Semantic Phishing Honeybot
SkillSecurityOffline experimental text-turn helper for phone scam-review demonstrations. Extracts candidate IoCs and suggests bait responses; it does not place, intercept, or answer calls.
Available today. Use it from your connected AI after setup.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Semantic Phishing Honeybot skill
What this skill tells your AI
The instructions your AI receives, as published by calle-ai/awesome-phone-call-agents in skills/call-semantic-phishing-honeybot/SKILL.md and read by ahel’s review.
The supplied helper uses regex over synthetic transcript text and returns candidate URLs, wallet strings, phone-like strings, and predefined response suggestions. It does not determine that a person is a scammer, operate a call, browse extracted URLs, or send threat reports. Any future engagement must be operator-authorized, bounded, stoppable, and separate from this offline demonstration.
Scientific Foundation
| Paper / Concept | Relevance |
|---|---|
| Active Defense & Honeybots | Email scam-baiting research motivates this design; it does not establish phone-call duration or effectiveness. |
| Social Engineering Taxonomy | Uses established psychological countermeasures (acting confused, feigning compliance) to trigger the scammer into repeating technical instructions (IoCs). |
| Vishing Kill-Chain Analysis | Targets the "Action/Exploitation" phase of the voice phishing kill chain to capture the final payload (e.g. the Bitcoin wallet). |
How it works
- Supply a synthetic transcript turn and fictional caller identifier; no call is answered or intercepted.
- The helper applies regex to the text to extract candidate indicators.
- It dynamically generates a
bait_prompttailored to the scammer's current objective:- If the scammer wants Bitcoin, the bot feigns ignorance about crypto to drag out the call.
- If the scammer provides a URL, the bot pretends its antivirus blocked it to gather alternative domains.
- Candidates are returned in
HoneybotResponse; they are neither verified nor automatically logged/shared.
Expected Outcomes & Metrics
These are unvalidated design targets for a future integration, not measurements or effects of the local helper.
| Metric | Target | Notes |
|---|---|---|
| IoC Extraction Rate | > 75% | Successfully pulling a wallet or URL from a known scam script. |
| Call Duration (Stalling) | > 5 mins | Time wasted per scammer. |
Limitations & Known Constraints
- Pattern Matching Limits: The current IoC extraction relies on basic regex (e.g. base58 for Bitcoin). It may miss newer or obfuscated wallet formats.
- Integration Boundary: No LLM or calling loop is included. A future host must impose an operator-controlled stop and duration limit; returned
continue_baitingis a suggestion, not authority to continue a call.
Signals
- GitHub stars
- 104
- Forks
- 527
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
call-semantic-phishing-honeybot- Source
- github.com/calle-ai/awesome-phone-call-agents