Human Factor Security skills for AI agents
9 practitioner-grade human factor security skills, each a focused Markdown document your agent loads into context on demand. Search them from Claude Desktop, Cursor or any MCP client, or pull one with the CLI.
All 9 skills
- business-email-compromise
Simulate BEC attacks to test financial controls, authorization procedures, and executive impersonation defenses
54 lines - credential-harvesting
Build authorized credential harvesting pages for phishing simulations using GoPhish, Evilginx, and transparent proxies
56 lines - deepfake-awareness
Build organizational awareness and verification procedures against deepfake voice, video, and AI-generated content threats
54 lines - helpdesk-exploitation
Test helpdesk and IT support social engineering resilience through authorized identity verification bypass assessments
54 lines - insider-threat-assessment
Assess insider threat program maturity through gap analysis of behavioral indicators, DLP, and access controls
54 lines - Phishing Defense
Use this skill when analyzing, preventing, or responding to phishing attacks. Activate when users mention phishing, spear phishing, smishing, vishing, suspicious emails, lookalike domains, credential-theft lures, QR-code phishing (quishing), MFA fatigue, or when they need to build phishing awareness programs, triage a reported message, or harden mail authentication (SPF, DKIM, DMARC).
116 lines - red-team-social-engineering
Execute full-scope red team social engineering campaigns combining email, phone, physical, and technical vectors
57 lines - social-media-reconnaissance
Conduct social media OSINT for authorized engagements to map organizational exposure and employee data leakage
54 lines - supply-chain-social-engineering
Assess supply chain and third-party social engineering risks through vendor impersonation and trusted relationship abuse testing
54 lines