deepfake-drill

deepfake-drill is a cursor rule for Cursor from mohitagw15856/pm-claude-skills. It costs 111 tokens per session (1,307 once invoked), scanned A, original, MIT.

A practice exercise for responding to fraud using a cloned voice or fake video, such as a caller pretending to be a company executive. A team works through the scenario using its real approval process.

In plain words
What is it for?
Training finance or operations teams, testing wire-transfer safeguards, and preparing for urgent requests involving money or sensitive actions. It produces a scenario, facilitator script, warning-sign checklist, and review of process gaps.
Why use it?
A convincing fake voice may not be detectable by listening alone. The exercise reveals whether staff and approval controls still work under pressure.

Cursor rule for Cursor

Written for Cursor: a Cursor rule (.mdc).

Good fit Training finance or operations teams, testing wire-transfer safeguards, and preparing for urgent requests involving money or sensitive actions. It produces a scenario, facilitator script, warning-sign checklist, and review of process gaps.

Compare 6 cursor rules from other repositories ↓
Install with agentmods
npx agentmods add rules/mohitagw15856/pm-claude-skills/deepfake-drill
About the project

PM Skills is a collection of plain-Markdown instructions that teach AI assistants structured methods for handling professional, personal, and life-admin tasks. People use it with Claude, ChatGPT, Gemini, Cursor, Codex, and other supported agents for work such as writing product requirements, reviewing documents, or planning difficult situations.

mohitagw15856/pm-claude-skills · 1,352 stars · on GitHub · mohitagw15856.github.io

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills

Made for: Cursor.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for deepfake-drill

README.md
[![agentmods](https://agentmods.dev/badge/rules/mohitagw15856/pm-claude-skills/deepfake-drill/github.svg)](https://agentmods.dev/rules/mohitagw15856/pm-claude-skills/deepfake-drill)
Your own site
<a href="https://agentmods.dev/rules/mohitagw15856/pm-claude-skills/deepfake-drill"><img src="https://agentmods.dev/badge/rules/mohitagw15856/pm-claude-skills/deepfake-drill/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for deepfake-drill

Your own site · 80×15
<a href="https://agentmods.dev/rules/mohitagw15856/pm-claude-skills/deepfake-drill"><img src="https://agentmods.dev/badge/rules/mohitagw15856/pm-claude-skills/deepfake-drill.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 111 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,307 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00111 $0.01307
Opus 5 $0.00056 $0.00654
Sonnet 5 $0.00022 $0.00261
Haiku 4.5 $0.00011 $0.00131

Measured 12d ago against content hash 35128fd6e091, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

deepfake-drill scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

exports/cursor/pm-2027/deepfake-drill/deepfake-drill.mdc · 115 lines

How it starts

The opening of the file, as written. The whole thing — 115 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Deepfake Drill Skill

The finance teams that lose seven figures to a cloned voice all describe the same call afterwards: it sounded exactly like him, he knew the deal names, he was stressed, it was 4:55pm on a Friday. Voice cloning needs seconds of audio now; the defense isn't detecting the fake — assume you can't — it's a process that holds even when the voice is perfect. This skill drills that process as a tabletop exercise: realistic pressure, your actual approval chain, and a debrief that fixes the gap the drill finds. It trains defenders; it does not help attackers — no cloning instructions, no evasion tips, ever.

What This Skill Produces

  • A drill scenario pack tailored to your org: the pretext, the pressure timeline, the escalating asks — written for a facilitator to read aloud, not for realism tooling
  • A facilitator script with decision points, expected-control checkpoints, and legitimate-looking curveballs ("the CFO is genuinely on a plane")
  • A tells checklist the team keeps afterwards: process tells (urgency + secrecy + channel-switch + authority), not audio tells
  • A gap report template: which control held, which was bypassed and how, the fix, the re-drill date

Required Inputs

Ask for (if not already provided):

  • The process being drilled: who can request payments/changes, who approves, above what thresholds, through which channels
  • The realistic attacker's knowledge: what's public about your execs, deals, vendors (assume LinkedIn + your press page)
  • Who's being drilled and whether it's announced or unannounced (recommend announced-window: "a drill will happen this month" — trains without the trust damage of full ambush)
  • Any real near-misses to build from

Process

  1. Design the scenario around YOUR weakest legitimate path. The drill pretexts that work are the ones your process half-allows: the acquisition that's "still confidential", the vendor bank-detail change, the exec travelling. Pick one, build the pretext from information a real attacker could gather publicly.
  2. Script the pressure, not the technology. The facilitator plays the caller using the three levers every real case uses — urgency (deadline in minutes), secrecy (tell no one, deal sensitivity), authority (the voice/name at the top) — plus the channel-switch ("can't do email, I'm boarding"). The script says what the caller says; it never explains how to clone a voice, and redirect any such request.
  3. Let the process fail safely. Facilitator notes for each decision point: what the control should catch, what to say if the participant bypasses it, when to escalate the pressure once. No individual shaming — the drill grades the process, and the debrief says so out loud.
  4. Debrief on tells and controls. The checklist that stays: any payment or detail-change request combining urgency + secrecy + channel-switch gets out-of-band verification on a known number, no exceptions for rank — the callback rule is the whole defense. Score which controls held.
  5. Fix and re-drill. Every gap gets an owner, a fix, and a date; the re-drill uses a different pretext. Recommend an annual cadence and folding the callback rule into onboarding.

Read the full file on GitHub · 115 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 115 lines · 111 tokens per session scan A 35128fd6e091

Subscribe to this mod's changes

deepfake-drill is a cursor rule published in the GitHub repository mohitagw15856/pm-claude-skills (1,352 stars, last pushed 3d ago), licensed MIT. It adds 111 tokens to every session and 1,307 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.