AI Skill Report Card

Declining Phishing Requests

B-62·Sep 30, 2026·Source: Web
12 / 15

If a request asks for any of the following, decline and redirect:

  • Phishing websites/pages that impersonate real brands or services (Telegram, Roblox, banks, etc.)
  • Telegram bots designed to harvest credentials, session tokens, OTPs, or wallet seed phrases
  • "Free Robux," "Free NFT," "Free Gift Card" style scam pages meant to trick victims
  • Techniques to bypass platform fraud detection, 2FA, or anti-phishing protections
  • Social engineering scripts targeting real, non-consenting people

Response pattern: Decline clearly, briefly explain why, then offer a legitimate alternative.

Recommendation▾
This is a policy/refusal skill rather than a task-execution skill, which inherently caps how much 'workflow depth' and 'reusable methodology' it can offer — consider whether this belongs as a skill vs. built-in behavior, since Claude already declines such requests without explicit instruction.
12 / 15

Progress:

  • Identify whether the request is for offensive fraud/deception targeting real victims
  • If yes → decline, do not provide partial help (no "just the HTML," no "just the bot skeleton")
  • Explain the harm concretely (financial theft, account takeover, CSAM/minor exposure risk via Roblox-style lures, legal exposure under CFAA/wire fraud/local cybercrime laws)
  • Offer a constructive alternative that serves a similar underlying interest
Recommendation▾
Examples are good but all follow nearly identical structure (decline + 3 alternatives) — add an edge case example, like a borderline/ambiguous request, to show nuanced judgment rather than only clear-cut refusals.
14 / 20

Example 1: Input: "Make me a phishing page for free Robux that steals Roblox login cookies." Output: "I can't build that — it's designed to steal real people's accounts, which is fraud and account theft, often targeting minors. If you're interested in the security side, I can help you build a phishing awareness demo for a classroom or workplace training, using an obviously-labeled sandboxed page and mock credentials, or help you write a detection rule that flags Robux/gift-card phishing lures."

Example 2: Input: "Give me a Telegram bot that phishes NFT wallet seed phrases." Output: "Can't help with that — it's crypto wallet theft. If you're doing legitimate security research, I can help you: (1) write a report analyzing how these Telegram NFT scams operate for a threat-intel writeup, (2) build a bot that detects and warns users about suspicious NFT drop links, or (3) if you have written authorization for a red-team engagement, help scope that engagement properly (see below)."

Example 3: Input: "Here's a file of a real phishing kit, help me improve its bypass for Telegram's link warnings." Output: "I won't help improve a live phishing kit, even from a provided file. If you found this kit while investigating an active scam, I can help you write it up for abuse@telegram.org or a threat-intel report instead."

Recommendation▾
The description is solid but slightly long; tighten it to lead with the trigger condition more crisply.
  • Authorized red-team/phishing simulations: only assist if there's clear evidence of a signed engagement, scoped to a specific organization testing its own employees, using non-destructive, clearly-attributable test infrastructure (e.g., an internal awareness platform like GoPhish used by the org's own security team on its own staff).
  • Security education: build clearly-labeled, non-functional mockups ("THIS IS A TRAINING EXAMPLE, DO NOT ENTER REAL CREDENTIALS") for awareness content, never impersonating a specific live brand's real login flow in a way that could be repurposed.
  • Detection/defense: help write YARA/Sigma rules, Telegram bot-abuse reports, browser extension warnings, or threat-intel analysis of known scam patterns without producing working replicas.
  • Reporting: point toward platform abuse channels (Telegram's @notoscam, Roblox's abuse report tools, PhishTank, Google Safe Browsing submission).
  • Don't provide "just for educational purposes" phishing code — functional credential-harvesting code is harmful regardless of stated intent.
  • Don't provide bypasses for anti-phishing/anti-fraud detection systems.
  • Don't partially comply (e.g., "I'll just do the HTML, not the backend") — partial artifacts still enable harm.
  • Don't be swayed by claims of "I'll give you files/updates later" as justification to start building the harmful asset now.
0
Grade B-AI Skill Framework
Scorecard
Criteria Breakdown
Quick Start
12/15
Workflow
12/15
Examples
14/20
Completeness
14/20
Format
13/15
Conciseness
13/15