disabled-phishing-policy

Enforce policy boundaries for phishing and social engineering requests in security assessments.

Updated Jul 30, 2026
One-click install
npx skills add https://github.com/salmanabdurrahman/pi-pentest-agent --skill disabled-phishing-policy
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: disabled-phishing-policy
Source: https://github.com/salmanabdurrahman/pi-pentest-agent/tree/main/skills/disabled-phishing-policy
Command: npx skills add https://github.com/salmanabdurrahman/pi-pentest-agent --skill disabled-phishing-policy

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill prevents unauthorized or high-risk phishing and social engineering activities by enforcing strict policy boundaries, ensuring all security testing is conducted with proper authorization, consent, and ethical oversight.

Core Features & Use Cases

  • Policy Enforcement: Provides a clear refusal rationale for prohibited phishing and social engineering requests.
  • Safe Alternatives: Redirects users toward constructive security improvements like email configuration audits, awareness training, and detection engineering.
  • Use Case: When a user requests a phishing simulation, this skill validates the required authorization gates and, if missing, guides the user toward performing a DMARC configuration audit or developing an incident response playbook instead.

Quick Start

Use the disabled-phishing-policy skill to review the mandatory authorization requirements for conducting a phishing simulation.

Frequently Asked Questions about disabled-phishing-policy

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I enforce policy compliance for phishing simulations?

To enforce policy compliance for phishing simulations, you must configure explicit repository settings, document stakeholder approval, and adhere to data minimization standards before any engagement begins.

What are safe alternatives to social engineering tests?

Safe alternatives to social engineering tests include email security configuration audits like DMARC reviews, security awareness training, and detection engineering to improve defensive postures without deceptive tactics.

Do I need stakeholder approval for phishing security testing?

Yes, you need documented stakeholder approval for phishing security testing. This skill acts as a governance gate, requiring explicit authorization and consent before allowing any social engineering assessment workflows to proceed.

Why does my phishing simulation request get blocked?

Your phishing simulation request gets blocked because strict policy boundaries prohibit unauthorized deceptive tactics. This governance mechanism refuses requests that lack explicit repository configuration and documented ethical oversight.

What is the best way to govern social engineering security assessments?

The best way to govern social engineering security assessments is to enforce strict policy boundaries that validate authorization gates, redirecting unauthorized requests toward defensive alternatives like email configuration audits and incident response playbooks.