Install
openclaw skills install @voronindenis5/phishing-spotterUse when you receive a suspicious email, SMS, or voice-mail attempt and want to know if it's phishing BEFORE clicking — parses raw message text or .eml files, extracts URLs and analyzes them character-by-character (homograph IDN tricks, subdomain brand spoofing, URL shorteners, punycode, credential-path patterns like /login/verify), checks 25+ social-engineering pressure patterns (urgency, fear, authority, curiosity, authority), scores the message 0-100, and explains each signal in plain language so you learn to spot the next one yourself.
openclaw skills install @voronindenis5/phishing-spotterPhishing is still how most accounts get hijacked — not zero-days, not genius hacking, just a message that looks like it's from your bank. AI has made these dramatically better: perfect grammar, tailored context, convincing sender names. The weakest link is the three seconds between "Your account will be suspended" and the click.
This skill is a train-your-instincts analyzer. It doesn't just say "dangerous" — it shows you every signal in the message, weighted, explained, so the analysis doubles as education. Run it on messages you're unsure about; after a dozen, you start seeing the patterns yourself.
What it checks:
pаypal.com with a Cyrillic а), brand names in subdomains (paypal.com.evil.io), URL shorteners, punycode (xn--), IP-address hosts, credential-bait paths (/login, /verify, /wallet), lookalike TLDs (.co, .tk, .xyz), @ trickery in URLs, hex/redirect chains.Offline, stdlib-only. No URLs are visited — analysis is purely textual, so running it never tips off an attacker.
From:, Reply-To, Subject get extra checks).# Analyze pasted text (body only)
python3 scripts/phishing_spotter.py analyze message.txt
# Analyze a full .eml with headers (more detectors fire)
python3 scripts/phishing_spotter.py analyze suspicious.eml
# Just dissect a URL you're unsure about
python3 scripts/phishing_spotter.py url "http://paypal.com.verify-account.io/login"
# List all pressure-pattern detectors
python3 scripts/phishing_spotter.py list-patterns
# JSON for pipelines
python3 scripts/phishing_spotter.py analyze message.txt --json
$ python3 scripts/phishing_spotter.py analyze references/sample-phish.txt
RISK SCORE: 87/100 — ALMOST CERTAINLY PHISHING
Based on 11 signals. Do not click, do not reply.
TOP SIGNALS:
[+25] BRAND IN SUBDOMAIN SPOOF
URL: http://paypal.com.verify-account.io/login
The real brand is in a SUBDOMAIN. Reading right-to-left: the actual
site is verify-account.io. paypal.com belongs to the attacker's
subdomain string, not to PayPal.
[+20] CREDENTIAL-BAIT PATH
/login in URL path — phishing kits love paths that promise a login
form. Combined with brand spoofing above, this is a credential
harvester with near-certainty.
[+15] ARTIFICIAL DEADLINE
"within 24 hours" — real institutions send notice before action,
not countdown ultimatums. Urgency exists to stop you thinking.
[+12] THREAT OF ACCOUNT LOSS
"your account will be permanently suspended" — fear of loss is the
#1 phishing motivator. Banks don't suspend accounts by email.
URL ANALYSIS:
1. http://paypal.com.verify-account.io/login
host=verify-account.io ← BRAND 'paypal' IN SUBDOMAIN (spoof)
path contains credential bait: /login
2. https://bit.ly/3xKp2mQ
shortener — destination hidden; expand (safely) before any trust
STRUCTURAL TELLS:
Display name "PayPal Support" vs domain verify-account.io — mismatch
BEFORE YOU ACT — verify independently:
1. Open your bank's app/site directly (type it yourself). Any real
"suspicious activity" notice will be visible there too.
2. If unsure, call the number ON YOUR CARD, never one from the message.
3. Report: forward to phishing@<brand-domain> and delete.
SIGNALS TO MEMORIZE FROM THIS MESSAGE:
1. Brand in subdomain (paypal.com.evil.io) — read domains right-to-left
2. 24-hour ultimatums
3. Display name ≠ sending domain
| Category | Detectors | Weight |
|---|---|---|
| URL spoofing | homograph/IDN chars, brand-in-subdomain, @ in URL, punycode xn--, IP host, lookalike TLD | 20–25 |
| URL infrastructure | shorteners, credential-bait paths, hex-encoded hosts, double redirects | 8–20 |
| Pressure tactics | artificial deadline, account-loss threat, legal action, authority claim, curiosity gap, lottery/reply-too-good | 10–15 |
| Payment rails | gift cards, crypto wallets, wire instructions, "pay to release" | 12–15 |
| Structural | display-name mismatch, reply-to divergence, generic greeting, no personalization, risky attachment ext | 5–12 |
Full pattern list: list-patterns.
analyze; present score, then the TOP signals with quotes — the quoted text IS the evidence.paypal.com.verify-account.io contains "paypal.com" as a substring — that's the trick. Detectors parse domain structure, not substrings.