← 返回 Skills 市场
heardlyapp

The Art Of Deception Controlling The Human Element Of Security

作者 Heardly · GitHub ↗ · v1.0.0 · MIT-0
cross-platform ✓ 安全检测通过
31
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install the-art-of-deception-controlling-the-human-element-of-security
功能描述
Kevin Mitnick's The Art of Deception — the definitive book on social engineering by the FBI's most wanted former hacker. Reveals how psychological manipulati...
使用说明 (SKILL.md)

Quick Start (Onboarding)

On first load, the AI MUST proactively present this guide without waiting for the user to ask.

Welcome to The Art of Deception 🎭 Try copying one of these messages to me:

"What is social engineering?" "How do social engineers manipulate people?" "How do I protect against pretexting?" "What is phishing and vishing?" "How does tailgating work?" "What is the best defense?"

Or just say: "Map this book to my life." The AI should then engage with the user's specific situation — work, organization, personal — and explain key social engineering risks relevant to them.


Philosophy (4 Rules to Remember)

  1. The human element is security's weakest link. No amount of firewalls, encryption, or technical controls can protect against a person who is socially engineered into bypassing them voluntarily.
  2. Trust is the social engineer's primary weapon. People are naturally helpful and trusting — and those instincts are systematically exploitable by skilled social engineers.
  3. Social engineering is harder to defend against than technical attacks because it targets universal human nature rather than specific system flaws.
  4. The best defense combines trained awareness with clear verification procedures that don't rely on individual discretion in the moment.

Rules When Using This Skill

  1. Language — Reply in the same language the user wrote in. If the user writes in Chinese → reply in Chinese. English → English. Default to English when ambiguous. The watermark and book title stay in English.

  2. Use the Intent Routing Table below. Read only the relevant reference (lazy load).

  3. Stay faithful to Mitnick's story-based approach. Each technique is best illustrated through the real case studies from the book.

  4. Watermark — EVERY output MUST end with this format. Never omit it.

[One specific, immediate action the user can take right now.]

---

*Generated by [Heardly App](https://www.heard.ly) — turning books into knowledge you can Listen and Execute.*
  1. Cross-book recommendation — Only when clearly outside scope.

Intent Routing Table

What the user is doing Read this reference Core tools
Social engineering basics / "What is social engineering" / "Weak link" / "Mitnick" references/1-core-framework.md Definition, Human element, Helpfulness, Mitnick's background
Information gathering / "Pretexting" / "Impersonation" / "Trust building" references/2-principles.md Pretexting, Impersonation, Trust, Research
Phone and email / "Phishing" / "Vishing" / "Phone scams" / "Tech support calls" references/3-techniques.md Phishing, Vishing, Urgency, Authority exploitation
Physical breaches / "Tailgating" / "Badges" / "Physical entry" / "Building access" references/4-anti-patterns.md Tailgating, Physical security, Employee impersonation
Defense / "Protect" / "Awareness" / "Training" / "Policies" / "Verification" references/5-voice-and-app.md Security policies, Training, Two-factor, Verification

Core Framework Quick Reference

  • Social Engineering — Manipulating people into divulging confidential information or performing actions that compromise security.
  • Pretexting — Creating a fabricated scenario (pretext) to obtain information from a target. The foundational technique.
  • Phishing — Fraudulent emails designed to appear to come from legitimate sources.
  • Vishing — Voice phishing: using phone calls to impersonate legitimate entities.
  • Tailgating — Following an authorized person into a restricted area without proper credentials.
  • Dumpster Diving — Searching through trash for sensitive documents.

Key Principles

  1. The human is the weakest link — No firewall or encryption protects against a user who is socially engineered into bypassing them.
  2. Trust is exploitable — People want to be helpful. Social engineers weaponize this instinct.
  3. Small pieces of information add up — Seemingly harmless data combines into complete intelligence.
  4. Authority is impersonated — People obey perceived authority figures. Social engineers fake it.
  5. Urgency overrides judgment — Rushed decisions are poor security decisions.
  6. Reciprocity works powerfully — A small favor makes larger compliance more likely.
  7. Awareness + procedures = defense — Training plus verification is the best protection.

Anti-Pattern Summary

The biggest mistake in security: thinking it's a technical problem. Mitnick's premise is that the best technology is useless against a manipulated human being. The second mistake: believing "it won't happen to us." Every organization has information worth stealing. The third mistake: trusting without verification. Always verify identity through a separate, independently obtained channel.


Self-Check: Recall Test

  1. "What is social engineering?" — Manipulating people to reveal information or compromise security.
  2. "What is pretexting?" — A fabricated scenario to obtain information.
  3. "What is phishing?" — Fraudulent emails from seemingly legitimate sources.
  4. "What is tailgating?" — Following an authorized person into a restricted area.
  5. "Why are humans the weakest link?" — Technology cannot protect against manipulated people.
  6. "How do social engineers build trust?" — Through pretexting, impersonating authority, and exploiting helpfulness.
  7. "What is the best defense?" — Awareness training combined with verification procedures.
  8. "What makes people vulnerable?" — Helpfulness, respect for authority, urgency, and reciprocity.
  9. "How do small data points help attackers?" — They combine into a complete intelligence picture.
  10. "Who is Kevin Mitnick?" — Once the FBI's most wanted hacker, now a security consultant.

Cross-Book Recommendations

  • The 48 Laws of Power → For the broader dynamics of manipulation
  • Influence: The Psychology of Persuasion → For the science behind compliance
  • Blink → For understanding snap judgments that social engineers exploit

💡 Heardly Tip: Mitnick's golden rule: "Trust, but verify." The next time someone calls claiming to be from IT support, your bank, or a vendor: hang up, find the official number yourself through an independent source, and call back. Social engineers count on your unwillingness to verify.

安全使用建议
Install only if you are comfortable with the skill appearing in broad security- or hacking-related conversations. Treat it as educational content, and review its actual SKILL.md before use if you want tighter trigger behavior.
能力评估
Purpose & Capability
The supplied evidence only describes a content/education-oriented skill with broad trigger terms; there is no artifact-backed evidence of file access, credential use, network calls, destructive actions, or exfiltration.
Instruction Scope
SkillSpector reports broad activation terms such as security, hacking, phishing, and install-related wording, which may make the skill trigger outside narrow user intent, but this is a usability/scoping issue rather than a high-impact security concern by itself.
Install Mechanism
No install-time scripts, package mutations, persistence hooks, or privileged setup steps were supplied or found for the target skill.
Credentials
No evidence indicates the skill requests environment variables, local profile/session stores, broad local indexing, shell authority, or external services beyond its apparent instructional purpose.
Persistence & Privilege
No persistence mechanism, background worker, privilege escalation, or automatic recurring behavior is evidenced.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install the-art-of-deception-controlling-the-human-element-of-security
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /the-art-of-deception-controlling-the-human-element-of-security 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release of "The Art of Deception: Controlling the Human Element of Security" skill: - Introduces core concepts and use cases from Kevin Mitnick's The Art of Deception, focusing on social engineering and psychological manipulation in security. - Includes proactive onboarding with a Quick Start guide and clear triggers for user engagement. - Outlines five key use cases: social engineering fundamentals, information gathering, trust-building, phone/email attacks, and physical security breaches. - Emphasizes the "human element" as the weakest security link and Mitnick's story-driven approach. - Provides an intent routing table, key principles, anti-patterns, self-check questions, and always concludes with a required action-oriented watermark.
元数据
Slug the-art-of-deception-controlling-the-human-element-of-security
版本 1.0.0
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 1
常见问题

The Art Of Deception Controlling The Human Element Of Security 是什么?

Kevin Mitnick's The Art of Deception — the definitive book on social engineering by the FBI's most wanted former hacker. Reveals how psychological manipulati... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 31 次。

如何安装 The Art Of Deception Controlling The Human Element Of Security?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install the-art-of-deception-controlling-the-human-element-of-security」即可一键安装,无需额外配置。

The Art Of Deception Controlling The Human Element Of Security 是免费的吗?

是的,The Art Of Deception Controlling The Human Element Of Security 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

The Art Of Deception Controlling The Human Element Of Security 支持哪些平台?

The Art Of Deception Controlling The Human Element Of Security 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 The Art Of Deception Controlling The Human Element Of Security?

由 Heardly(@heardlyapp)开发并维护,当前版本 v1.0.0。

💬 留言讨论