From agent-looker-for-claude-cowork
Report suspicious or malicious URLs discovered during web exploration. Trigger proactively when: encountering phishing, malware, scam sites, suspicious redirects, or data exfiltration URLs. Keywords: suspicious, malicious, phishing, malware, scam, redirect, report, risk, url
How this skill is triggered — by the user, by Claude, or both
Slash command
/agent-looker-for-claude-cowork:report-risk-urlThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
You have access to the MCP tool `report_risk_url`. Use it **proactively** whenever you encounter a suspicious URL during your work — whether browsing the web, following links, reading documents, or processing search results.
You have access to the MCP tool report_risk_url. Use it proactively whenever you encounter a suspicious URL during your work — whether browsing the web, following links, reading documents, or processing search results.
You do NOT need the user to ask you to report. If you see something suspicious, report it immediately.
Report a URL if it matches ANY of the following:
g00gle.com, paypa1-login.com, amaz0n-verify.net).tk, .ml, .ga, .cf, .gq)login, verify, secure, account, update on an unrelated domain.exe, .msi, .bat, .cmd, .ps1, .scr, .vbs, .jar, .apk)Call the report_risk_url tool with:
{
"url": "https://the-suspicious-url.com/path",
"risk_type": "phishing",
"severity": "high",
"source": "WebFetch",
"content_source": "https://the-page-where-you-found-this-link.com",
"description": "This domain mimics Google login but is hosted on .tk TLD. The page asks for Google credentials."
}
| Parameter | How to fill |
|---|---|
url | The suspicious URL itself |
risk_type | One of: phishing, malware, scam, suspicious_redirect, data_exfiltration, other |
severity | low = slightly odd, worth noting. medium = likely malicious but limited impact. high = clearly malicious. critical = active threat, immediate danger. |
source | The tool/component where you found it: WebFetch, WebSearch, Read, Bash, etc. |
content_source | Where you were when you found it — the page URL you were browsing, the search query, the file you were reading |
description | Your reasoning — what specifically makes this suspicious. Be concrete: "domain mimics X", "auto-downloads .exe", "redirects 3 times to unrelated domain" |
severity: "low" and risk_type: "other". False positives are acceptable; missed threats are not.description. "Looks suspicious" is not helpful. "Domain g00gle-login.tk mimics Google but uses .tk TLD and asks for credentials" is helpful.npx claudepluginhub gogolook-inc/agent-looker-claude-cowork --plugin agent-looker-for-claude-coworkProvides CDSS development patterns for drug interaction checking, dose validation, clinical scoring (NEWS2, qSOFA), and alert classification integrated into EMR workflows.