phishing-spotter

Use when you receive a suspicious email, SMS, or voice-mail attempt and want to know if it's phishing BEFORE clicking — parses raw message text or .eml files, extracts URLs and analyzes them character-by-character (homograph IDN tricks, subdomain brand spoofing, URL shorteners, punycode, credential-path patterns like /login/verify), checks 25+ social-engineering pressure patterns (urgency, fear, authority, curiosity, authority), scores the message 0-100, and explains each signal in plain language so you learn to spot the next one yourself.

Install

openclaw skills install @voronindenis5/phishing-spotter