← 返回 Skills 市场
harrylabsj

Social Engineering Defense Drill

作者 haidong · GitHub ↗ · v1.0.0 · MIT-0
cross-platform ✓ 安全检测通过
16
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install social-engineering-defense-drill
功能描述
Scenario-based practice that walks users through Web3 social engineering attacks — fake support, impersonation, urgency traps — and builds resistance through...
使用说明 (SKILL.md)

Social Engineering Defense Drill

Overview

Social Engineering Defense Drill is a scenario-based practice skill that helps users recognize, analyze, and resist Web3 social engineering attacks. Instead of a generic "don't trust anyone" warning, this skill walks users through specific techniques attackers use — urgency, authority impersonation, emotional manipulation, false scarcity — and builds resistance through structured analysis of real scenarios.

This skill does not investigate scammers, verify identities, or connect to any chain. It works from the message or scenario the user provides.

When to Use This Skill

Use this skill when:

  • You received a suspicious DM, Telegram message, or Discord ping.
  • You are unsure whether a "support" contact is legitimate.
  • You want to build stronger habits around social verification.
  • You were recently targeted and want to learn from the experience.
  • You want to practice recognizing social engineering patterns before encountering them.

Core Workflow

  1. Receive the suspicious message or scenario description from the user.
  2. Break down the social engineering techniques being used:
    • Urgency: "Act now or lose everything."
    • Authority impersonation: Pretending to be support, team members, or influencers.
    • Emotional manipulation: Fear, greed, excitement, or guilt.
    • False scarcity: "Only 3 spots left," "exclusive access."
    • Social proof fabrication: Fake testimonials, bot activity, fake screenshots.
  3. Explain why each technique works psychologically.
  4. Walk through the "pause and verify" protocol: what to check, where to verify, who to ask.
  5. Provide a counter-script the user can use to disengage safely.
  6. End with a reflection: what made this feel credible, and how to recognize it faster next time.

Output Format

For each analysis, the skill provides:

  • Technique breakdown — which social engineering tactics are present
  • Psychological explanation — why these techniques are effective
  • Pause-and-verify steps — concrete actions before responding
  • Disengagement script — safe words and phrases to exit the interaction
  • Learning reflection — what to remember for next time

Safety Boundaries

This skill cannot and will not:

  • Investigate the scammer, trace wallet addresses, or report to authorities on behalf of the user.
  • Verify whether a specific contact is a real team member or legitimate representative.
  • Guarantee that following the drill will prevent all future scams.
  • Access any on-chain data or external services.

Important disclaimer: This drill builds pattern recognition, not immunity. Always independently verify contacts through official channels (project website, official Discord announcement channel, verified social media accounts). Scammers continuously evolve their techniques.

Refusal example: "I cannot confirm whether this Telegram account is the real support team. Even if the message contains accurate-looking details, always verify through the project's official website or Discord announcement channel."

Examples

Example: Fake Support DM

User provides: "I got a DM from 'MetaMask Support' saying there's suspicious activity on my wallet and I need to 'validate' my wallet by visiting a link and entering my seed phrase. The account has the MetaMask logo."

Skill response:

  • Technique breakdown:
    • Authority impersonation: Using the MetaMask brand name and logo to appear official.
    • Urgency: "Suspicious activity" creates pressure to act immediately without thinking.
    • Emotional manipulation: Fear of losing funds overrides rational verification.
  • Psychological explanation: Authority bias makes us trust branded communications without verifying the source. Urgency suppresses the brain's analytical reasoning — when we feel time pressure, we default to familiar patterns (in this case, complying with "support").
  • Pause-and-verify steps:
    1. Pause. Real support teams never DM first.
    2. Check: Is this from an official verified account? MetaMask support does not initiate DMs.
    3. Verify: Go to the official MetaMask website (not the link in the DM) and check their support policy.
    4. Ask: Would real support ask for my seed phrase? (No — this is the universal red flag.)
  • Disengagement script: "I'll check the official support channels and get back to you." Then block and report the account. Do not engage further.
  • Learning reflection: The MetaMask logo and brand name created a false sense of legitimacy. Remember: any request for your seed phrase is a scam, regardless of how official it looks.

Acceptance Criteria

  • Identifies specific social engineering techniques (not just "it's a scam").
  • Explains psychological mechanisms behind each technique.
  • Provides actionable disengagement scripts.
  • Uses scenario-based analysis, not generic advice.
  • Does not claim to verify identities or investigate scammers.
  • All responses in English.
  • No code execution, API calls, wallet connections, or live chain queries.
安全使用建议
This skill appears safe to use as an educational aid. When sharing suspicious messages for analysis, avoid pasting seed phrases, private keys, passwords, or other secrets, and continue verifying contacts through official channels as the skill recommends.
功能分析
Type: OpenClaw Skill Name: social-engineering-defense-drill Version: 1.0.0 The 'Social Engineering Defense Drill' skill is a purely educational, text-based tool designed to help users identify and analyze Web3 social engineering tactics. It contains no executable code, explicitly disables code execution in 'skill.json', and includes clear safety boundaries in 'SKILL.md' that prevent the agent from attempting to access on-chain data or verify identities. The content is well-structured and aligns entirely with its stated purpose of security education.
能力标签
cryptorequires-walletrequires-sensitive-credentials
能力评估
Purpose & Capability
The stated purpose is scenario-based scam recognition and the artifacts consistently describe only user-provided message analysis.
Instruction Scope
Instructions focus on identifying tactics, explaining psychology, verifying through official channels, and safely disengaging.
Install Mechanism
There is no install spec, no required binaries, no dependencies, and skill.json declares no code execution.
Credentials
The skill does not request environment variables, credentials, wallet connections, chain access, external services, or local file access.
Persistence & Privilege
No persistence, background behavior, credential use, privilege escalation, or account mutation is shown in the provided artifacts.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install social-engineering-defense-drill
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /social-engineering-defense-drill 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Social Engineering Defense Drill v1.0.0 - Initial release of a scenario-based skill for practicing resistance to Web3 social engineering attacks. - Guides users through analyzing suspicious messages by breaking down specific attacker techniques (urgency, authority impersonation, emotional manipulation, false scarcity). - Explains the psychology behind social engineering methods in each scenario. - Provides concrete pause-and-verify steps and safe disengagement scripts. - Includes a reflection component for ongoing learning and faster pattern recognition. - Stays within strict boundaries: does not investigate scammers, verify identities, or access external data.
元数据
Slug social-engineering-defense-drill
版本 1.0.0
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 1
常见问题

Social Engineering Defense Drill 是什么?

Scenario-based practice that walks users through Web3 social engineering attacks — fake support, impersonation, urgency traps — and builds resistance through... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 16 次。

如何安装 Social Engineering Defense Drill?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install social-engineering-defense-drill」即可一键安装,无需额外配置。

Social Engineering Defense Drill 是免费的吗?

是的,Social Engineering Defense Drill 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

Social Engineering Defense Drill 支持哪些平台?

Social Engineering Defense Drill 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Social Engineering Defense Drill?

由 haidong(@harrylabsj)开发并维护,当前版本 v1.0.0。

💬 留言讨论