What problem does it solve?
Security teams receive a steady stream of user-reported suspicious emails, and manually triaging each one — checking authentication headers, resolving links, inspecting attachments — is repetitive and inconsistent. This Skill standardizes that triage so every reported email gets the same disciplined analysis and a clear risk verdict.
Core Features & Use Cases
- Header and sender analysis: Checks SPF, DKIM, DMARC, Reply-To mismatches, Return-Path anomalies, and display-name spoofing on the original forwarded message.
- Link and attachment inspection: Resolves links to their real destinations, flags lookalike domains and credential-harvesting pages, and identifies true attachment types via content rather than extension.
- Five-tier risk classification: Assigns Critical, High, Medium, Low, or Benign tiers backed by specific indicators, with a recommended action such as blocking a sender or warning staff.
- Use Case: A scheduled check finds three new reports in the phishing-report Gmail inbox; the agent triages each independently and posts a verdict with indicators and a recommended action to the security Slack channel.
Quick Start
Triage the new emails in the phishing-report inbox and post a risk verdict with recommended actions to the security Slack channel.