Human Factor Security skills for AI agents
9 practitioner-grade human factor security skills, each a focused Markdown document your agent loads into context on demand. Search them from Claude Desktop, Cursor or any MCP client, or pull one with the CLI.
All 9 skills
- business-email-compromise
Simulate BEC attacks to test financial controls, authorization procedures, and executive impersonation defenses
55 lines - credential-harvesting
Build authorized credential harvesting pages for phishing simulations using GoPhish, Evilginx, and transparent proxies
57 lines - deepfake-awareness
Build organizational awareness and verification procedures against deepfake voice, video, and AI-generated content threats
55 lines - helpdesk-exploitation
Test helpdesk and IT support social engineering resilience through authorized identity verification bypass assessments
55 lines - insider-threat-assessment
Assess insider threat program maturity through gap analysis of behavioral indicators, DLP, and access controls
55 lines - Phishing Defense
Use this skill when analyzing, preventing, or responding to phishing attacks. Activate when users mention phishing, spear phishing, smishing, vishing, suspicious emails, lookalike domains, credential-theft lures, QR-code phishing (quishing), MFA fatigue, or when they need to build phishing awareness programs, triage a reported message, or harden mail authentication (SPF, DKIM, DMARC).
117 lines - red-team-social-engineering
Execute full-scope red team social engineering campaigns combining email, phone, physical, and technical vectors
58 lines - social-media-reconnaissance
Conduct social media OSINT for authorized engagements to map organizational exposure and employee data leakage
55 lines - supply-chain-social-engineering
Assess supply chain and third-party social engineering risks through vendor impersonation and trusted relationship abuse testing
55 lines