Semantic Phishing Honeybot
SkillSecurityHelps review suspicious phone-scam texts by extracting indicators of compromise and suggesting bait replies.
Use Semantic Phishing Honeybot in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Semantic Phishing Honeybot and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Semantic Phishing Honeybot skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
About this skill
Offline experimental text-turn helper for phone scam-review demonstrations. Extracts candidate IoCs and suggests bait responses; it does not place, intercept, or answer calls.
What this skill tells your AI
The instructions your AI receives, as published by calle-ai/awesome-phone-call-agents in skills/call-semantic-phishing-honeybot/SKILL.md and read by ahel’s review.
The supplied helper uses regex over synthetic transcript text and returns candidate URLs, wallet strings, phone-like strings, and predefined response suggestions. It does not determine that a person is a scammer, operate a call, browse extracted URLs, or send threat reports. Any future engagement must be operator-authorized, bounded, stoppable, and separate from this offline demonstration.
Scientific Foundation
| Paper / Concept | Relevance |
|---|---|
| Active Defense & Honeybots | Email scam-baiting research motivates this design; it does not establish phone-call duration or effectiveness. |
| Social Engineering Taxonomy | Uses established psychological countermeasures (acting confused, feigning compliance) to trigger the scammer into repeating technical instructions (IoCs). |
| Vishing Kill-Chain Analysis | Targets the "Action/Exploitation" phase of the voice phishing kill chain to capture the final payload (e.g. the Bitcoin wallet). |
How it works
- Supply a synthetic transcript turn and fictional caller identifier; no call is answered or intercepted.
- The helper applies regex to the text to extract candidate indicators.
- It dynamically generates a
bait_prompttailored to the scammer's current objective:- If the scammer wants Bitcoin, the bot feigns ignorance about crypto to drag out the call.
- If the scammer provides a URL, the bot pretends its antivirus blocked it to gather alternative domains.
- Candidates are returned in
HoneybotResponse; they are neither verified nor automatically logged/shared.
Expected Outcomes & Metrics
These are unvalidated design targets for a future integration, not measurements or effects of the local helper.
| Metric | Target | Notes |
|---|---|---|
| IoC Extraction Rate | > 75% | Successfully pulling a wallet or URL from a known scam script. |
| Call Duration (Stalling) | > 5 mins | Time wasted per scammer. |
Limitations & Known Constraints
- Pattern Matching Limits: The current IoC extraction relies on basic regex (e.g. base58 for Bitcoin). It may miss newer or obfuscated wallet formats.
- Integration Boundary: No LLM or calling loop is included. A future host must impose an operator-controlled stop and duration limit; returned
continue_baitingis a suggestion, not authority to continue a call.
Signals
- GitHub stars
- 104
- Forks
- 528
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
call-semantic-phishing-honeybot- Source
- github.com/calle-ai/awesome-phone-call-agents
github.com/calle-ai/awesome-phone-call-agents
Related picks
Skill · davila7
The pick for Web (OWASP)security-and-hardening
Skill · addyosmani
The pick for Web (OWASP)gws-shared
Skill · googleworkspace
More in Securitybrandkit
Skill · leonxlnx
More in Securitydefi-amm-security
Skill · affaan-m
More in Securityfastapi-patterns
Skill · affaan-m
More in Security