Works with the AI tools you already use
Payment Fraud Triage — BEC & Vendor Fraud Verdict (CLEAR/VERIFY/HOLD)
by Julian GM
Triage a vendor email, invoice, or bank-detail change request for BEC/fraud signals before you pay — mechanical CLEAR / VERIFY / HOLD verdict, honest about what it can't check.
$29
· or 145 creditsSecure checkout via Stripe
About this skill
What it does A method the AI executes over a payment artifact you supply — a vendor email, an invoice, a bank-detail change request, a wire/ACH instruction — and checks it against the fraud patterns that actually cost money: business email compromise (BEC), vendor impersonation, lookalike/homoglyph domains, thread hijacking, CEO fraud, unauthorized IBAN/account changes. Output is a mechanical verdict: CLEAR, VERIFY, or HOLD — plus, on every HOLD or VERIFY, the exact action that would move it to CLEAR. The core question this skill is built around: when a vendor says "our bank account changed," who actually confirmed that, and where did the confirmation number come from? Most fraud losses in this category don't come from a badly-worded email — they come from a friendly, confident narration next to one hard fact nobody re-checked. Honest by design Every decisive claim is labeled verified, reported, or unverified. A control that wasn't executed is unverified — never quietly upgraded to reported because the story sounded convincing. Unverified sender does not equal verified sender. "We called and they confirmed" is not evidence unless the number called came from your own vendor records, not from the email being checked — this skill is built specifically to catch that distinction, because "not-checked" and "no hits" are two different claims and this method never blurs them into one. It also refuses to become something it isn't: no drafting phishing lures or "test" social-engineering content, and no profiling the employee who happened to send the email — the subject is always the transaction and the counterparty entity, never a person. Audited & signed Ships with a GPG-signed integrity manifest (MANIFEST.sha256 + MANIFEST.sha256.asc) covering the full assessment logic — the signal matrix, the verdict formula, the anti-false-CLEAR and anti-false-HOLD rules. Verify it yourself in three commands (references/VERIFY.md). Cross-check the fingerprint against this listing — an independent channel, exactly as the verification instructions themselves require: 3E5C 01D0 6619 A997 5C83 DDA7 7273 DD27 D9C1 E2B1 What's inside
Details
How to install
Drop the file into your AI Agent. Works with Claude, Cursor, ChatGPT, and 20+ more.
Reviews
No reviews yet - be the first to share your experience.
Only users who have downloaded or purchased this skill can leave a review.
Be the first to review this skill.
Only users who have downloaded or purchased this skill can leave a review.
Security Scanned
Passed automated security review
Permissions
File Scopes
Creator
Frequently Asked Questions
Browse More Skills

Business Strategist
A framework-driven consultant for business diagnosis, market mapping, and pricing strategy.
Bounty Security Pattern Master Library — 399 Vulnerability Patterns
A premium library of 399 vulnerability patterns and DeFi attack vectors for AI-driven bug hunting and security audits.

Game Design Blueprint Architect
Transform any game idea into a production-ready game design blueprint with gameplay mechanics, feature planning, art direction, monetization strategy, asset planning, and MVP roadmap.
sun-tzu-business-strategy
Convert Sun Tzu’s The Art of War into actionable business strategy, competitive memos, and market-entry plans.