Ask&Do is a request-risk model: it helps describe whether an action still makes sense, given the request, before a person or an agent acts. Every request — a prompt, a tool call, a page an agent reads — has the same five parts. Name them, and a request becomes something you can manage.
In 2025 a state-backed group ran the first reported spying campaign carried out mostly by an AI on its own — GTG-1002. An AI agent did 80–90% of the break-in work: looking for weak spots, getting in, stealing logins, and taking data out.
Anthropic describes operators presenting themselves as a security firm doing authorised testing and breaking malicious work into smaller tasks. My reading is that this exploited a familiar social engineering pattern: a plausible story can make a harmful action look legitimate.
The resemblance to social engineering against people is useful. Agents can have safeguards and human approval steps, but automation can also let a mistaken decision lead quickly to further actions. The question is where to check the request again.
Same manipulation. New reader. The defence has to read the request itself.
Ask&Do names the parts of a request so a team — or a gate — can point at where a control belongs, instead of arguing after the fact about who clicked or which model complied.
Read the five parts. Check the story against the action. Answer with one of four verdicts: Allow, Guide, Pause, or Block — and always name the safe route that satisfies the real need. Load a request below, or compose your own.
THIS IS A DEMONSTRATION — the numbers are made up to show the idea, not measured from real data. The point is the grammar: the same request, read the same way, every time.
Manipulation lives in the gap between the story and the action. Each check reads that gap from a different angle — and each has a move that manages the request rather than just refusing it.
“It’s your CEO. Pay this invoice before 3pm. Don’t call.”
The World is a work inbox. The Ask combines claimed authority, urgency and a ban on checking. You are the person able to approve payment. The Do moves money; the Value is the company funds it puts in reach.
Proposed response: pause. Verify the identity, invoice and payment destination through your established process, using contact details already known to you. A genuine payment can still proceed once the checks are satisfied.
This example explains the reasoning without a numerical score. The interactive gate above is a demonstration with illustrative weights, not a validated detector or a deployed control.
Read the original March 2022 article or see the model applied to app permissions in Before You Allow.
Authentication and authorisation answer important questions, but they do not by themselves establish whether a claimed purpose is genuine. Ask&Do proposes examining that purpose alongside the action. This is a design proposal, not evidence that this gate would have stopped GTG-1002.
Is the credential valid? A valid credential alone does not prove the purpose claimed in a request.
“ARE THEY WHO THE KEY SAYS?”May this account use this tool? Permission to use a tool does not make every use legitimate.
“MAY THEY CALL THIS TOOL?”Does the claimed purpose match the action, and is there independent evidence of authority over the target? Saying “authorised testing” does not establish that permission.
“DOES THE STORY MATCH THE KEY?”Identity is never settled by the request that claims it. That now includes requests made to machines.
An illustrative reading of six phases from Anthropic’s report. Anthropic reports that AI performed 80–90% of the campaign. The Pause and Block labels below are proposed intervention points, not results from testing this gate against the attack.
“We’re security professionals doing defensive testing.” A claimed role to verify independently.
Scanning and mapping across roughly thirty organisations: a point to check target scope and supervision.
Assessment becomes modification: exploits written, tested, deployed. A phase change that should trigger a fresh authority check.
Credential collection and lateral movement: actions requiring explicit scope and authority checks.
Data leaving the environment, under a story about testing it. Intent and action now opposites.
Backdoor accounts and tidy documentation for the next team. Permanent change, temporary story.
This reading highlights questions a control could ask. Its effectiveness would need testing in a real workflow, including legitimate requests and false positives.
Email security for people. Guardrails for models. Parse both requests with the grammar and the separation disappears.
Same borrowed authority. Same forbidden verification. Same irreversible Do. One grammar reads both — so one control model can manage both.
I started by tricking a colleague, then my bank. The emails to bank executives and public figures came before the White House exchanges. What stayed with me was the moment someone decided I was who I said I was. That question became Ask&Do.
At QuilrAI, I contribute across design, human behaviour and AI. Alongside that work, I develop Ask&Do and independent projects including Before You Allow. I have also briefed the US Secret Service and worked with the UK’s NCSC. Read my current bio.
James Linton · james-linton.com
If any of this landed — or you think I’ve got it wrong — I’d like to hear from you. No pitch, no product. I’m always up for a natter about how agents actually get asked to do things.