brand-impersonation-response
Respond to a brand or executive impersonation incident — deepfaked executives, cloned support lines, fake apps, spoofed domains, or AI-generated scam content wearing your name
Install / Use
npx skills add mohitagw15856/pm-claude-skills --skill brand-impersonation-responseInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Customer SupportSupported Platforms
Tags
Our assessment of brand-impersonation-response
brand-impersonation-response scores 85/100 on our quality scale, 172nd of 335 Customer Support skills we index.
Its SKILL.md is 6.3 KB long, well organised into 8 sections and no code examples: a thorough specification that gives an agent plenty to work with.
With 1,396 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 8 days ago, so brand-impersonation-response is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
brand-impersonation-response compared with similar skills
All 4 of these similar skills score higher than brand-impersonation-response; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| brand-impersonation-response (this skill)by mohitagw15856 | 85 | 1.4k | 8d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 10d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 10d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 11d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 11d ago | SKILL.md |
Frequently asked questions
- How do I install brand-impersonation-response?
- Run
npx skills add mohitagw15856/pm-claude-skills --skill brand-impersonation-response. The install tabs above show the steps for each supported agent. - Which AI agents does brand-impersonation-response work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is brand-impersonation-response safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is brand-impersonation-response still maintained?
- The repository was last updated 8 days ago, so brand-impersonation-response is actively maintained.
Skill content
View source on GitHubname: brand-impersonation-response description: "Respond to a brand or executive impersonation incident — deepfaked executives, cloned support lines, fake apps, spoofed domains, or AI-generated scam content wearing your name. Use when a deepfake of a leader is circulating, customers report a fake version of your product or support channel, or to prepare the impersonation playbook before it happens. Produces an incident response: verification protocol, takedown sequencing by platform, customer and public communications, and the hardening plan. For general crisis comms use press-release/pm-crisis skills; for security incidents inside your systems use security-incident-response."
Brand Impersonation Response Skill
Cheap generative tools made impersonation an industrial product: a CEO deepfake pushing a token, a cloned support line harvesting card numbers, a spoofed checkout collecting credentials. The attack isn't on your systems — it's on your customers' trust, using your face. Speed and sequencing decide the damage; this skill runs both.
What This Skill Produces
- A verification protocol — confirm it's fake, preserve evidence, assess reach before amplifying it
- A takedown sequence by platform/registrar/store, with the escalation paths that actually work
- Communications for each audience: targeted customers, all customers, public, employees, and (deepfaked) the impersonated person
- A hardening plan so the next attempt lands softer
Required Inputs
Ask for (if not already provided):
- What's circulating: the artifact (video/audio/site/app/account), where it lives, how it was discovered
- The harm mechanism: financial scam? credential harvesting? reputation/market manipulation? (Drives urgency and legal posture)
- Reach so far — views, victim reports, whether it's spreading or stagnant
- Who's impersonated — the brand, a product surface, or a named human (a deepfaked person is also a victim; the response includes them)
Response Method
Phase 1 — Verify and preserve (first hours). Confirm fabrication with the impersonated party directly (deepfakes are good; "that's obviously fake" is not a verification method). Preserve everything before takedowns delete the evidence: URLs, hashes, screen recordings, WHOIS, wallet addresses, timestamps — the takedown kills the scam, the evidence supports fraud referrals and platform escalation. Quietly assess reach; do not publicly respond yet — a statement about a 400-view scam gives it 40,000.
Phase 2 — Contain (same day). Takedowns in parallel, sequenced by harm-per-hour:
- Payment/credential harvesting first: hosting provider + registrar (impersonation/phishing abuse reports), Google Safe Browsing / Microsoft SmartScreen flagging (kills most browser traffic faster than the registrar acts), payment processor fraud teams if cards are flowing
- Platforms: impersonation reports via brand/IP channels, not generic user reports — trademark-based reports move in hours where "report account" moves in weeks; file with rights documentation attached
- App stores: developer-impersonation + trademark claims through the formal IP channels
- Route it as fraud, not just abuse, where money moved: law enforcement referral (IC3 or local equivalent) — platforms escalate faster with a case number Log every report: platform, ticket, time — the log is the escalation tool when nothing moves.
Phase 3 — Communicate (as reach demands). The proportionality rule: warn the targeted, inform the asking, broadcast only when reach forces it.
- Targeted/victimised customers immediately: what happened, what we will never ask (the anchor line: "we will never DM you for payment/credentials/wallet transfers"), what to do if they engaged, one report channel
- The impersonated executive (deepfake cases): they're a victim, not just an asset — align their personal statement with the company's; one voice
- Public statement only past the reach threshold: short, factual, no link or screenshot of the fake, the never-ask anchor, the report channel. Never repeat the scam's claims in the correction (repetition entrenches)
- Support + social teams get the script before the public does — they're already getting the questions
Phase 4 — Harden (the week after). Verification anchors customers can check (verified handles list on your domain, DMARC/BIMI, signed comms for high-stakes messages) · monitoring for the next round (domain-permutation watch, brand-mention alerts, app-store sweeps — impersonators retry) · the internal deepfake protocol (a "CEO" voice call requesting a transfer gets a callback on a known number — write it down now) · pre-registered abuse contacts at the platforms that were slow this time.
Output Format
Impersonation Response: [what's circulating] — [date]
Verification: [how fabrication was confirmed · evidence preserved (list) · reach assessment]
Takedown log | Target | Channel used | Filed | Status | Escalation path | |---|---|---|---|---|
Communications (drafted, per audience): [targeted-customer notice · support script · public statement (with its reach trigger) · executive's personal statement if applicable]
The never-ask anchor: [the exact line, everywhere]
Hardening plan: [verification anchors · monitoring · internal deepfake protocol · owner + dates]
Quality Checks
- [ ] Evidence was preserved before takedowns were filed
- [ ] Takedowns route through IP/trademark channels with documentation, not generic reports
- [ ] Public response is gated on a stated reach threshold, not reflex
- [ ] No communication links, screenshots, or restates the scam's content
- [ ] Money-moved cases include the law-enforcement referral
- [ ] The hardening plan includes the internal voice-deepfake protocol
Anti-Patterns
- [ ] Do not amplify a low-reach scam with a high-reach denial — proportionality is the discipline
- [ ] Do not file generic "report this account" tickets when trademark channels exist — wrong queue, weeks lost
- [ ] Do not let takedowns destroy the evidence — preserve first, always
- [ ] Do not leave the deepfaked human out of the response — an executive learning the plan from the press release is a second incident
- [ ] Do not treat it as a one-off — impersonation that worked once is a campaign; monitoring is part of the response, not the postscript
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
