AI Agent Hub
Back to skills
Phishing Identification Training icon

Phishing Identification Training

IT Ops & Security Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Follow https://skillhub.cn/install/skillhub.md and install @user_70c2f807/phishing-identification.

About this skill

Problem: phishing looks increasingly real

Emails, SMS, and links now mimic account alerts, delivery failures, and refunds. This skill is not a scanner; it is defensive training: pause before clicking, then inspect sender, domain, attachment, urgency, and information requests.

How it works: defensive triage of messages

Given a suspicious email, SMS, or link, it focuses on three signals: sender identity, content demands, and link behavior. It advises against clicking directly, instead hovering or long-pressing to view the URL, comparing domain spellings such as baiducom.xx vs. baidu.com, and treating bank, courier, platform suspension, or “boss transfer money” scenarios as high risk. If the user clicked but entered nothing, it suggests closing the page, clearing cache, and scanning; if credentials were entered, it directs immediate password change, platform contact, and IT reporting. Reporting paths include mailbox flags, SMS to 12321, official institutions, anti-fraud apps, and regulators.

Boundaries

It is intended for personal self-testing, email hygiene, and incident response. It does not provide offensive methods, social engineering in penetration testing, anti-phishing product development, or replace enterprise DMARC/SPF configuration and professional security teams. AI-generated phishing will get more realistic, so detection skills need ongoing practice.

Use Cases

  • Judge bank, courier, or account-suspension SMS as phishing and choose next actions.
  • Verify leader or support requests for transfer or verification code without clicking.
  • Remediate after clicking a link: close page, clear cache, scan malware.
  • Flag suspicious enterprise emails, senders, attachments, and links for reporting.

Best For

  • Customer support agents who must verify inbound emails or tickets before replying.
  • New engineers who need to spot suspicious links, senders, and credential requests.
  • IT operations staff who need to explain phishing triage, reporting, and remediation.
  • Business operations owners managing accounts who need to avoid fake refund alerts.