Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Phishing Tester

ASecurity

Run authorized phishing simulations to measure susceptibility, train staff, and strengthen reporting culture — safely and ethically.

2 stars
0 votes
0 copies
0 views
Added 9/29/2026
ai-agentsrustgotestingsecurity

Works with

cli

Security Analysis

A100/100

Scanned 9/29/2026

$npx -y skills add aicodedecode/awesome-muse-skills --skill phishing-tester --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Phishing Tester?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Phishing Tester
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aicodedecode-phishing-tester/badge)](https://www.skillsdirectory.com/skills/aicodedecode-phishing-tester)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: phishing-tester
description: Run authorized phishing simulations to measure susceptibility, train staff, and strengthen reporting culture — safely and ethically.
category: security
---

## Overview

Phishing simulations send benign, clearly-controlled mock lures to employees to measure how many click, how many report, and how fast. Done well, they are a training tool that builds the reporting habit. Done badly, they are a trust-destroying gotcha exercise. The difference is entirely in program design: transparency, proportionality, and blameless follow-up.

This skill covers running an ethical simulation program: authorization, safe lure design, measurement, and coaching. It contains no real phishing tradecraft.

A simulation program lives or dies on trust: employees must believe it exists to protect them, not to trap them. Announce the program, explain the no-punishment policy in plain language, and make every touchpoint educational. The day employees forward real phish to security without being asked, the program has worked — regardless of what the click-rate dashboard says.

## When to use

- Establishing a baseline of phishing susceptibility for awareness planning.
- Validating that training and technical controls (email filtering, reporting button) work.
- Meeting compliance or cyber-insurance expectations for testing human controls.
- After a real phishing incident, to check whether the lesson stuck.

## Core concepts

- **Authorization and scope:** written approval from leadership and HR/legal; simulations target employees as part of an announced security program — never secret tests of individuals, never targeting personal accounts.
- **Benign by design:** lures must be obviously fake on close inspection, contain no malware, harvest no real credentials (use clearly-labeled training landing pages), and cause no data loss.
- **Proportionality:** lures should resemble realistic threats, not exploit personal trauma, financial fear, or HR consequences (fake layoffs, fake bonus cuts, fake disciplinary notices are off-limits).
- **The metric that matters is reporting:** click rate tells you exposure; report rate and report speed tell you resilience. Optimize for reporting.
- **Immediate micro-training:** a clicker lands on a 60-second "here is what gave it away" page — education at the teachable moment, not a walk of shame.
- **Aggregate, don't single out:** report by department/role for coaching; individual data stays with security and managers for supportive follow-up only.

- **Difficulty calibration.** Start with obvious lures and progress to sophisticated ones. A baseline that crushes morale with a nation-state-grade lure teaches nothing.
- **Channel expansion with care.** Email first; SMS and voice simulations only with explicit additional approval, as they feel more invasive and carry higher trust risk.
- **Control effectiveness signal.** Simulation results also test your email filtering — high click rates on lures that should have been filtered are a tooling problem, not a people problem.

## Practical workflow

1. **Get authorization:** leadership + HR + legal sign-off on the program charter: purpose, scope, lure boundaries, data handling, and no-punishment policy. Announce the program's existence (not the schedule).
2. **Baseline:** run a neutral-difficulty simulation to establish click/report rates by department. This is your before picture.
3. **Design lures responsibly:** model on current real-world themes (fake shared doc, password expiry, delivery notice); keep difficulty progressive; never use the prohibited themes above.
4. **Execute safely:** send in waves during business hours; landing pages clearly branded as training; no credential storage — if a form is used, discard input and say so.
5. **Measure:** click rate, credential-submit rate (if applicable), report rate, median time-to-report, and repeat-clicker rate. Compare against baseline.
6. **Coach and improve:** immediate micro-training for clickers; targeted coaching for repeat clickers and high-risk roles; share anonymized trends org-wide ("reporting up 40% — great work"); feed results into the awareness program.

### Program charter essentials

- Purpose: measure and improve phishing resilience, not punish
- Scope: which populations, which channels (email; SMS/voice only with extra approval)
- Prohibited lure themes (HR actions, layoffs, personal emergencies, financial threats)
- Data handling: who sees individual results, retention period
- No-punishment commitment and coaching approach
- Success metrics: report rate and time-to-report trending up

### Sustaining the practice

- Vary themes each round; retire lures after a single use
- Publish anonymized trends org-wide to normalize reporting as a shared win
- Align simulation difficulty progression with training curriculum
- Review the program charter annually with HR and legal

### Metrics that prove it works

- Click, submit, and report rates by department, trended per round
- Median time-to-report (the resilience metric)
- Repeat-clicker rate after coaching intervention
- Coaching completion rate for clickers

## Common pitfalls

- **Gotcha culture.** Surprise tests with punishment destroy the trust that reporting culture needs. Announce the program; coach, don't punish.
- **Cruel or manipulative lures.** Fake layoffs or bonus threats cause real distress and HR crises. Keep lures professional and proportional.
- **Harvesting real credentials.** Never collect or store actual passwords, even "for training." Use obviously-fake forms and discard input.
- **Measuring only clicks.** A program that drives clicks down but never measures reporting is optimizing the wrong thing.
- **Targeting personal accounts or non-employees.** Simulations stay inside the employment relationship and the announced program.
- **No follow-through.** Simulations without coaching and control improvements are just surveillance. Every round should change training or tooling.
- **Testing too frequently.** Monthly gotcha emails breed fatigue and resentment. Quarterly themed rounds with fresh lures beat constant low-grade testing.
- **Reusing the same lure.** Teams learn the template, not the skepticism. Retire lures after one use and model new ones on current real-world campaigns.
- **Naming and shaming departments.** Public leaderboards of 'worst clickers' destroy trust. Share trends, coach privately, celebrate reporting.
- **Simulations during layoffs or crises.** Testing stressed employees facing real uncertainty is cruel and produces meaningless data. Pause the program when the org is under strain.

Attribution

aicodedecodeaicodedecode
View sourceSee grades on GitHubMore from aicodedecode →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →