Agent skill

Deepfake Drill

by mohitagw15856 in mohitagw15856/pm-claude-skills

Run a tabletop drill of a voice-clone or deepfake fraud attempt — the 'CEO needs this wire today' call — against your actual approval process, before a real attacker does, then debrief the tells and…

MITAuto-check passed

Install Deepfake Drill

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill deepfake-drill -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills deepfake-drill --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/deepfake-drill .claude/skills/deepfake-drill && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deepfake-drill
GitHub stars
1.4k
Token cost
~1.5k tokens
SKILL.md length
693 words
Files
1
Skills in repo
1,348
Repo updated
First seen
Licence
MIT

At a glance

Run a tabletop drill of a voice-clone or deepfake fraud attempt — the 'CEO needs this wire today' call — against your actual approval process, before a real attacker does, then debrief the tells and…

  • Works in 5 steps: Design the scenario around YOUR weakest… → Script the pressure, not the technology.… → Let the process fail safely. Facilitator… → …
  • Someone asks to train the team on deepfake fraud
  • SKILL.md covers What This Skill Produces, Required Inputs, Process and Output Format, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Deepfake Drill is an agent skill from mohitagw15856/pm-claude-skills. Run a tabletop drill of a voice-clone or deepfake fraud attempt — the 'CEO needs this wire today' call — against your actual approval process, before a real attacker does, then debrief the tells and fix the process gap. Use when someone asks to train the team on deepfake fraud, test wire-transfer controls, run a social-engineering tabletop, or 'could we get CEO-frauded?'. Produces a drill scenario pack, a facilitator script, a tells checklist, and the process fixes the drill exposed. Defensive training only.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex — PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Someone asks to train the team on deepfake fraud
  • Test wire-transfer controls
  • Run a social-engineering tabletop
  • Could we get CEO-frauded?

Example prompts

  • “CEO needs this wire today”
  • “could we get CEO-frauded?”
  • “/deepfake-drill”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Design the scenario around YOUR weakest legitimate path. The drill
  2. Script the pressure, not the technology. The facilitator plays the
  3. Let the process fail safely. Facilitator notes for each decision point
  4. Debrief on tells and controls. The checklist that stays: any payment or
  5. Fix and re-drill. Every gap gets an owner, a fix, and a date; the

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Deepfake Drill loads about 1.5k tokens when it runs. Until then it costs about 132 tokens; SKILL.md has 693 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~132
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (© mohitagw15856). 693 words, ~1,481 tokens.

Download SKILL.mdSave it as .claude/skills/deepfake-drill/SKILL.md (or your agent's skills folder).
name
deepfake-drill
description
Run a tabletop drill of a voice-clone or deepfake fraud attempt — the 'CEO needs this wire today' call — against your actual approval process, before a real attacker does, then debrief the tells and fix the process gap. Use when someone asks to train the team on deepfake fraud, test wire-transfer controls, run a social-engineering tabletop, or 'could we get CEO-frauded?'. Produces a drill scenario pack, a facilitator script, a tells checklist, and the process fixes the drill exposed. Defensive training only.

Deepfake Drill Skill

The finance teams that lose seven figures to a cloned voice all describe the same call afterwards: it sounded exactly like him, he knew the deal names, he was stressed, it was 4:55pm on a Friday. Voice cloning needs seconds of audio now; the defense isn't detecting the fake — assume you can't — it's a process that holds even when the voice is perfect. This skill drills that process as a tabletop exercise: realistic pressure, your actual approval chain, and a debrief that fixes the gap the drill finds. It trains defenders; it does not help attackers — no cloning instructions, no evasion tips, ever.

What This Skill Produces

  • A drill scenario pack tailored to your org: the pretext, the pressure timeline, the escalating asks — written for a facilitator to read aloud, not for realism tooling
  • A facilitator script with decision points, expected-control checkpoints, and legitimate-looking curveballs ("the CFO is genuinely on a plane")
  • A tells checklist the team keeps afterwards: process tells (urgency + secrecy + channel-switch + authority), not audio tells
  • A gap report template: which control held, which was bypassed and how, the fix, the re-drill date

Required Inputs

Ask for (if not already provided):

  • The process being drilled: who can request payments/changes, who approves, above what thresholds, through which channels
  • The realistic attacker's knowledge: what's public about your execs, deals, vendors (assume LinkedIn + your press page)
  • Who's being drilled and whether it's announced or unannounced (recommend announced-window: "a drill will happen this month" — trains without the trust damage of full ambush)
  • Any real near-misses to build from

Process

  1. Design the scenario around YOUR weakest legitimate path. The drill pretexts that work are the ones your process half-allows: the acquisition that's "still confidential", the vendor bank-detail change, the exec travelling. Pick one, build the pretext from information a real attacker could gather publicly.
  2. Script the pressure, not the technology. The facilitator plays the caller using the three levers every real case uses — urgency (deadline in minutes), secrecy (tell no one, deal sensitivity), authority (the voice/name at the top) — plus the channel-switch ("can't do email, I'm boarding"). The script says what the caller says; it never explains how to clone a voice, and redirect any such request.
  3. Let the process fail safely. Facilitator notes for each decision point: what the control should catch, what to say if the participant bypasses it, when to escalate the pressure once. No individual shaming — the drill grades the process, and the debrief says so out loud.
  4. Debrief on tells and controls. The checklist that stays: any payment or detail-change request combining urgency + secrecy + channel-switch gets out-of-band verification on a known number, no exceptions for rank — the callback rule is the whole defense. Score which controls held.
  5. Fix and re-drill. Every gap gets an owner, a fix, and a date; the re-drill uses a different pretext. Recommend an annual cadence and folding the callback rule into onboarding.
Show full SKILL.md (206 more words)Show less

Output Format

## Drill scenario: [pretext name]
[Setup, what the attacker plausibly knows, the ask sequence, timing]

## Facilitator script
[Read-aloud beats · decision points with expected control · escalation and
curveball notes · hard stop conditions]

## The tells checklist (keep this)
[Process tells + the callback rule, one page]

## Gap report
| Control | Held / bypassed | How | Fix | Owner | Re-drill date |

## Aftercare
[The no-blame debrief framing + the announcement for the wider team]

Quality Checks

  • The scenario is built from the org's own process and public information — generic scripts don't find real gaps
  • Zero content that teaches attack technique: no cloning tools, methods, or detection-evasion — pressure is scripted as dialogue only
  • The debrief framing is process-blame, not person-blame, explicitly
  • The callback rule appears verbatim in the tells checklist with the "no exceptions for rank" clause
  • Every gap in the report has an owner and a re-drill date

Anti-Patterns

  • Do not produce actual cloned audio, cloning instructions, or tool recommendations for impersonation — decline that direction plainly, even "for realism"; the drill works as read-aloud tabletop
  • Do not run fully unannounced ambush drills on individuals — announced windows train; ambushes traumatize and get the program cancelled
  • Do not let the drill conclude "train people to hear fakes" — the defense is the callback rule, because the fakes are already good enough
  • Do not skip finance-adjacent paths: payroll detail changes and vendor bank updates are the same attack in cheaper clothes

[[scam-message-decoder]] for the text/email versions; [[oncall-runbook]] patterns for the verification procedure; [[incident-postmortem]] if drilling because a real attempt already happened.

Example Trigger Phrases

  • "Train the team on deepfake fraud."
  • "Test wire-transfer controls."
  • "Run a social-engineering tabletop."
  • "Could we get CEO-frauded?"

© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/deepfake-drill of mohitagw15856/pm-claude-skills.

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

Deepfake Drill next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deepfake Drill compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deepfake Drill this skillmohitagw15856/pm-claude-skills1.4k—~1.5kAutomated safety check: PassMIT
Drill Medavepoon/buildwithclaude3.6k—~697Automated safety check: NotesMIT
Voice Cloning Studiosickn33/agentic-awesome-skills47k1 repos~3.1kAutomated safety check: PassMIT-0
Socratic Drillanthropics/claude-for-legal9.6k3 repos~1.6kAutomated safety check: PassApache-2.0
Performing Soc Tabletop Exercisemukul975/Anthropic-Cybersecurity-Skills34k—~4.2kAutomated safety check: PassApache-2.0
Performing Ransomware Tabletop Exercisemukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0

Similar skills

  • Drill Me

    davepoon/buildwithclaude

    Teach the user a topic as an adaptive tutor — retrieval practice, spaced repetition with decay, and persistent memory in ~/.drill-me/.

    3.6k GitHub stars~697 tokensUpdated 2 days ago
    EducationAuto-check: notes
  • Voice Cloning Studio

    sickn33/agentic-awesome-skills

    Install and use the official AI Voice Cloning package, pinned by digest, for paid hosted work on the Beatra service.

    47k GitHub starsUsed in 1 repo~3.1k tokens
    Media & CreativeAuto-check passed
  • Socratic Drill

    anthropics/claude-for-legal

    Official

    Socratic drilling — it asks, you answer, it pushes back. An agent skill from anthropics/claude-for-legal.

    9.6k GitHub starsUsed in 3 repos~1.6k tokens
    EducationAuto-check passed
  • Performing Soc Tabletop Exercise

    mukul975/Anthropic-Cybersecurity-Skills

    Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under…

    34k GitHub stars~4.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Performing Ransomware Tabletop Exercise

    mukul975/Anthropic-Cybersecurity-Skills

    Plans and facilitates tabletop exercises simulating ransomware incidents, using realistic scenarios based on threat actors like LockBit and ALPHV/BlackCat with injects covering double extortion and…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Audit Dynamo Rust hot-path .clone() calls, explain which clones are removable and why, and only apply clone-removal patches when explicitly requested.

    8.3k GitHub stars~2k tokensUpdated today
    Auto-check passed

More from mohitagw15856/pm-claude-skills

All 1,348 skills in this repo
  • Car Tco

    mohitagw15856/pm-claude-skills

    Compare the total cost of car ownership across buy-new, buy-used, lease, and keep-your-current-car — depreciation, insurance, maintenance ramp, and fuel over a real horizon, not just the monthly…

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Cs Health Scorecard

    mohitagw15856/pm-claude-skills

    Build a customer health scorecard for a specific account. An agent skill from mohitagw15856/pm-claude-skills.

    1.4k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table — liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Fire Number

    mohitagw15856/pm-claude-skills

    Compute a financial-independence (FIRE) target and years-to-reach with every assumption labeled as an assumption — plus a sensitivity table instead of a single false-precision answer.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium — the arithmetic that proves a rate is not salary÷2000.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Questions about Deepfake Drill

What does Deepfake Drill do?

Run a tabletop drill of a voice-clone or deepfake fraud attempt — the 'CEO needs this wire today' call — against your actual approval process, before a real attacker does, then debrief the tells and…. Deepfake Drill is an agent skill from mohitagw15856/pm-claude-skills. Run a tabletop drill of a voice-clone or deepfake fraud attempt — the 'CEO needs this wire today' call — against your actual approval process, before a real attacker does, then debrief the tells and fix the process gap.

When should I use Deepfake Drill?

Deepfake Drill fits situations like: someone asks to train the team on deepfake fraud; test wire-transfer controls; run a social-engineering tabletop; could we get CEO-frauded?.

How do I install Deepfake Drill in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill deepfake-drill -a claude-code`. Or copy the skill folder (skills/deepfake-drill in mohitagw15856/pm-claude-skills) into .claude/skills/deepfake-drill in your project. Claude Code loads it when a task matches its description.

How do I install Deepfake Drill in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill deepfake-drill -a codex`. Or copy the skill folder (skills/deepfake-drill in mohitagw15856/pm-claude-skills) into .agents/skills/deepfake-drill in your project. Codex loads it when a task matches its description.

Can I use Deepfake Drill in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill deepfake-drill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deepfake-drill, .gemini/skills/deepfake-drill, .github/skills/deepfake-drill and .opencode/skills/deepfake-drill in your project.

What does Deepfake Drill need to run?

SKILL.md names no scripts, command-line tools or credentials: Deepfake Drill is instructions for the agent only.

Does Deepfake Drill access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Deepfake Drill safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Deepfake Drill use?

Deepfake Drill is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Deepfake Drill use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Deepfake Drill?

Skills that share tags, products or a category with Deepfake Drill: Drill Me (davepoon/buildwithclaude, 3.6k stars), Voice Cloning Studio (sickn33/agentic-awesome-skills, 47k stars), Socratic Drill (anthropics/claude-for-legal, 9.6k stars) and Performing Soc Tabletop Exercise (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deepfake Drill?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,434 GitHub stars. The repository holds 1,348 skills in this directory. The repository was last updated on October 9, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.