scam-site-investigation

Investigate suspicious websites by analyzing HTML, DNS, certificates, and social profiles.

1|Updated May 18, 2026
One-click install
npx skills add https://github.com/rickyananda/hermes-skills --skill scam-site-investigation
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: scam-site-investigation
Source: https://github.com/rickyananda/hermes-skills/tree/main/research/scam-site-investigation
Command: npx skills add https://github.com/rickyananda/hermes-skills --skill scam-site-investigation

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill helps determine whether a suspicious website is legitimate by combining technical fingerprinting, infrastructure analysis, and operator tracing into a single investigation workflow.

Core Features & Use Cases

  • Website legitimacy checks: Inspect page source, scripts, headers, DNS, and certificates to identify the stack and hosting footprint.
  • OSINT and identity tracing: Connect domains to social profiles, verification records, and related infrastructure signals.
  • Phishing and scam detection: Spot wallet-drainer patterns, deceptive forms, engagement farming, and other high-risk behaviors.
  • Use case: A user shares an unfamiliar crypto project URL and needs a clear verdict with evidence about whether it looks like a scam.

Quick Start

Use the scam-site-investigation skill to analyze the URL I share and return a concise legitimacy verdict with the strongest technical and OSINT evidence.

Frequently Asked Questions about scam-site-investigation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I investigate a suspicious website to determine if it is a scam?

To investigate a suspicious website for scam detection, you inspect its page source, scripts, headers, DNS, and certificates to fingerprint the technology stack and identify red-flag patterns like wallet drainers or deceptive forms.

What is OSINT infrastructure fingerprinting for phishing site checks?

OSINT infrastructure fingerprinting for phishing site checks is the process of analyzing DNS records, certificates, and headers to identify a website's hosting footprint and connect domains to related infrastructure signals.

How do I trace the operators behind a suspicious URL using social media profiles?

To trace website identity and operators behind a suspicious URL, you connect the domain's infrastructure signals and verification records to social profiles using OSINT techniques and identity tracing analysis.

Can I use this for crypto and NFT project vetting to spot wallet drainer patterns?

Yes, you can use this scam-site investigation workflow for crypto and NFT project vetting to spot wallet-drainer patterns, engagement farming, and other high-risk behaviors by analyzing the page's HTML and JavaScript.

What is the best way to check a website's legitimacy using DNS and certificate analysis?

The best way to check website legitimacy using DNS and certificate analysis is to combine infrastructure fingerprinting with OSINT tracing to evaluate hosting footprints and identify deceptive patterns across technical layers.

What limitations exist when tracing scam operators through infrastructure analysis?

Limitations when tracing scam operators through infrastructure analysis include relying on available DNS, certificate, and header data, as sophisticated operators often obscure social profiles and use evasive hosting footprints to avoid detection.