← Back to library
SecurityOpenskill · 4 min read

Skill: The AI Phishing Shield. Spot AI-Generated Scam Emails Before Your Team Gets Hooked

AI-generated phishing is convincing enough to fool experienced operators. This 3-minute process uses Claude to analyze any suspicious email and tell you exactly what to do next.


What it is: A repeatable 3-minute process for using AI to analyze suspicious emails before your team clicks, forwards, or wires anything.

Why it matters: AI-generated phishing has gotten convincing. It uses your name, your vendor's tone, your real invoice format, all scraped from LinkedIn, your website, and past breaches. A scam email that once took an expert 20 minutes to craft now takes a criminal 20 seconds. Your team can't tell the difference by look alone anymore.

When to use it:

  • Any email asking you to update payment info, approve a wire, or click a link
  • Vendor invoices arriving from a slightly different address than usual
  • Urgent "account suspended" or "order on hold" messages
  • Any email your staff flags as "something feels off"

How to run it: 3 minutes

Step 1: Copy the raw email text
In Gmail or Outlook, open the suspicious email and copy the full visible text: subject line, sender name, sender address, and body. Do NOT click any links.

Step 2: Paste into Claude (private workspace)
Open Claude in your private business account. Paste this prompt, then paste the email text below it:

Role: You are a cybersecurity analyst who specializes in identifying phishing and social engineering attacks targeting small business operators.

Task: Analyze the email below and tell me:

  1. Is this likely legitimate, suspicious, or a confirmed phishing attempt? Give a confidence level (low / medium / high).
  2. What are the 2–3 specific red flags (or trust signals) that led to your conclusion?
  3. What should I do next: reply, delete, call to verify, or escalate?

Email to analyze:
[PASTE EMAIL TEXT HERE]

Format: Three numbered answers, plain English, no jargon. Assume I'm a business owner with no security training.

Step 3: Read the verdict and act

  • Suspicious or phishing: Do not reply or click anything. Call the sender at a phone number you already have, not one in that email. Alert your team.
  • Looks legitimate but still uncertain: Call to verify anyway. Wire fraud recovery takes months and rarely succeeds. One phone call takes 2 minutes.

What this doesn't catch: AI can miss a well-crafted attack that uses accurate internal details. Treat this as a first filter and pair it with your team's gut check.

Privacy rule: Never paste emails that contain SSNs, medical records, or full financial account numbers into any AI tool. Use the 60-second redaction pass first.

The payoff: One caught phishing attempt typically saves $5,000–$50,000 in wire fraud or ransomware recovery costs. This takes 3 minutes to run.