Agent skill

Scam Message Decoder

by mohitagw15856 in mohitagw15856/pm-claude-skills

Decode a suspicious message β€” text, email, call transcript, or DM β€” against the anatomy of known scam families, with a πŸ”΄πŸŸ‘πŸŸ’ read and the safe next move.

MITAuto-check passedProductivity & Automation

Install Scam Message Decoder

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill scam-message-decoder -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills scam-message-decoder --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/scam-message-decoder .claude/skills/scam-message-decoder && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation Β· loads skills from .claude/skills/

Facts

Skill name
scam-message-decoder
GitHub stars
1.4k
Token cost
~1.6k tokens
SKILL.md length
792 words
Files
1
Skills in repo
1,322
Repo updated
First seen
Licence
MIT

At a glance

Decode a suspicious message β€” text, email, call transcript, or DM β€” against the anatomy of known scam families, with a πŸ”΄πŸŸ‘πŸŸ’ read and the safe next move.

  • Works in 5 steps: The skeleton check: urgency ("within 24… β†’ Family matching sharpens the read:… β†’ The universal counter is channel… β†’ …
  • Someone asks is this a scam
  • SKILL.md covers What This Skill Produces, Required Inputs, Framework: The Anatomy Rules and Output Format, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Scam Message Decoder is an agent skill from mohitagw15856/pm-claude-skills. Decode a suspicious message β€” text, email, call transcript, or DM β€” against the anatomy of known scam families, with a πŸ”΄πŸŸ‘πŸŸ’ read and the safe next move. Use when someone asks is this a scam, decode this suspicious text, my 'bank' just called me, this job offer seems off, or my parent got a weird message. Produces the verdict with the specific scam-family match, the tells quoted from the message itself, the safe-verification path (never the message's own links or numbers), and the if-you-already-clicked triage.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Productivity & Automation, covering Meeting notes and agendas. The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex β€” PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Someone asks is this a scam
  • Decode this suspicious text
  • My bank just called me
  • This job offer seems off

Example prompts

  • β€œ/scam-message-decoder”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. The skeleton check: urgency ("within 24 hours", "your account will be suspended") + unusual payment rail (gift cards, wire, crypto…
  2. Family matching sharpens the read: bank-fraud-alert calls (real banks don't ask you to move money to a "safe account" β€” that request IS…
  3. The universal counter is channel independence: hang up and call the number on the card Β· type the site yourself Β· contact the "relative"…
  4. 🟒 exists and gets said: real messages get flagged by anxious people constantly; a delivery text that matches an expected package, links…
  5. Already-engaged triage, in order: money sent β†’ contact the bank/rail's fraud line now (speed matters for recalls β€” some rails can claw…

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Scam Message Decoder loads about 1.6k tokens when it runs. Until then it costs about 135 tokens; SKILL.md has 792 words of instructions outside code blocks.

Always Β· name and description, kept in context so the agent knows when to use it
~135
When it runs Β· the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters Γ· 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check β€” not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (Β© mohitagw15856). 792 words, ~1,550 tokens.

Download SKILL.mdSave it as .claude/skills/scam-message-decoder/SKILL.md (or your agent's skills folder).
name
scam-message-decoder
description
Decode a suspicious message β€” text, email, call transcript, or DM β€” against the anatomy of known scam families, with a πŸ”΄πŸŸ‘πŸŸ’ read and the safe next move. Use when someone asks is this a scam, decode this suspicious text, my 'bank' just called me, this job offer seems off, or my parent got a weird message. Produces the verdict with the specific scam-family match, the tells quoted from the message itself, the safe-verification path (never the message's own links or numbers), and the if-you-already-clicked triage.

Scam Message Decoder Skill

Every scam is a costume over the same skeleton: manufactured urgency, an unusual payment or credential request, and a channel you didn't initiate. This skill reads the actual message against the known families β€” phishing, smishing, the fake-fraud-alert call, job scams, romance/pig-butchering, invoice fraud, grandparent emergencies, tech-support pop-ups β€” quotes the tells from the text itself, and gives the one move that defeats nearly all of them: verify through a channel you already had, never through anything the message provides. No shame anywhere in the output; these work on smart people because they're built by professionals to.

What This Skill Produces

  • The verdict β€” πŸ”΄ scam-pattern match / 🟑 suspicious-verify-first / 🟒 consistent-with-legitimate β€” with the family named
  • The tells, quoted β€” each red flag pointed at the message's own words
  • The safe next move β€” the independent-channel verification path, specific to the situation
  • The already-engaged triage β€” clicked/paid/shared? The damage-control ladder, calm and ordered

Required Inputs

Ask for these if not provided:

  • The message itself β€” pasted verbatim (sender address/number included; the from-field is often the loudest tell)
  • The context β€” do they have a relationship with the claimed sender? Were they expecting anything? (An unexpected "your package is held" and an expected delivery read differently β€” barely)
  • Engagement status β€” just received, or already clicked/replied/paid β€” the second reroutes the whole output to triage first

Framework: The Anatomy Rules

  1. The skeleton check: urgency ("within 24 hours", "your account will be suspended") + unusual payment rail (gift cards, wire, crypto, payment apps to strangers β€” no legitimate institution takes gift cards, ever, for anything) + initiated-by-them = πŸ”΄ regardless of how good the costume is. These three carry more weight than any logo.
  2. Family matching sharpens the read: bank-fraud-alert calls (real banks don't ask you to move money to a "safe account" β€” that request IS the scam) Β· delivery/toll smishing (the link domain is the tell) Β· job scams (pay-for-equipment, check-then-refund = the overpayment engine) Β· romance/investment grooming (weeks of warmth, then a platform only they can see) Β· invoice/BEC (the changed-bank-details email β€” verify by phone on a known number, always) Β· grandparent/emergency (voice "proof" no longer proves β€” say so plainly) Β· tech-support pop-ups (the number on the screen is the scam). Each match brings its specific counter-move.
  3. The universal counter is channel independence: hang up and call the number on the card Β· type the site yourself Β· contact the "relative" on their known number Β· verify invoices by known-number phone call. The message's links, numbers, and "press 1" exist to keep you inside the scam's channel β€” the decode says this explicitly every time.
  4. 🟒 exists and gets said: real messages get flagged by anxious people constantly; a delivery text that matches an expected package, links to the real domain, and asks for nothing is 🟒 β€” with the note that typing the tracking number into the carrier's site yourself costs nothing. Crying wolf on everything teaches people to stop checking.
  5. Already-engaged triage, in order: money sent β†’ contact the bank/rail's fraud line now (speed matters for recalls β€” some rails can claw back, some can't; no promises made) Β· credentials shared β†’ change that password + everywhere it's reused + enable 2FA Β· card numbers β†’ freeze/reissue Β· remote access granted β†’ disconnect, run security scan, change passwords from a different device Β· then report (the platform, and the national reporting body β€” named as a type, jurisdiction-flagged). Shame delays every one of these steps, so the triage opens by saying: professionals fall for professional scams; speed matters more than embarrassment.
Show full SKILL.md (236 more words)Show less

Output Format

Scam Decode: [message type] β€” verdict: [πŸ”΄/🟑/🟒]

[The one-line verdict with the family name: "πŸ”΄ β€” this matches the fake-bank-fraud-alert pattern."]

The Tells

"[quoted line from the message]" [What it signals Β· why legitimate senders don't do this]

The Safe Move

[The independent-channel verification, specific: which number/site, from where]

If You Already Engaged

[The ordered triage for what was shared, calm, no shame β€” speed over embarrassment]

Scam patterns evolve and reporting channels vary by country β€” when money has moved, the bank's fraud line and local reporting body come before everything else. No legitimate organization takes payment in gift cards.

Quality Checks

  • Every red flag quotes the message's actual words
  • The verdict names a specific family, not generic "be careful"
  • The safe move uses only channels the user already had
  • 🟒 verdicts are given when earned, with the free-verification note
  • The triage is ordered by recoverability speed and opens shame-free

Anti-Patterns

  • Do not shame the target anywhere β€” these are professional operations; embarrassment is part of their design
  • Do not verify through anything the message provided β€” links, numbers, "press 1"
  • Do not mark everything πŸ”΄ β€” false alarms train people to stop asking
  • Do not promise recovery of sent money β€” route to the fraud line fast and honestly
  • Do not reproduce or improve scam text β€” this skill decodes attacks, never drafts them

Example Trigger Phrases

  • "Is this a scam?"
  • "Decode this suspicious text."
  • "My 'bank' just called me."
  • "My parent got a weird message."

Β© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/scam-message-decoder of mohitagw15856/pm-claude-skills.

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

Scam Message Decoder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; β€œused in” counts other GitHub owners with a copy.

Scam Message Decoder compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Scam Message Decoder this skillmohitagw15856/pm-claude-skills1.4kβ€”~1.6kAutomated safety check: PassMIT
Meeting Notesoutline/outline41kβ€”~551Automated safety check: PassCustom licence
Management Talkthananon/9arm-skills3.2kβ€”~3.2kAutomated safety check: PassNone
Challenge Baseline ModelAgibotTech/genie_sim1.4kβ€”~2.4kAutomated safety check: PassCustom licence
Handwriting Stand Uplimin112/min-skill362β€”~2.5kAutomated safety check: PassNone
Daily Journalravila4/claude-adhd-skills157β€”~2.5kAutomated safety check: PassMIT

Similar skills

  • Meeting Notes

    outline/outline

    Create meeting notes in Outline from a template; use when the user wants an agenda, notes, or a follow-up document for a meeting.

    41k GitHub stars~551 tokensUpdated yesterday
    Productivity & AutomationAuto-check passed
  • Management Talk

    thananon/9arm-skills

    Rewrite engineer-to-engineer content for engineering-org leadership (VPs, directors, PMs, release managers, execs in an engineering-savvy company) and shape it for the channel it is going to β€” JIRA…

    3.2k GitHub stars~3.2k tokensUpdated 3 mo ago
    Productivity & AutomationAuto-check passed
  • Challenge Baseline Model

    AgibotTech/genie_sim

    Provision and launch the Simulation Challenge baseline inference model end to end: clone the inference code from a given git repo/branch, download the checkpoints from ModelScope into the repo's…

    1.4k GitHub stars~2.4k tokensUpdated 1 mo ago
    Productivity & AutomationAuto-check passed
  • Handwriting Stand Up

    limin112/min-skill

    Turn a screen recording of handwriting (or a photo of handwritten text) into a single-file HTML "continuation" β€” the recording plays, the ink lifts off the page as solid 3D letters, a short animated…

    362 GitHub stars~2.5k tokensUpdated 15 days ago
    Productivity & AutomationAuto-check passed
  • Daily Journal

    ravila4/claude-adhd-skills

    Draft, organize, or update development journal entries. An agent skill from ravila4/claude-adhd-skills.

    157 GitHub stars~2.5k tokensUpdated 7 mo ago
    Productivity & AutomationAuto-check passed
  • Granola

    ArtemXTech/claude-code-obsidian-starter

    Query and sync Granola meetings to Obsidian vault. An agent skill from ArtemXTech/claude-code-obsidian-starter.

    224 GitHub stars~905 tokensUpdated 3 days ago
    Productivity & AutomationAuto-check passed

More from mohitagw15856/pm-claude-skills

All 1,322 skills in this repo
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table β€” liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium β€” the arithmetic that proves a rate is not salaryΓ·2000.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Offer Comparison

    mohitagw15856/pm-claude-skills

    Compare two or more job offers as total-comp curves over four years β€” vesting cliffs, bonuses, 401(k) match, and the crossover year computed, not vibed.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Refinance Breakeven

    mohitagw15856/pm-claude-skills

    Compute the month a refinance actually starts saving money β€” payment delta, breakeven month, and total interest on both paths including the term-reset trap.

    1.4k GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Rent Vs Buy

    mohitagw15856/pm-claude-skills

    Model rent-vs-buy honestly β€” year-by-year net position for both paths including the assumption everyone drops (the renter invests the difference), with a breakeven horizon instead of a verdict.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Questions about Scam Message Decoder

What does Scam Message Decoder do?

Decode a suspicious message β€” text, email, call transcript, or DM β€” against the anatomy of known scam families, with a πŸ”΄πŸŸ‘πŸŸ’ read and the safe next move. Scam Message Decoder is an agent skill from mohitagw15856/pm-claude-skills. Decode a suspicious message β€” text, email, call transcript, or DM β€” against the anatomy of known scam families, with a πŸ”΄πŸŸ‘πŸŸ’ read and the safe next move.

When should I use Scam Message Decoder?

Scam Message Decoder fits situations like: someone asks is this a scam; decode this suspicious text; my bank just called me; this job offer seems off.

How do I install Scam Message Decoder in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill scam-message-decoder -a claude-code`. Or copy the skill folder (skills/scam-message-decoder in mohitagw15856/pm-claude-skills) into .claude/skills/scam-message-decoder in your project. Claude Code loads it when a task matches its description.

How do I install Scam Message Decoder in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill scam-message-decoder -a codex`. Or copy the skill folder (skills/scam-message-decoder in mohitagw15856/pm-claude-skills) into .agents/skills/scam-message-decoder in your project. Codex loads it when a task matches its description.

Can I use Scam Message Decoder in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill scam-message-decoder -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/scam-message-decoder, .gemini/skills/scam-message-decoder, .github/skills/scam-message-decoder and .opencode/skills/scam-message-decoder in your project.

What does Scam Message Decoder need to run?

SKILL.md names no scripts, command-line tools or credentials: Scam Message Decoder is instructions for the agent only.

Does Scam Message Decoder access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Scam Message Decoder safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Scam Message Decoder use?

Scam Message Decoder is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Scam Message Decoder use?

About 1.6k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Scam Message Decoder?

Skills that share tags, products or a category with Scam Message Decoder: Meeting Notes (outline/outline, 41k stars), Management Talk (thananon/9arm-skills, 3.2k stars), Challenge Baseline Model (AgibotTech/genie_sim, 1.4k stars) and Handwriting Stand Up (limin112/min-skill, 362 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Scam Message Decoder?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,431 GitHub stars. The repository holds 1,322 skills in this directory. The repository was last updated on October 7, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.