phishing-triage
Decide fast whether a suspicious message is a phishing scam — and what to do next — without clicking anything. Use when asked is this email/text a s…
它会碰到什么
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Phishing Triage
Phishing works by manufacturing urgency so you act before you think. This does the thinking: it reads the specific signals in the message — the sender, the link, the pressure, the ask — gives a clear verdict, and tells you how to verify safely (by going to the source yourself, never via the message). And if you already clicked or entered details, it switches straight to damage control.
What This Skill Produces
- A verdict — likely phishing / likely legit / unsure, with confidence
- The specific flags — the red flags present (mismatched sender, look-alike link, urgency, unusual ask, generic greeting) and any reassuring green flags
- The safe verify step — how to confirm by contacting the company through official channels you look up yourself
- What to do next — delete and report if phishing; the safe way to act if it's genuine
- Already clicked? — the immediate recovery steps (change password, enable 2FA, watch for fraud, run a scan)
Required Inputs
Ask for these if not provided:
- The message — the text/email content, sender address, and any link (as text — don't click)
- The channel — email, SMS, DM, call, QR code
- The ask — what it wants (click, log in, pay, share a code, download)
- Context — were you expecting it; do you have an account with the claimed sender
- Did you act — clicked, entered credentials, paid, or shared a code
Framework: Read The Signals, Verify At Source
- Check the sender and the link, not the display name. Look at the real address/domain and where a link actually points (hover/long-press) — look-alikes and mismatches are the tell.
- Weigh the pressure and the ask. Urgency ("act now or lose access"), threats, unexpected attachments, requests for passwords/codes/payment, or gift-card asks are classic phishing.
- Verify independently. Never use the message's links or numbers — go to the company's official site/app or a number from your card/statement and check there.
- Match the pattern. Too-good offers, "confirm your details," delivery-fee scams, "your account is suspended," and one-time-code requests are common templates.
- If in doubt, don't act — verify or delete. The safe default is to not click and to confirm through a channel you trust.
- If already caught, pivot to recovery immediately — speed limits the damage.
Output Format
Message triage: [channel] · asks you to [action]
Verdict: [likely phishing / likely legit / unsure] — [confidence].
Red flags: [sender/domain · link mismatch · urgency · unusual ask · greeting …].
Green flags (if any): [expected · matches official domain …].
Verify safely: go to [official site/app or number from your card] — not the message's links.
Do this: [delete + report as phishing] · or [the safe way to act if genuine].
If you already clicked / entered details
- Change that password (and anywhere reused) + enable 2FA · watch for fraud / contact your bank if payment or card details · run a security scan · report it.
Quality Checks
- [ ] Gives a clear verdict with confidence
- [ ] Cites the specific red/green flags in the actual message
- [ ] Verification uses independent official channels, never the message's links
- [ ] Tells the user exactly what to do next
- [ ] Includes recovery steps for those who already clicked/entered details
- [ ] Never instructs the user to click the suspicious link
Anti-Patterns
- A vague "be careful" with no verdict or specific flags.
- Telling them to click the link to "check."
- Trusting the display name over the real address/domain.
- Using the phone number/link in the message to "verify."
- No recovery path for someone who already fell for it.
Example Trigger Phrases
- "Is this text from my bank real? It says my account is locked."
- "I got an email asking me to confirm my password — is it a scam?"
- "Someone messaged me a link about a package fee. Legit?"
- "I think I just got phished — I clicked the link and logged in."
- "Did I just get scammed? They asked for a one-time code."
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。
它属于哪个仓库
plugins/pm-digital-safety/skills/phishing-triage/SKILL.md同一个仓库里的其他技能
同名技能的其他版本
有 3 个不同仓库或目录里都有叫 phishing-triage 的技能。它们内容并不相同,别混用:
- mohitagw15856/pm-claude-skills — Decide fast whether a suspicious message is a phishing scam — and what to do next — withou
- mohitagw15856/pm-claude-skills — Decide fast whether a suspicious message is a phishing scam — and what to do next — withou