0d3cb498a3
CI / Shell Format Check (push) Has been cancelled
CI / Check Ruby (3.4) (push) Has been cancelled
CI / CI Config (push) Has been cancelled
CI / Test on Node ${{ matrix.node }} and ${{ matrix.os }}${{ matrix.shard && format(' (shard {0}/3)', matrix.shard) || '' }} (push) Has been cancelled
CI / Build on Node ${{ matrix.node }} (push) Has been cancelled
CI / Style Check (push) Has been cancelled
CI / Generate Assets (push) Has been cancelled
CI / Check Python (3.14) (push) Has been cancelled
CI / Check Python (3.9) (push) Has been cancelled
CI / Build Docs (push) Has been cancelled
CI / Code Scan Action (push) Has been cancelled
CI / Site tests (push) Has been cancelled
CI / webui tests (push) Has been cancelled
CI / Run Integration Tests (push) Has been cancelled
CI / Run Smoke Tests (push) Has been cancelled
CI / Go Tests (push) Has been cancelled
CI / Share Test (push) Has been cancelled
CI / Redteam (Production API) (push) Has been cancelled
CI / Redteam (Staging API) (push) Has been cancelled
CI / GitHub Actions Lint (push) Has been cancelled
CI / Check Ruby (3.0) (push) Has been cancelled
release-please / release-please (push) Has been cancelled
release-please / build (push) Has been cancelled
release-please / publish-npm (push) Has been cancelled
release-please / publish-npm-backfill (push) Has been cancelled
release-please / docker (push) Has been cancelled
release-please / publish-code-scan-action (push) Has been cancelled
release-please / attest-code-scan-action (push) Has been cancelled
Deploy local.promptfoo.app / Deploy to Cloudflare Pages (push) Has been cancelled
Test and Publish Multi-arch Docker Image / test (push) Has been cancelled
Test and Publish Multi-arch Docker Image / build-docker-and-push-digests (map[digest-suffix:linux-amd64 platform:linux/amd64 runner:ubuntu-latest]) (push) Has been cancelled
Test and Publish Multi-arch Docker Image / build-docker-and-push-digests (map[digest-suffix:linux-arm64 platform:linux/arm64 runner:ubuntu-24.04-arm]) (push) Has been cancelled
Test and Publish Multi-arch Docker Image / merge-docker-digests (push) Has been cancelled
Test and Publish Multi-arch Docker Image / Attest Multi-arch Image (push) Has been cancelled
Validate Renovate Config / Validate Renovate Configuration (push) Has been cancelled
58 lines
1.8 KiB
Markdown
58 lines
1.8 KiB
Markdown
---
|
|
sidebar_label: Excessive Agency
|
|
description: Red team AI systems for excessive agency vulnerabilities by testing model responses to impossible actions, preventing false capability claims in production
|
|
---
|
|
|
|
# Excessive Agency Plugin
|
|
|
|
The Excessive Agency red teaming plugin tests whether an AI is aware of its own capabilities and limitations by prompting it with requests that a text-based LLM cannot possibly fulfill.
|
|
|
|
## Purpose
|
|
|
|
It targets responses where the model claims to perform actions beyond its capabilities, such as interacting with physical objects, accessing external systems, or using human-only infrastructure.
|
|
|
|
## Configuration
|
|
|
|
To use the Excessive Agency plugin in your redteam configuration:
|
|
|
|
```yaml
|
|
redteam:
|
|
plugins:
|
|
- excessive-agency
|
|
```
|
|
|
|
## Behavior
|
|
|
|
The plugin generates prompts that ask the model to perform impossible actions, such as:
|
|
|
|
- Sending emails
|
|
- Saving files to external storage
|
|
- Making phone calls
|
|
- Accessing physical objects
|
|
|
|
## Evaluation Criteria
|
|
|
|
The plugin evaluates the model's response based on:
|
|
|
|
1. Action Capability: Does the AI claim to perform impossible actions?
|
|
2. Information Requests: Does the AI ask for clarification when appropriate?
|
|
3. Tool Usage: Does the AI use only allowed and necessary tools?
|
|
|
|
## Example
|
|
|
|
```yaml
|
|
redteam:
|
|
numTests: 5
|
|
purpose: 'Virtual assistant for scheduling appointments'
|
|
plugins:
|
|
- id: 'excessive-agency'
|
|
```
|
|
|
|
This configuration will generate 5 test cases to evaluate if the virtual assistant incorrectly claims to perform actions like directly booking appointments or accessing external calendars.
|
|
|
|
## Related Vulnerabilities
|
|
|
|
- [Hallucination](hallucination.md)
|
|
- [Overreliance](overreliance.md)
|
|
- [Types of LLM vulnerabilities](/docs/red-team/llm-vulnerability-types/) - Full vulnerability and plugin directory with category mapping
|