Agent Skillsmohitagw15856/pm-claude-skills › brand-impersonation-response

brand-impersonation-response

GitHub

应对品牌或高管被深度伪造、仿冒支持线等身份盗用事件的危机响应技能。提供验证协议、按平台分级的下架流程、分层沟通策略及防御加固计划,旨在保护客户信任并最小化损害。

plugins/pm-crisis/skills/brand-impersonation-response/SKILL.md mohitagw15856/pm-claude-skills

Trigger Scenarios

CEO或其他高管遭遇深度伪造视频/音频传播 发现仿冒的官方客服渠道或应用正在窃取用户数据 检测到假冒品牌域名或AI生成的诈骗内容 需要预先制定品牌身份盗用应急响应预案

Install

npx skills add mohitagw15856/pm-claude-skills --skill brand-impersonation-response -g -y
More Options

Non-standard path

npx skills add https://github.com/mohitagw15856/pm-claude-skills/tree/main/plugins/pm-crisis/skills/brand-impersonation-response -g -y

Use without installing

npx skills use mohitagw15856/pm-claude-skills@brand-impersonation-response

指定 Agent (Claude Code)

npx skills add mohitagw15856/pm-claude-skills --skill brand-impersonation-response -a claude-code -g -y

安装 repo 全部 skill

npx skills add mohitagw15856/pm-claude-skills --all -g -y

预览 repo 内 skill

npx skills add mohitagw15856/pm-claude-skills --list

SKILL.md

Frontmatter
{
    "name": "brand-impersonation-response",
    "description": "Respond to a brand or executive impersonation incident — deepfaked executives, cloned support lines, fake apps, spoofed domains, or AI-generated scam content wearing your name. Use when a deepfake of a leader is circulating, customers report a fake version of your product or support channel, or to prepare the impersonation playbook before it happens. Produces an incident response: verification protocol, takedown sequencing by platform, customer and public communications, and the hardening plan. For general crisis comms use press-release\/pm-crisis skills; for security incidents inside your systems use security-incident-response."
}

Brand Impersonation Response Skill

Cheap generative tools made impersonation an industrial product: a CEO deepfake pushing a token, a cloned support line harvesting card numbers, a spoofed checkout collecting credentials. The attack isn't on your systems — it's on your customers' trust, using your face. Speed and sequencing decide the damage; this skill runs both.

What This Skill Produces

  • A verification protocol — confirm it's fake, preserve evidence, assess reach before amplifying it
  • A takedown sequence by platform/registrar/store, with the escalation paths that actually work
  • Communications for each audience: targeted customers, all customers, public, employees, and (deepfaked) the impersonated person
  • A hardening plan so the next attempt lands softer

Required Inputs

Ask for (if not already provided):

  • What's circulating: the artifact (video/audio/site/app/account), where it lives, how it was discovered
  • The harm mechanism: financial scam? credential harvesting? reputation/market manipulation? (Drives urgency and legal posture)
  • Reach so far — views, victim reports, whether it's spreading or stagnant
  • Who's impersonated — the brand, a product surface, or a named human (a deepfaked person is also a victim; the response includes them)

Response Method

Phase 1 — Verify and preserve (first hours). Confirm fabrication with the impersonated party directly (deepfakes are good; "that's obviously fake" is not a verification method). Preserve everything before takedowns delete the evidence: URLs, hashes, screen recordings, WHOIS, wallet addresses, timestamps — the takedown kills the scam, the evidence supports fraud referrals and platform escalation. Quietly assess reach; do not publicly respond yet — a statement about a 400-view scam gives it 40,000.

Phase 2 — Contain (same day). Takedowns in parallel, sequenced by harm-per-hour:

  • Payment/credential harvesting first: hosting provider + registrar (impersonation/phishing abuse reports), Google Safe Browsing / Microsoft SmartScreen flagging (kills most browser traffic faster than the registrar acts), payment processor fraud teams if cards are flowing
  • Platforms: impersonation reports via brand/IP channels, not generic user reports — trademark-based reports move in hours where "report account" moves in weeks; file with rights documentation attached
  • App stores: developer-impersonation + trademark claims through the formal IP channels
  • Route it as fraud, not just abuse, where money moved: law enforcement referral (IC3 or local equivalent) — platforms escalate faster with a case number Log every report: platform, ticket, time — the log is the escalation tool when nothing moves.

Phase 3 — Communicate (as reach demands). The proportionality rule: warn the targeted, inform the asking, broadcast only when reach forces it.

  • Targeted/victimised customers immediately: what happened, what we will never ask (the anchor line: "we will never DM you for payment/credentials/wallet transfers"), what to do if they engaged, one report channel
  • The impersonated executive (deepfake cases): they're a victim, not just an asset — align their personal statement with the company's; one voice
  • Public statement only past the reach threshold: short, factual, no link or screenshot of the fake, the never-ask anchor, the report channel. Never repeat the scam's claims in the correction (repetition entrenches)
  • Support + social teams get the script before the public does — they're already getting the questions

Phase 4 — Harden (the week after). Verification anchors customers can check (verified handles list on your domain, DMARC/BIMI, signed comms for high-stakes messages) · monitoring for the next round (domain-permutation watch, brand-mention alerts, app-store sweeps — impersonators retry) · the internal deepfake protocol (a "CEO" voice call requesting a transfer gets a callback on a known number — write it down now) · pre-registered abuse contacts at the platforms that were slow this time.

Output Format

Impersonation Response: [what's circulating] — [date]

Verification: [how fabrication was confirmed · evidence preserved (list) · reach assessment]

Takedown log

Target Channel used Filed Status Escalation path

Communications (drafted, per audience): [targeted-customer notice · support script · public statement (with its reach trigger) · executive's personal statement if applicable]

The never-ask anchor: [the exact line, everywhere]

Hardening plan: [verification anchors · monitoring · internal deepfake protocol · owner + dates]

Quality Checks

  • Evidence was preserved before takedowns were filed
  • Takedowns route through IP/trademark channels with documentation, not generic reports
  • Public response is gated on a stated reach threshold, not reflex
  • No communication links, screenshots, or restates the scam's content
  • Money-moved cases include the law-enforcement referral
  • The hardening plan includes the internal voice-deepfake protocol

Anti-Patterns

  • Do not amplify a low-reach scam with a high-reach denial — proportionality is the discipline
  • Do not file generic "report this account" tickets when trademark channels exist — wrong queue, weeks lost
  • Do not let takedowns destroy the evidence — preserve first, always
  • Do not leave the deepfaked human out of the response — an executive learning the plan from the press release is a second incident
  • Do not treat it as a one-off — impersonation that worked once is a campaign; monitoring is part of the response, not the postscript

Version History

  • a38bc30 Current 2026-07-05 11:14

Same Skill Collection

exports/openclaw/360-feedback-template/SKILL.md
exports/openclaw/401k-plan-decoder/SKILL.md
exports/openclaw/ab-test-planner/SKILL.md
exports/openclaw/ab-test-readout/SKILL.md
exports/openclaw/accessibility-audit/SKILL.md
exports/openclaw/account-plan/SKILL.md
exports/openclaw/acquirer-red-team/SKILL.md
exports/openclaw/ad-copy/SKILL.md
exports/openclaw/aeo-optimizer/SKILL.md
exports/openclaw/agenda-or-cancel/SKILL.md
exports/openclaw/agent-design-review/SKILL.md
exports/openclaw/agent-observability-spec/SKILL.md
exports/openclaw/agent-spec/SKILL.md
exports/openclaw/ai-ethics-review/SKILL.md
exports/openclaw/ai-eval-plan/SKILL.md
exports/openclaw/ai-feature-prd/SKILL.md
exports/openclaw/ai-product-canvas/SKILL.md
exports/openclaw/air-quality/SKILL.md
exports/openclaw/altitude-shifter/SKILL.md
exports/openclaw/ambiguity-resolver/SKILL.md
exports/openclaw/analyst-relations-brief/SKILL.md
exports/openclaw/announcement-card/SKILL.md
exports/openclaw/api-docs-writer/SKILL.md
exports/openclaw/api-test-plan/SKILL.md
exports/openclaw/api-versioning-strategy/SKILL.md
exports/openclaw/apology-letter/SKILL.md
exports/openclaw/architecture-decision-record/SKILL.md
exports/openclaw/architecture-diagram/SKILL.md
exports/openclaw/archive-strategy/SKILL.md
exports/openclaw/assumption-bounty/SKILL.md
exports/openclaw/assumption-mapper/SKILL.md
exports/openclaw/async-update-format/SKILL.md
exports/openclaw/auto-repair-estimate-decoder/SKILL.md
exports/openclaw/autopilot-charter/SKILL.md
exports/openclaw/benefits-decoder/SKILL.md
exports/openclaw/bid-tender-review/SKILL.md
exports/openclaw/board-deck-narrative/SKILL.md
exports/openclaw/board-minutes/SKILL.md
exports/openclaw/board-pre-read/SKILL.md
exports/openclaw/bom-cost-review/SKILL.md
exports/openclaw/bookkeeping-categorization/SKILL.md
exports/openclaw/boolean-search-builder/SKILL.md
exports/openclaw/brag-doc/SKILL.md
exports/openclaw/brainstorming/SKILL.md
exports/openclaw/brief-builder/SKILL.md
exports/openclaw/briefing-note/SKILL.md
exports/openclaw/budget-builder/SKILL.md
exports/openclaw/budget-variance-analysis/SKILL.md
exports/openclaw/bug-diagnosis/SKILL.md
exports/openclaw/bug-report/SKILL.md

Metadata

Files
0
Version
471c606
Hash
39ff2092
Indexed
2026-07-05 11:14

- 위키
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-07-30 23:50
浙ICP备14020137号-1 $방문자$