CtrlK
BlogDocsLog inGet started
Tessl Logo

building-phishing-reporting-button-workflow

Implement a phishing report button (Microsoft 365 built-in Report button or third-party like KnowBe4/Cofense) in email clients with a SOAR-driven automated triage workflow that classifies reported emails, extracts IOCs, takes remediation actions, and gives feedback to reporters. Use when deploying user-reported phishing intake or automating triage of the resulting reporting mailbox.

60

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

Fix and improve this skill with Tessl

tessl review fix ./skills/building-phishing-reporting-button-workflow/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

52%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body presents a well-sequenced five-step workflow with a validation checklist, but guidance stays at the directional level without executable commands, and the entire bundle — including ready-made scripts and detailed workflow/API references — is orphaned because no file is ever referenced. Tightening the Overview/When-to-Use boilerplate and linking the bundle would raise both conciseness and actionability.

Suggestions

Add a references section or inline links pointing to the existing bundle files, e.g. "Detailed triage workflows: see references/workflows.md", "API and parsing examples: references/api-reference.md", "Ready-to-use triage engine: scripts/process.py", "Configuration template: assets/template.md" — this would also surface the executable code that is currently missing from the body.

Replace directional steps with executable specifics, such as the exact Microsoft 365 admin path or PowerShell cmdlets for enabling the built-in Report button and routing user reports, and a concrete SOAR playbook trigger configuration.

Trim the Overview's explanation of what a phishing report button is and the 70% report-rate statistic, and replace the generic "When to Use" boilerplate bullets with the skill's actual triggers.

Add an inline validation checkpoint and error-recovery guidance for the destructive Step 3 actions (auto-retract from all inboxes, block sender domain), e.g. verify retraction succeeded and a rollback path for misclassified legitimate email.

DimensionReasoningScore

Conciseness

The body is mostly tight bullet lists, but the Overview explains concepts Claude already knows ("A phishing reporting button empowers users to flag suspicious emails ... creating a critical feedback loop") and includes an unsourced marketing stat ("70%+ report rates"), while "When to Use" is templated boilerplate ("When deploying or configuring building phishing reporting button workflow capabilities"). This fits anchor 3 ("mostly efficient but includes some unnecessary explanation or could be tightened") rather than anchor 4, where over-explanation would be only minor.

3 / 5

Actionability

Steps name concrete tools and outcomes ("Enable Microsoft built-in Report button via Security & Compliance Center", "Submit URLs to VirusTotal, URLScan.io", classification categories, time targets), but no step includes an executable command, setting path, or code snippet — e.g., how to actually enable the Report button or wire the SOAR playbook. This matches anchor 3 ("some concrete guidance but incomplete ... missing key details") and sits above anchor 2 because the guidance is specific about tools, classifications, and thresholds rather than pure high-level hints.

3 / 5

Workflow Clarity

Five clearly sequenced steps cover deploy → triage → respond → feedback → measure, and a dedicated Validation section provides explicit checkpoints ("Reported email arrives in dedicated mailbox within 60 seconds", "Auto-retraction removes confirmed phishing from all inboxes"). It does not reach anchor 5 because checkpoints are an end-of-process checklist rather than inline gates, and there is no error-recovery loop for destructive actions (e.g., what to do when auto-retract fails or a legitimate email is misclassified and retracted) — anchor 4's "most checkpoints present; minor validation gaps".

4 / 5

Progressive Disclosure

The bundle contains six substantive files (references/api-reference.md, references/standards.md, references/workflows.md, scripts/agent.py, scripts/process.py, assets/template.md — 660 lines total, including an executable triage engine), but the body never mentions or links to any of them, leaving them undiscoverable. This matches anchor 2 ("references are buried") rather than anchor 3, which requires references to be at least present but weakly signaled; the body's own section structure is good, which keeps it above anchor 1.

2 / 5

Total

12

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that states concrete capabilities in third-person imperative voice and includes an explicit, specific "Use when..." trigger clause. Trigger terms are natural and include product synonyms, with only minor keyword gaps (e.g., "Outlook", "phish alert").

DimensionReasoningScore

Specificity

The description lists several concrete actions — "classifies reported emails, extracts IOCs, takes remediation actions, and gives feedback to reporters" — alongside a specific domain (Microsoft 365 Report button, KnowBe4/Cofense, SOAR triage). It falls just below anchor 5 because "takes remediation actions" is generic and the concrete actions are not comprehensive (e.g., no mention of deployment configuration or metrics covered in the body), matching anchor 4's "several specific actions; minor gaps in coverage".

4 / 5

Completeness

It clearly answers "what" ("Implement a phishing report button ... with a SOAR-driven automated triage workflow that classifies reported emails, extracts IOCs, takes remediation actions, and gives feedback to reporters") and explicitly answers "when" with concrete triggers ("Use when deploying user-reported phishing intake or automating triage of the resulting reporting mailbox"), matching anchor 5 exactly.

5 / 5

Trigger Term Quality

Strong natural keywords users would say: "phishing report button", "Report button", "reported emails", "reporting mailbox", "triage", plus product synonyms "KnowBe4/Cofense". It misses a few common variations such as "Outlook", "phish alert button", and "user reporting", so it fits anchor 4 ("good keyword coverage; a few natural terms missing") rather than anchor 5's comprehensive synonym coverage.

4 / 5

Distinctiveness Conflict Risk

The niche is distinct — phishing report button deployment combined with SOAR triage of a reporting mailbox — with named products (Microsoft 365, KnowBe4, Cofense) giving unique trigger terms. It would not plausibly fire for unrelated email-security or general incident-response skills, matching anchor 5's "clear niche with distinct triggers; minimal conflict risk"; anchor 4 would require some overlap with closely related skills, which is not evident.

5 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
mukul975/Anthropic-Cybersecurity-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.