Skillbook
Safety · № S01
Free

Spot a phishing email

The 7 tells, ranked by how often they actually catch people.

For
Anyone
Time per use
1 min
Format
.md and .skill
How to use it
  1. 1.
    Open Claude or ChatGPT.
    Either works. The skill is just text.
  2. 2.
    Copy this skill from the free shelf.
    One click; no install, no setup.
  3. 3.
    Paste it as your first message.
    The assistant now knows how to do this one job.
  4. 4.
    Give it your specifics, get the result.
    Roughly 1 min, every time you need it.
s01-spot-a-phishing-email.skill.md1.3 KB
Run once
Install as agent behavior

Install this as reusable agent behavior.

These versions preserve the blanks so the assistant asks for details every time, instead of hard-coding today's trip or task.

# Spot a phishing email

I'll paste an email I'm suspicious of. Tell me whether it's phishing and how confident you are.

## What I want back

**Verdict:** Almost certainly phishing / Probably phishing / Unclear / Probably legit / Almost certainly legit.

**The seven tells, applied to this email:**

1. **Sender domain mismatch** — does the visible name match the actual domain?
2. **Urgency** — are they pressuring action in a short timeframe?
3. **Hovered links** — where do the links actually go vs. where they say they go?
4. **Generic greeting** — "Dear Customer" when they should know my name.
5. **Asks for credentials, money, or codes** — directly or through a "verify your account" link.
6. **Unusual sender for the request** — would this person/company actually email this?
7. **Subtle wrongness** — odd grammar, off-brand formatting, a logo that's slightly wrong.

For each: present / absent / not visible from what I pasted.

**What to do:**

- If phishing: don't click, report it (give me the right path for my email provider), and check whether anything's already compromised.
- If legit: still verify out-of-band before doing what it asks.
- If unclear: how to verify without clicking anything in the email.

## Rules

- Err toward suspicion.
- Don't tell me to "be careful." Tell me what to do.

Email below.

On the house. Run it in Claude or ChatGPT, or install it as agent behavior.

↓ Download .md