Semantic Phishing Honeybot

SkillSecurity

Helps review suspicious phone-scam texts by extracting indicators of compromise and suggesting bait replies.

Use Semantic Phishing Honeybot in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add Semantic Phishing Honeybot and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the Semantic Phishing Honeybot skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Semantic Phishing HoneybotStart free
About this skill

Offline experimental text-turn helper for phone scam-review demonstrations. Extracts candidate IoCs and suggests bait responses; it does not place, intercept, or answer calls.

What this skill tells your AI

The instructions your AI receives, as published by calle-ai/awesome-phone-call-agents in skills/call-semantic-phishing-honeybot/SKILL.md and read by ahel’s review.

The supplied helper uses regex over synthetic transcript text and returns candidate URLs, wallet strings, phone-like strings, and predefined response suggestions. It does not determine that a person is a scammer, operate a call, browse extracted URLs, or send threat reports. Any future engagement must be operator-authorized, bounded, stoppable, and separate from this offline demonstration.

Scientific Foundation

Paper / ConceptRelevance
Active Defense & HoneybotsEmail scam-baiting research motivates this design; it does not establish phone-call duration or effectiveness.
Social Engineering TaxonomyUses established psychological countermeasures (acting confused, feigning compliance) to trigger the scammer into repeating technical instructions (IoCs).
Vishing Kill-Chain AnalysisTargets the "Action/Exploitation" phase of the voice phishing kill chain to capture the final payload (e.g. the Bitcoin wallet).

How it works

  1. Supply a synthetic transcript turn and fictional caller identifier; no call is answered or intercepted.
  2. The helper applies regex to the text to extract candidate indicators.
  3. It dynamically generates a bait_prompt tailored to the scammer's current objective:
    • If the scammer wants Bitcoin, the bot feigns ignorance about crypto to drag out the call.
    • If the scammer provides a URL, the bot pretends its antivirus blocked it to gather alternative domains.
  4. Candidates are returned in HoneybotResponse; they are neither verified nor automatically logged/shared.

Expected Outcomes & Metrics

These are unvalidated design targets for a future integration, not measurements or effects of the local helper.

MetricTargetNotes
IoC Extraction Rate> 75%Successfully pulling a wallet or URL from a known scam script.
Call Duration (Stalling)> 5 minsTime wasted per scammer.

Limitations & Known Constraints

  • Pattern Matching Limits: The current IoC extraction relies on basic regex (e.g. base58 for Bitcoin). It may miss newer or obfuscated wallet formats.
  • Integration Boundary: No LLM or calling loop is included. A future host must impose an operator-controlled stop and duration limit; returned continue_baiting is a suggestion, not authority to continue a call.

Signals

GitHub stars
104
Forks
528
Last commit
Sep 2026
Advanced
Item type
skill
Key
call-semantic-phishing-honeybot
Source
github.com/calle-ai/awesome-phone-call-agents