social-eng-phishing

Installation
SKILL.md

Phishing assessment

When it applies

The engagement authorizes an email human-factor test and you've cleared social-eng-methodology (authorization, allowed pretext themes, target boundaries, no-harm line). The goal is a measurement — click rate, credential-submission rate, and, most importantly, the report rate — not to embarrass anyone.

Why it works

Phishing exploits trust and context, not a software bug: a message that looks like it comes from a trusted source, with a plausible reason to act now, gets clicks even from trained users. Measuring that safely tells the client where awareness and technical controls (MFA, mail filtering, reporting tooling) need to improve.

Installs
2
GitHub Stars
19
First Seen
7 days ago
social-eng-phishing — noorqureshi/sploitagent