Agent skill

Phishing Triage

by mohitagw15856 in mohitagw15856/pm-claude-skills

Decide fast whether a suspicious message is a phishing scam — and what to do next — without clicking anything.

MITAuto-check passed

Install Phishing Triage

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill phishing-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills phishing-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/phishing-triage .claude/skills/phishing-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
phishing-triage
GitHub stars
1.4k
Token cost
~1.2k tokens
SKILL.md length
619 words
Files
1
Skills in repo
1,348
Repo updated
First seen
Licence
MIT

At a glance

Decide fast whether a suspicious message is a phishing scam — and what to do next — without clicking anything.

  • Works in 6 steps: Check the sender and the link, not the… → Weigh the pressure and the ask. Urgency… → Verify independently. Never use the… → …
  • Asked is this email/text a scam
  • SKILL.md covers What This Skill Produces, Required Inputs, Framework: Read The Signals,… and Output Format, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Phishing Triage is an agent skill from mohitagw15856/pm-claude-skills. Decide fast whether a suspicious message is a phishing scam — and what to do next — without clicking anything. Use when asked is this email/text a scam, is this message legit, I got a suspicious message, or did I just get phished. Produces a quick verdict with the specific red (and green) flags in the message, a safe way to verify through official channels, exactly what to do next (delete/report, or act if genuine), and recovery steps if you already clicked or entered details.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex — PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Asked is this email/text a scam
  • Is this message legit
  • I got a suspicious message
  • Did I just get phished

Example prompts

  • “/phishing-triage”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Check the sender and the link, not the display name. Look at the real address/domain and where a link actually points (hover/long-press)…
  2. Weigh the pressure and the ask. Urgency ("act now or lose access"), threats, unexpected attachments, requests for passwords/codes/payment…
  3. Verify independently. Never use the message's links or numbers — go to the company's official site/app or a number from your…
  4. Match the pattern. Too-good offers, "confirm your details," delivery-fee scams, "your account is suspended," and one-time-code requests…
  5. If in doubt, don't act — verify or delete. The safe default is to not click and to confirm through a channel you trust.
  6. If already caught, pivot to recovery immediately — speed limits the damage.

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Phishing Triage loads about 1.2k tokens when it runs. Until then it costs about 124 tokens; SKILL.md has 619 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~124
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (© mohitagw15856). 619 words, ~1,161 tokens.

Download SKILL.mdSave it as .claude/skills/phishing-triage/SKILL.md (or your agent's skills folder).
name
phishing-triage
description
Decide fast whether a suspicious message is a phishing scam — and what to do next — without clicking anything. Use when asked is this email/text a scam, is this message legit, I got a suspicious message, or did I just get phished. Produces a quick verdict with the specific red (and green) flags in the message, a safe way to verify through official channels, exactly what to do next (delete/report, or act if genuine), and recovery steps if you already clicked or entered details.

Phishing Triage

Phishing works by manufacturing urgency so you act before you think. This does the thinking: it reads the specific signals in the message — the sender, the link, the pressure, the ask — gives a clear verdict, and tells you how to verify safely (by going to the source yourself, never via the message). And if you already clicked or entered details, it switches straight to damage control.

What This Skill Produces

  • A verdict — likely phishing / likely legit / unsure, with confidence
  • The specific flags — the red flags present (mismatched sender, look-alike link, urgency, unusual ask, generic greeting) and any reassuring green flags
  • The safe verify step — how to confirm by contacting the company through official channels you look up yourself
  • What to do next — delete and report if phishing; the safe way to act if it's genuine
  • Already clicked? — the immediate recovery steps (change password, enable 2FA, watch for fraud, run a scan)

Required Inputs

Ask for these if not provided:

  • The message — the text/email content, sender address, and any link (as text — don't click)
  • The channel — email, SMS, DM, call, QR code
  • The ask — what it wants (click, log in, pay, share a code, download)
  • Context — were you expecting it; do you have an account with the claimed sender
  • Did you act — clicked, entered credentials, paid, or shared a code

Framework: Read The Signals, Verify At Source

  1. Check the sender and the link, not the display name. Look at the real address/domain and where a link actually points (hover/long-press) — look-alikes and mismatches are the tell.
  2. Weigh the pressure and the ask. Urgency ("act now or lose access"), threats, unexpected attachments, requests for passwords/codes/payment, or gift-card asks are classic phishing.
  3. Verify independently. Never use the message's links or numbers — go to the company's official site/app or a number from your card/statement and check there.
  4. Match the pattern. Too-good offers, "confirm your details," delivery-fee scams, "your account is suspended," and one-time-code requests are common templates.
  5. If in doubt, don't act — verify or delete. The safe default is to not click and to confirm through a channel you trust.
  6. If already caught, pivot to recovery immediately — speed limits the damage.

Output Format

Show full SKILL.md (253 more words)Show less
Message triage: [channel] · asks you to [action]

Verdict: [likely phishing / likely legit / unsure] — [confidence]. Red flags: [sender/domain · link mismatch · urgency · unusual ask · greeting …]. Green flags (if any): [expected · matches official domain …].

Verify safely: go to [official site/app or number from your card] — not the message's links. Do this: [delete + report as phishing] · or [the safe way to act if genuine].

If you already clicked / entered details

  • Change that password (and anywhere reused) + enable 2FA · watch for fraud / contact your bank if payment or card details · run a security scan · report it.

Quality Checks

  • Gives a clear verdict with confidence
  • Cites the specific red/green flags in the actual message
  • Verification uses independent official channels, never the message's links
  • Tells the user exactly what to do next
  • Includes recovery steps for those who already clicked/entered details
  • Never instructs the user to click the suspicious link

Anti-Patterns

  • A vague "be careful" with no verdict or specific flags.
  • Telling them to click the link to "check."
  • Trusting the display name over the real address/domain.
  • Using the phone number/link in the message to "verify."
  • No recovery path for someone who already fell for it.

Example Trigger Phrases

  • "Is this text from my bank real? It says my account is locked."
  • "I got an email asking me to confirm my password — is it a scam?"
  • "Someone messaged me a link about a package fee. Legit?"
  • "I think I just got phished — I clicked the link and logged in."
  • "Did I just get scammed? They asked for a one-time code."

© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/phishing-triage of mohitagw15856/pm-claude-skills.

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

Phishing Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Phishing Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Phishing Triage this skillmohitagw15856/pm-claude-skills1.4k—~1.2kAutomated safety check: PassMIT
Issue Triagepaperclipai/paperclip100k—~1kAutomated safety check: PassMIT
Messages Opsaffaan-m/ECC277k1 repos~724Automated safety check: PassMIT
Triaging Issuespytorch/pytorch104k—~4.2kAutomated safety check: PassCustom licence
Triagepnpm/pnpm37k—~2.9kAutomated safety check: PassMIT
Herdr Issue Triageherdrdev/herdr43k—~517Automated safety check: PassApache-2.0

Similar skills

  • Issue Triage

    paperclipai/paperclip

    Triage Paperclip inbox issues that are stale, blocked, in-review, or assigned-but-not-progressing, and decide a single next action per issue (resume, reassign, unblock, escalate, or close).

    100k GitHub stars~1k tokensUpdated today
    DevelopmentAuto-check passed
  • Messages Ops

    affaan-m/ECC

    Evidence-first live messaging workflow for ECC. An agent skill from affaan-m/ECC.

    277k GitHub starsUsed in 1 repo~724 tokens
    Productivity & AutomationAuto-check passed
  • Triaging Issues

    pytorch/pytorch

    Triages GitHub issues by routing to oncall teams, applying labels, and closing questions.

    104k GitHub stars~4.2k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Triage

    pnpm/pnpm

    Triage an incoming GitHub issue against the pnpm codebase and related open issues, then apply exactly one implementation-readiness label using pnpm's state: taxonomy.

    37k GitHub stars~2.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Herdr Issue Triage

    herdrdev/herdr

    Triages open herdr GitHub issues into a short decision-first Markdown table with a priority light, recommendation, age, reactions and a reason for each.

    43k GitHub stars~517 tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Runs issue triage and PR triage in parallel, then cross-analyzes the results to flag duplicate coverage, security gaps, P0 issues with no PR, and PR conflicts.

    83k GitHub stars~1.6k tokensUpdated yesterday
    DevelopmentAuto-check: notes

More from mohitagw15856/pm-claude-skills

All 1,348 skills in this repo
  • Car Tco

    mohitagw15856/pm-claude-skills

    Compare the total cost of car ownership across buy-new, buy-used, lease, and keep-your-current-car — depreciation, insurance, maintenance ramp, and fuel over a real horizon, not just the monthly…

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Cs Health Scorecard

    mohitagw15856/pm-claude-skills

    Build a customer health scorecard for a specific account. An agent skill from mohitagw15856/pm-claude-skills.

    1.4k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table — liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Fire Number

    mohitagw15856/pm-claude-skills

    Compute a financial-independence (FIRE) target and years-to-reach with every assumption labeled as an assumption — plus a sensitivity table instead of a single false-precision answer.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium — the arithmetic that proves a rate is not salary÷2000.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Questions about Phishing Triage

What does Phishing Triage do?

Decide fast whether a suspicious message is a phishing scam — and what to do next — without clicking anything. Phishing Triage is an agent skill from mohitagw15856/pm-claude-skills. Decide fast whether a suspicious message is a phishing scam — and what to do next — without clicking anything.

When should I use Phishing Triage?

Phishing Triage fits situations like: asked is this email/text a scam; is this message legit; I got a suspicious message; did I just get phished.

How do I install Phishing Triage in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill phishing-triage -a claude-code`. Or copy the skill folder (skills/phishing-triage in mohitagw15856/pm-claude-skills) into .claude/skills/phishing-triage in your project. Claude Code loads it when a task matches its description.

How do I install Phishing Triage in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill phishing-triage -a codex`. Or copy the skill folder (skills/phishing-triage in mohitagw15856/pm-claude-skills) into .agents/skills/phishing-triage in your project. Codex loads it when a task matches its description.

Can I use Phishing Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill phishing-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/phishing-triage, .gemini/skills/phishing-triage, .github/skills/phishing-triage and .opencode/skills/phishing-triage in your project.

What does Phishing Triage need to run?

SKILL.md names no scripts, command-line tools or credentials: Phishing Triage is instructions for the agent only.

Does Phishing Triage access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Phishing Triage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Phishing Triage use?

Phishing Triage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Phishing Triage use?

About 1.2k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Phishing Triage?

Skills that share tags, products or a category with Phishing Triage: Issue Triage (paperclipai/paperclip, 100k stars), Messages Ops (affaan-m/ECC, 277k stars), Triaging Issues (pytorch/pytorch, 104k stars) and Triage (pnpm/pnpm, 37k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Phishing Triage?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,434 GitHub stars. The repository holds 1,348 skills in this directory. The repository was last updated on October 9, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.