Back to skill

Security audit

phishing-spotter

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local, offline phishing-message analyzer whose code and instructions match its stated purpose.

Install only if you are comfortable running a local Python script on messages you choose to provide. Do not paste unrelated sensitive inbox contents unless needed for the analysis, and follow the skill's own guidance not to open or visit suspicious links during review.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

YARA rule 'exploit_framework': Exploit framework components and payloads [hacktools]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: phishing-spotter
description: "Use when you receive a suspicious email, SMS, or voice-mail attempt and want to know if it's phishing BEFORE clicking — parses raw message text or .eml files, extracts URLs and analyzes them character-by-character (homograph IDN tricks, subdomain brand spoofing, URL shorteners, punycode, credential-path patterns like /login/verify), checks 25+ social-engineering pressure patterns (urgency, fear, authority, curiosity, authority), scores the message 0-100, and explains each signal in plain language so you learn to spot the next one yourself."
version: 1.0.0
author: Denis Voronin
license: MIT
tags: [phishing, security, email, scams, fraud-prevention, education]
---

# Phishing Spotter

## Overview

Phishing is still how most accounts get hijacked — not zero-days, not genius hacking, just a message that looks like it's from your bank. AI has made these dramatically better: perfect grammar, tailored context, convincing sender names. Th

YARA rule 'exploit_framework': Exploit framework components and payloads [hacktools]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/phishing_spotter.py (reported line 5)May include surrounding context.

python
#!/usr/bin/env python3
"""Phishing Spotter — textual phishing/smishing/vishing analysis.

Dissects URLs (homograph tricks, subdomain spoofs, shorteners, punycode),
scores 25+ social-engineering pressure patterns, checks structural tells,
and explains every signal in plain language. Never fetches anything.

Usage:
    phishing_spotter.py analyze <file> [--json]
    phishing_spotter.py url "<url>"
    phishing_spotter.py list-patterns
"""
from __future__ import annotations

import argparse
import json
import re
import sys
import unicodedata
from urllib.parse import unquote, urlparse

# --------------------------------------------------------------------------
# Known reference data (offline)
# --------------------------------------------------------------------------

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
71% confidence
Finding

The skill advertises shell execution (python3 scripts/phishing_spotter.py ...) and references analysis of .eml/text inputs, but it does not declare an explicit tool or permission scope. In an agent environment, missing scope boundaries can lead to overbroad access, increasing the chance that the skill is run with unnecessary shell or network privileges despite the documentation claiming analysis should remain offline.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.