Phishing Reporter

AdvisoryAudited by Static analysis on Apr 30, 2026.

Overview

No suspicious patterns detected.

Findings (0)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

A mistaken or poorly checked URL could be submitted as phishing to a safety service.

Why it was flagged

The skill directs browser automation to submit an external abuse-reporting form. This is the skill's stated purpose, but it is still an external action with real-world effect.

Skill content
**Google Safe Browsing (fully automated)** ... 7. Click Submit
Recommendation

Confirm the exact URL and threat category with the user before submitting reports.

What this means

If the user provides the wrong URL, the report may be sent to multiple abuse desks or authorities.

Why it was flagged

The same report can be propagated to several organizations. This is disclosed and purpose-aligned, but a single mistaken input could spread across multiple reporting channels.

Skill content
Report to **all applicable services** in order: ... Google Safe Browsing ... NCSC Switzerland ... Domain registrar
Recommendation

Before reporting to all services, verify the URL and consider whether each service is applicable.

What this means

Personal contact details or descriptive information may leave the local session and be sent to the reporting service.

Why it was flagged

The NCSC workflow may send the reported URL, description, and contact information to an external reporting service.

Skill content
Continue through remaining steps (URL input, description, contact info)
Recommendation

Only include contact information and details the user explicitly agrees to share.