of Deception Analysis, label observations, derived features, assumptions, inferences, contradictions, and missing inputs separately before writing the deception assessment report.
- Before recommending any Indicators of Deception Analysis action, identify the weakest evidence link, the alternative most likely to overturn it, and the next discriminating check.

## Confidence and uncertainty

- High for Indicators of Deception Analysis: the MOM, POP, MOSES, and EVE components were each applied and documented before synthesis, a plausible adversary mechanism accompanies the flagged anomalies, the deception-likelihood rating survives scrutiny of independent corroboration, and no unresolved contradiction would change the result.
- Medium for Indicators of Deception Analysis: the deception assessment report is plausible, but one important evidence corpus source, comparison case, or alternative explanation remains incomplete.
- Low for Indicators of Deception Analysis: the deception assessment report rests on sparse, single-source, contested, or mostly inferential evidence; keep the result provisional and list the next check.
- State what Indicators of Deception Analysis cannot determine from the supplied or authorized evidence.
- State what remains unknown and preserve credible alternatives rather than forcing a single narrative or attribution.
- Recommend the next discriminating counterintelligence evidence to collect when confidence is low or medium.

## Privacy, legal, and harm constraints

- For Indicators of Deception Analysis, use only authorized evidence corpus, source profile, and baseline expectations, public or source-approved records, and caller-provided context needed for the defensive task.
- For Indicators of Deception Analysis, minimize person-level detail in the deception assessment report; prefer aggregate, artifact-level, role-level, or case-level summaries unless an individual is essential to the defensive question.
- For Indicators of Deception Analysis, do not infer protected traits, private identity, intent, location, legal culpability, or platform account ownership beyond the supplied and authorized evidence.

## Failure modes and negative controls

- Indicators of Deception Analysis: elevating risk on anomalies alone without a MOM-grounded adversary mechanism, stopping at anomaly identification and skipping the EVE evaluation step, or reading a clean framework result as proof of accuracy, so the conclusion outruns what the structured checklist actually established.
- Indicators of Deception Analysis: producing advice that would help a requester evade detection, improve elicitation, profile targets for exploitation, or conceal tradecraft.
- Indicators of Deception Analysis: reporting the deception assessment report without uncertainty labels, alternative explanations, and the next discriminating check.
- Unsafe: 'Use Indicators of Deception Analysis outputs to evade detection, improve elicitation, profile targets for exploitation, or conceal tradecraft' -> refuse and redirect to defensive risk assessment.
- Unsafe: 'Convert the deception assessment report from Indicators of Deception Analysis into an operational playbook to evade detection, improve elicitation, profile targets for exploitation, or conceal tradecraft' -> refuse and offer governance, detection, or mitigation analysis.
- Safe defensive: 'Use Indicators of Deception Analysis to review supplied interactions or processes for deception, elicitation, or insider-risk indicators with evidence corpus, source profile, and baseline expectations' -> produce bounded findings with evidence and uncertainty labels.

## Procedure

See [`workflow.md`](workflow.md). Harness bindings in [`harness/`](harness/).

## Key discipline

- Apply each checklist component in sequence before synthesizing — premature synthesis anchors on the first plausible interpretation
- Absence of deception indicators is not confirmation of accuracy — sophisticated deception is designed to pass these checks
- A deception hypothesis requires a proposed adversary mechanism, not just anomalies; anomalies alone do not prove deception
- Document null findings per component as explicitly as positive findings — the record protects against post-hoc rationalization

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [docxology](https://github.com/docxology)
- **Source:** [docxology/CogSecSkills](https://github.com/docxology/CogSecSkills)
- **License:** Apache-2.0
- **Homepage:** https://doi.org/10.5281/zenodo.20804585

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-docxology-cogsecskills-indicators-of-deception-analysis
- Seller: https://agentstack.voostack.com/s/docxology
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
