← 返回 Skills 市场
kostja94

brand-protection

作者 Kostja Zhang · GitHub ↗ · v1.0.1 · MIT-0
cross-platform ✓ 安全检测通过
95
总下载
0
收藏
1
当前安装
1
版本数
在 OpenClaw 中安装
/install brand-protection
功能描述
When the user faces brand impersonation, fake websites, phishing sites, or trademark infringement. Also use when the user mentions "fake site," "impersonatio...
使用说明 (SKILL.md)

Strategy: Brand Protection

Guides discovery, reporting, and prevention of brand impersonation—fake websites, phishing sites, trademark infringement, and domain squatting. See domain-selection for defensive domain registration; trust-badges for official site verification signals; about-page for identity declaration.

When invoking: On first use, if helpful, open with 1–2 sentences on what this skill covers and why it matters, then provide the main output. On subsequent use or when the user asks to skip, go directly to the main output.

Initial Assessment

Check for project context first: If .claude/project-context.md or .cursor/project-context.md exists, read it for brand name, official domain, and key assets.

Identify:

  1. Impersonation type: Fake website, phishing, trademark misuse, domain squatting
  2. Evidence available: Screenshots, URLs, WHOIS, hosting info
  3. Legal assets: Registered trademark, copyright ownership
  4. Impact: Traffic interception (fake site ranks for brand queries)? Payment fraud (users pay on fake site, then contact official support)?

Evidence Collection Checklist

Item Action
Full URLs Document all key pages of the fake site
Screenshots Homepage, product pages, logo, layout; include date/time
Comparison Side-by-side: official vs fake (layout, logo, copy similarity)
WHOIS Use ICANN Lookup for registrar, creation date, registrant
Hosting IP lookup to identify hosting provider

Reporting Channels (Priority Order)

Channel Entry Use Case
Domain registrar Abuse / Report Misuse on registrar site Brand impersonation, trademark, fraud
Hosting provider Same; submit abuse form Hosting infringing content
Google Safe Browsing Report Phishing Phishing / impersonation risk
Google Trademark Trademark Complaint or [email protected] Trademark infringement in search; requires registered trademark
Bing Content Removal Content Moderation Platform Copyright/trademark; content removal from Bing
Payment processors PayPal Resolution Center, Stripe support If fake site accepts payments; report fraud
Social platforms X, Facebook, Instagram abuse forms If fake site is promoted or linked there
Google Ads / Microsoft Ads Platform trademark complaint forms If impersonator runs brand ads
DMCA To hosting provider Copyright infringement; images, copy, design copied
ICANN DNS Abuse complaint If registrar does not respond within reasonable time

Report content: Include full URL, clear description of fraudulent activity, and all evidence (screenshots, logs).

Reporting Best Practices

Registrar vs hosting: Use ICANN Lookup for registrar. For hosting, use IP lookup (HostingCheckerOnline, HostingDetector, ipinfo.io) to find origin server—registrar may be Cloudflare while origin host is elsewhere; report to both.

Cloudflare as registrar: Use abuse.cloudflare.com or abuse form; select "Phishing & Malware" for impersonation. Email complaints are generally not processed; use the online form. Provide specific URLs of infringing pages.

Hosting detection: Sites behind Cloudflare CDN hide origin IP. Use reverse IP lookup or hosting detection tools to identify underlying host; submit abuse to that provider as well.

Parallel reporting: Submit to registrar, host, and Google Safe Browsing simultaneously; do not wait for one before others. Google trademark review takes 1–8 weeks.

Legal Options

Option When Notes
Cease and desist Trademark infringement Lawyer-drafted; often first step
DMCA takedown Copyrighted material copied Images, copy, design; hosting providers typically comply
Consumer protection Scam / fraud FTC ReportFraud.ftc.gov (US)
Law enforcement Financial loss, identity theft IC3 (FBI) for cybercrime

Prevention Measures

Defensive Registration

  • Register brand+ai, brand+app, brand+official, etc. See domain-selection for defensive registration.
  • Redirect variants to main domain; do not deploy separate sites.

Official Site Verification

Place "Official website: [domain]" prominently:

  • Homepage (above fold or hero)
  • Sign-in / Sign-up pages
  • Pricing / Payment pages: "Only pay at [official-domain]. Do not enter payment on other domains."
  • Footer: "© [Brand]. Official site: [domain]"
  • FAQ: "How do I verify I'm on the official site?" → "The only official URL is [domain]. Any other domain is not affiliated."

Use trust-badges for verification signals. See about-page for identity declaration.

Customer Support (Payment Fraud)

When users report "can't use after payment" but no record exists—likely paid on fake site:

  1. Verify source: Ask which URL they used (request screenshot or URL).
  2. Response template: Explain that the only official site is [official-domain]; if they paid elsewhere, that site is not affiliated. Recommend: (a) dispute charge with payment provider, (b) use only [official-domain] going forward.
  3. Roll out template to support team; ensure consistent messaging.

User Education

  • Social media pinned post / announcement: "Only use [official-domain]"
  • Email signatures, support replies: link to official domain only

Traffic Recovery (When Impersonation Intercepts Search)

Tactic Purpose
Brand search ads Run Google Ads and Microsoft Ads on brand terms; ensure official site appears first for brand queries
SEO Strengthen official site for branded queries; Organization schema, clear H1, meta tags. See schema-markup, title-tag
Social Pinned post: "Only use [official-domain]. Beware of impersonation."

Monitoring (Ongoing)

  • Periodic search: brand name + common variants (e.g., brand+ai, brand+app)
  • See brand-monitoring for monitoring setup, tool selection, and cadence

Timeline (Typical)

Phase Focus
Immediate (Days 1–3) Support template; site declaration; evidence collection
Short-term (Week 1–2) Abuse reports; Google Safe Browsing; DMCA if applicable
Traffic (Week 2+) Brand ads; SEO; social announcement
Ongoing Monitoring; defensive registration if feasible

Implementation Checklist

Short-term (1–2 weeks): Evidence collection; abuse reports to registrar and host; Google Safe Browsing report; DMCA if applicable; add "Official website" on site.

Medium-term: Add impersonation guidance to domain-selection; official verification to trust-badges, about-page.

Long-term: Periodic search (brand + variants); brand monitoring (BrandShield, Doppel); defensive registration of variants.

Output Format

  • Evidence package (checklist, evidence list)
  • Report templates (registrar, hosting, Google)
  • Timeline (immediate vs medium vs long-term actions)
  • Prevention (defensive registration, site verification, user education)

References

Related Skills

  • domain-selection: Defensive domain registration; brand variants
  • rebranding-strategy: When rebranding, sync brand protection checks
  • brand-monitoring: Proactive monitoring setup; tool selection; this skill = reactive takedown
  • branding: Brand asset protection; consistency
  • trust-badges: Official site verification signals
  • about-page: Official identity and domain declaration
  • homepage-generator: "Official website" placement
  • google-ads, paid-ads-strategy: Brand search ads for traffic recovery
  • schema-markup, title-tag: SEO for branded queries
安全使用建议
This skill appears coherent for brand-impersonation response. Before installing: (1) understand it may read local project-context files (remove sensitive data from .claude/.cursor if you don’t want it used); (2) avoid uploading screenshots or customer data containing PII to public reporting forms—redact or get consent; (3) verify URLs and evidence before filing takedowns to avoid false reports; and (4) consult legal counsel for cease-and-desist/DMCA actions when unsure. No credentials or installs are requested, so the main risk is accidental disclosure of sensitive evidence when preparing reports.
功能分析
Type: OpenClaw Skill Name: brand-protection Version: 1.0.1 The 'brand-protection' skill provides legitimate, non-executable instructions for an AI agent to assist users in identifying and reporting brand impersonation, phishing, and trademark infringement. It includes standard procedures for evidence collection and reporting to official channels like ICANN, Google Safe Browsing, and domain registrars (SKILL.md).
能力标签
cryptocan-make-purchases
能力评估
Purpose & Capability
Name/description match the actions in SKILL.md: discovery, evidence collection, reporting to registrars/hosts/search engines, and legal/remediation guidance. The skill does not request unrelated credentials, binaries, or install steps.
Instruction Scope
Instructions are focused on collecting URLs, screenshots, WHOIS/hosting data and submitting reports to the listed abuse/reporting endpoints — all appropriate. The SKILL.md also instructs the agent to read local project context files (.claude/project-context.md or .cursor/project-context.md) for brand info; this is reasonable but the package metadata did not declare those config paths as required, so callers should be aware the skill may read those files if present.
Install Mechanism
Instruction-only skill with no install spec and no code files — minimal risk from installation or remote downloads.
Credentials
No environment variables, credentials, or config paths are required. All external interactions are to public reporting tools and lookup services appropriate to the task.
Persistence & Privilege
always is false and there is no behavior that modifies other skills or requests persistent agent-wide privileges.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install brand-protection
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /brand-protection 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.1
Automated batch sync
元数据
Slug brand-protection
版本 1.0.1
许可证 MIT-0
累计安装 1
当前安装数 1
历史版本数 1
常见问题

brand-protection 是什么?

When the user faces brand impersonation, fake websites, phishing sites, or trademark infringement. Also use when the user mentions "fake site," "impersonatio... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 95 次。

如何安装 brand-protection?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install brand-protection」即可一键安装,无需额外配置。

brand-protection 是免费的吗?

是的,brand-protection 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

brand-protection 支持哪些平台?

brand-protection 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 brand-protection?

由 Kostja Zhang(@kostja94)开发并维护,当前版本 v1.0.1。

💬 留言讨论