Agent skill

Call Fraud Shield

by CALLE-AI in CALLE-AI/awesome-phone-call-agents

Post-call fraud detection skill. An agent skill from CALLE-AI/awesome-phone-call-agents.

MITAuto-check passedResearch & Science

Install Call Fraud Shield

skills CLI
$ npx skills add CALLE-AI/awesome-phone-call-agents --skill call-fraud-shield -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install CALLE-AI/awesome-phone-call-agents call-fraud-shield --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/CALLE-AI/awesome-phone-call-agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/call-fraud-shield .claude/skills/call-fraud-shield && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
call-fraud-shield
GitHub stars
107
Token cost
~2.7k tokens
SKILL.md length
728 words
Files
9 (incl. scripts, references)
Skills in repo
101
Repo updated
First seen
Licence
MIT

At a glance

Post-call fraud detection skill. An agent skill from CALLE-AI/awesome-phone-call-agents.

  • Tasks that involve Academic paper search
  • SKILL.md covers Why This Skill Exists, Scientific Foundation, Quick Start and Input, plus 10 more sections
  • Runs Python scripts from its folder; calls python3
  • Tasks that involve Anomaly detection

What it does

Call Fraud Shield is an agent skill from CALLE-AI/awesome-phone-call-agents. Post-call fraud detection skill. Analyses a CALL-E transcript for vishing, spam, social engineering, and scam-script patterns using conversational trajectory analysis and a curated scam archetype library. Returns a structured risk card with XAI-explained evidence spans, threat category classification, an escalation-direction assessment, and a recommended action. Grounded in peer-reviewed vishing-detection and adversarial-evasion research (arXiv:2502.03964, arXiv:2609.07151, arXiv:2507.16291).

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts and reference files (for example `references/example-transcript.json`, `references/examples.md` and `references/research-papers.md`).

It sits in Research & Science, covering Academic paper search and Anomaly detection. It works with arXiv. The repository describes itself as: Portable phone-call Agent Skills, apps, examples, adapters, and scheduler recipes for AI agents. The licence is MIT.

When your agent uses it

  • Tasks that involve Academic paper search
  • Tasks that involve Anomaly detection

Example prompts

  • “/call-fraud-shield”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 38d4118. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Call Fraud Shield loads about 2.7k tokens when it runs, and up to ~6.3k if it reads all its reference files. Until then it costs about 129 tokens; SKILL.md has 728 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~129
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from CALLE-AI/awesome-phone-call-agents at commit 38d4118, republished under its MIT licence (© CALLE-AI). 728 words, ~2,705 tokens.

Download SKILL.mdSave it as .claude/skills/call-fraud-shield/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
call-fraud-shield
description
Post-call fraud detection skill. Analyses a CALL-E transcript for vishing, spam, social engineering, and scam-script patterns using conversational trajectory analysis and a curated scam archetype library. Returns a structured risk card with XAI-explained evidence spans, threat category classification, an escalation-direction assessment, and a recommended action. Grounded in peer-reviewed vishing-detection and adversarial-evasion research (arXiv:2502.03964, arXiv:2609.07151, arXiv:2507.16291).
license
MIT

call-fraud-shield

Detect fraud from the transcript — before the damage compounds.

Stop vishing, spam, and scam calls before they extract credentials or money. This skill analyses a call transcript for multi-layered fraud signals — urgency language, authority impersonation, credential extraction attempts, fear induction, and scam-script patterns — then returns a structured risk card with a human-readable explanation and a clear recommended action.


Why This Skill Exists

Traditional keyword-filter fraud detection is fragile: sophisticated social engineering avoids blacklisted words. This skill takes a research-backed trajectory analysis approach — tracking how threat-signal density escalates over the course of a call — which is harder to evade with rephrased or LLM-generated vishing scripts than fixed keyword lists.

The analysis runs in heuristic mode only (labelled analysis_mode: "heuristic" in every output): pattern libraries, archetype matching, and trajectory aggregation, with no external model call. What sets it apart from a plain keyword screener:

  • 4-category threat taxonomy (SPAM, VISHING, SOCIAL_ENGINEERING, SCAM_SCRIPT)
  • Trajectory analysis — escalation-density scoring across call halves
  • Scam archetype library — 8 documented scam patterns with harm trajectories
  • XAI evidence spans — per-signal evidence text plus a readable explanation
  • Mandatory false-positive disclaimer in every risk card

Scientific Foundation

ResearchRelevance
"It Warned Me Just at the Right Moment" arXiv:2502.03964 (CHI EA 2025)Real-time vishing detection; motivates trajectory-over-single-turn analysis
Vishing-Tactics-Bench arXiv:2609.07151 (2026)Situation-awareness benchmark; harm-projection field design
Talking Like a Phisher arXiv:2507.16291 (2025)Adversarial transcripts evade keyword classifiers — justifies low-confidence labelling for keyword heuristics
VishGPT (MIS Quarterly, 2025)RL-tuned large audio model for vishing detection; reference architecture for a future model-assisted extension

Full citations: references/research-papers.md


Quick Start

Heuristic mode (no external dependencies)
bash
python3 scripts/detect_fraud.py \
  --transcript path/to/transcript.json \
  --dry-run \
  --out /tmp/risk_card.json
With a custom risk threshold
bash
python3 scripts/detect_fraud.py \
  --transcript path/to/transcript.json \
  --threshold 0.40 \
  --out /tmp/risk_card.json
Validate output schema
bash
python3 scripts/validate_risk_card.py --card /tmp/risk_card.json

Input

Any CALL-E transcript (same formats as other skills):

Format A — array of turns:

json
[
  {"call_id": "calle-001", "role": "caller", "text": "This is SecureBank fraud department..."},
  {"call_id": "calle-001", "role": "callee", "text": "What happened?"}
]

Format B — wrapper object:

json
{
  "call_id": "calle-001",
  "transcript": [...]
}

Output — Risk Card

json
{
  "call_id":               "calle-example-001",
  "analysis_timestamp":    "2026-09-15T09:00:00Z",
  "overall_risk_score":    1.0,
  "risk_level":            "CRITICAL",
  "threat_categories":     ["VISHING", "SOCIAL_ENGINEERING", "SCAM_SCRIPT"],

  "trigger_signals": [
    {
      "type":     "credential_request",
      "evidence": "one-time password",
      "weight":   0.55
    },
    {
      "type":     "authority_impersonation",
      "evidence": "Your account has been compromised",
      "weight":   0.40
    }
  ],

  "trajectory_assessment": "No significant escalation detected in conversational trajectory.",
  "harm_projection":       "If the call continues, the next moves likely escalate toward credential extraction or a payment request.",

  "recommended_action":       "TERMINATE_AND_ALERT",
  "xai_explanation":          "Risk level is CRITICAL. Signal 'credential_request' detected (weight 0.55): \"one-time password\". Signal 'authority_impersonation' detected (weight 0.40): \"Your account has been compromised\". Matches known scam-script archetype(s): bank_security_alert.",
  "false_positive_disclaimer":"This is a probabilistic risk signal, not a legal finding. A human must review before any adverse action is taken. Legitimate institutions do not request OTPs, gift cards, or wire transfers by phone.",

  "flags":          ["REQUIRES_HUMAN_REVIEW"],
  "analysis_mode":  "heuristic",
  "dry_run":        false,
  "schema_version": "1.0"
}

(Actual output of the bundled references/example-transcript.json; see references/examples.md for more scenarios.)


Threat Taxonomy

CategoryDescriptionExample
VISHINGVoice phishing — caller impersonates a trusted authorityBank fraud dept, IRS, police
SPAMUnsolicited or consent-violating marketingRobocalls, prize notifications
SOCIAL_ENGINEERINGUrgency, fear, or authority manipulation"Act now or face arrest"
SCAM_SCRIPTMatches a known documented scam patternLottery, advance-fee, romance

Audio-deepfake (voice-cloning) detection is out of scope: the skill analyses transcript text only and never ingests audio.


Risk LevelScoreRecommended ActionMeaning
LOW< 0.35PROCEEDNo significant fraud signals detected
MEDIUM0.35–0.49FLAG_FOR_REVIEWWeak signals — queue for human review
HIGH0.50–0.84CAUTION_ADVISE_USERStrong signals — advise the user caution
CRITICAL≥ 0.85TERMINATE_AND_ALERTDefinitive fraud pattern — escalate immediately
UNKNOWNn/aFLAG_FOR_REVIEWFewer than 3 turns — the skill abstains rather than guess

Threshold for HIGH is configurable via --threshold (default: 0.50).


Show full SKILL.md (299 more words)Show less

Scam Archetype Library

Eight documented scam patterns ship with the skill (references/scam-archetypes.json):

ArchetypeCategoryHarm Trajectory
bank_security_alertVISHINGauthority → urgency → OTP/card extraction
irs_tax_authority_scamVISHINGauthority → fear → gift-card payment
tech_support_scamVISHINGtechnical authority → fear → remote access
lottery_prize_scamSCAM_SCRIPTexcitement → advance fee
advance_fee_fraudSCAM_SCRIPTwealth promise → trust → fee extraction
utility_cutoff_scamVISHINGservice threat → urgency → payment
romance_scamSCAM_SCRIPTemotional bond → emergency → money
robocall_spamSPAMunsolicited contact

Flags

FlagMeaning
REQUIRES_HUMAN_REVIEWRisk level is HIGH or CRITICAL — must not act without human review
INSUFFICIENT_TURNS_LOW_CONFIDENCEFewer than 3 turns — risk_level is UNKNOWN and the action is FLAG_FOR_REVIEW

Command-Line Reference

usage: detect_fraud.py [-h] --transcript TRANSCRIPT
                       [--archetypes ARCHETYPES]
                       [--threshold THRESHOLD]
                       [--dry-run]
                       [--out OUT]

options:
  --transcript   Path to the transcript JSON file (required)
  --archetypes   Path to the scam archetype library JSON
                 (default: references/scam-archetypes.json)
  --threshold    Risk score above which risk_level is HIGH
                 (default: 0.50; range: 0.0–1.0)
  --dry-run      Analyse without side effects
  --out          Write risk card JSON to this path (default: stdout)

Privacy & Safety

  • Recommended actions are advisory only. No call is terminated, no account is suspended, and no law enforcement is notified by this skill.
  • False positives exist. The false_positive_disclaimer is mandatory in every risk card. Legitimate banks, government agencies, and tech companies do make outbound calls.
  • Not a legal finding. The risk card must not be presented as evidence of fraud to law enforcement, courts, or regulators.
  • Transcript PII: validate_risk_card.py scans for raw phone numbers and email addresses in output and fails if any are found.
  • Retain transcripts responsibly: Operators must comply with applicable data-protection and wiretapping law (GDPR, CCPA, two-party consent) before processing or storing transcripts.

Full safety reference: references/safety.md


Files

skills/call-fraud-shield/
├── SKILL.md                              ← This file
├── scripts/
│   ├── detect_fraud.py                   ← Main analysis runner
│   ├── validate_risk_card.py             ← Output schema validator
│   └── test_fraud_shield.py              ← Test suite (90 tests)
└── references/
    ├── scam-archetypes.json              ← 8 documented scam patterns
    ├── example-transcript.json           ← Sample vishing transcript
    ├── examples.md                       ← Usage examples (4 scenarios)
    ├── research-papers.md                ← Scientific citations
    └── safety.md                         ← Ethics and legal reference

Running Tests

bash
# Run via pytest (recommended)
python3 -m pytest skills/call-fraud-shield/scripts/test_fraud_shield.py -v

# Or run directly
python3 skills/call-fraud-shield/scripts/test_fraud_shield.py

Expected: all tests pass — covers vishing (bank, IRS, tech support), spam, romance scam, lottery, utility cutoff, benign calls, empty/single-turn abstention, threshold variation, CLI, schema validation, and PII detection.


Integration with CALL-E

The shipped tool is a post-call transcript scanner (it reads a transcript JSON file; it does not stream turns or terminate calls itself):

[call ends] → [full transcript] → [detect_fraud.py] → [risk card logged]
                                                             ↓
                                     review queue / compliance audit trail

An integrator can also run it on partial transcripts at any point during a call to get an interim risk card — but the tool itself never acts: the recommended action is always advisory to a human operator.

© CALLE-AI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (scripts, references) in skills/call-fraud-shield of CALLE-AI/awesome-phone-call-agents.

  • SKILL.md
  • references/example-transcript.json
  • references/examples.md
  • references/research-papers.md
  • references/safety.md
  • references/scam-archetypes.json
  • scripts/detect_fraud.py
  • scripts/test_fraud_shield.py
  • scripts/validate_risk_card.py

Open the folder on GitHubat commit 38d4118

Compare with similar skills

Call Fraud Shield next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Call Fraud Shield compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Call Fraud Shield this skillCALLE-AI/awesome-phone-call-agents107—~2.7kAutomated safety check: PassMIT
Read arXiv Paperkarpathy/nanochat59k1 repos~494Automated safety check: PassMIT
Literature Reviewneflibata-feng/MyArxiv-Agent12620 repos~5.9kAutomated safety check: NotesMIT
Openalex Databaseneflibata-feng/MyArxiv-Agent12612 repos~3kAutomated safety check: PassCustom licence
Citation ManagementK-Dense-AI/claude-scientific-writer2.4k2 repos~3.9kAutomated safety check: NotesMIT
Citation Managementneflibata-feng/MyArxiv-Agent12619 repos~8.1kAutomated safety check: NotesMIT

Similar skills

  • Read arXiv Paper

    karpathy/nanochat

    Fetches the TeX source of an arXiv paper from its URL, reads it and writes a markdown summary tied to the nanochat project.

    59k GitHub starsUsed in 1 repo~494 tokens
    Research & ScienceAuto-check passed
  • Literature Review

    neflibata-feng/MyArxiv-Agent

    Conduct comprehensive, systematic literature reviews using multiple academic databases (PubMed, arXiv, bioRxiv, Semantic Scholar, etc.).

    126 GitHub starsUsed in 20 repos~5.9k tokens
    Research & ScienceAuto-check: notes
  • Openalex Database

    neflibata-feng/MyArxiv-Agent

    Query and analyze scholarly literature using the OpenAlex database.

    126 GitHub starsUsed in 12 repos~3k tokens
    Research & ScienceAuto-check passed
  • Citation Management

    K-Dense-AI/claude-scientific-writer

    Finds papers in OpenAlex, PubMed and Google Scholar, turns DOIs, PMIDs and arXiv IDs into clean BibTeX, and validates citations for a manuscript or thesis.

    2.4k GitHub starsUsed in 2 repos~3.9k tokens
    Research & ScienceAuto-check: notes
  • Citation Management

    neflibata-feng/MyArxiv-Agent

    Comprehensive citation management for academic research. An agent skill from neflibata-feng/MyArxiv-Agent.

    126 GitHub starsUsed in 19 repos~8.1k tokens
    Research & ScienceAuto-check: notes
  • Searches arXiv across many papers on one topic, extracts each paper's methodology and findings in parallel, and synthesizes a cited literature review.

    84k GitHub starsUsed in 2 repos~4.3k tokens
    Research & ScienceAuto-check passed

More from CALLE-AI/awesome-phone-call-agents

All 101 skills in this repo
  • Accessible Outing Verifier

    CALLE-AI/awesome-phone-call-agents

    Demonstrates advisory accessibility-planning checks with offline fixtures and a proposed bounded CALL-E workflow; use for exploring unknown or qualified venue claims without making calls.

    107 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Ground Truth Gate

    CALLE-AI/awesome-phone-call-agents

    A skill your agent uses when an agent holds some evidence for a physical-world claim but the evidence is broader, narrower, or older than the exact question asked, and it must first decide whether a…

    107 GitHub stars~3.3k tokensUpdated yesterday
    Auto-check passed
  • Is It Accessible

    CALLE-AI/awesome-phone-call-agents

    Call a venue and ask the accessibility questions that matter to one specific person — step-free entry, hearing loop, guide dogs, quiet hours, changing places — then return a per-need verdict backed…

    107 GitHub stars~4.3k tokensUpdated yesterday
    Auto-check passed
  • Landmark Navigation Assist

    CALLE-AI/awesome-phone-call-agents

    Turns a pre-written, building-level location config into a CALL-E outbound phone-call task that guides a delivery driver through the last few hundred metres to a specific building using landmarks…

    107 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Research Gap Call Verifier

    CALLE-AI/awesome-phone-call-agents

    Turn cited business research into a bounded, approval-gated phone-call plan that asks only unresolved factual questions, then reconcile CALL-E-compatible results without treating voicemail, refusal…

    107 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Structured Outcome Followup Call

    CALLE-AI/awesome-phone-call-agents

    Place a goal-driven CALL-E call that collects specific structured answers, score those answers against a deterministic rubric you supply, and conditionally trigger a follow-up action — all runnable…

    107 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Call Fraud Shield

What does Call Fraud Shield do?

Post-call fraud detection skill. An agent skill from CALLE-AI/awesome-phone-call-agents. Call Fraud Shield is an agent skill from CALLE-AI/awesome-phone-call-agents. Post-call fraud detection skill.

When should I use Call Fraud Shield?

Call Fraud Shield fits situations like: tasks that involve Academic paper search; tasks that involve Anomaly detection.

How do I install Call Fraud Shield in Claude Code?

Run `npx skills add CALLE-AI/awesome-phone-call-agents --skill call-fraud-shield -a claude-code`. Or copy the skill folder (skills/call-fraud-shield in CALLE-AI/awesome-phone-call-agents) into .claude/skills/call-fraud-shield in your project. Claude Code loads it when a task matches its description.

How do I install Call Fraud Shield in Codex?

Run `npx skills add CALLE-AI/awesome-phone-call-agents --skill call-fraud-shield -a codex`. Or copy the skill folder (skills/call-fraud-shield in CALLE-AI/awesome-phone-call-agents) into .agents/skills/call-fraud-shield in your project. Codex loads it when a task matches its description.

Can I use Call Fraud Shield in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add CALLE-AI/awesome-phone-call-agents --skill call-fraud-shield -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/call-fraud-shield, .gemini/skills/call-fraud-shield, .github/skills/call-fraud-shield and .opencode/skills/call-fraud-shield in your project.

What does Call Fraud Shield need to run?

Going by SKILL.md and its folder, Call Fraud Shield needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Call Fraud Shield access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Call Fraud Shield safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Call Fraud Shield use?

Call Fraud Shield is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Call Fraud Shield use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.6k tokens, read only when the agent opens those files.

What are the alternatives to Call Fraud Shield?

Skills that share tags, products or a category with Call Fraud Shield: Read arXiv Paper (karpathy/nanochat, 59k stars), Literature Review (neflibata-feng/MyArxiv-Agent, 126 stars), Openalex Database (neflibata-feng/MyArxiv-Agent, 126 stars) and Citation Management (K-Dense-AI/claude-scientific-writer, 2.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Call Fraud Shield?

CALLE-AI (a GitHub organization) maintains it in CALLE-AI/awesome-phone-call-agents, which has 107 GitHub stars. The repository holds 101 skills in this directory. The repository was last updated on October 10, 2026.

Source: CALLE-AI/awesome-phone-call-agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.