Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
kostja94 avatar

Brand Protection

  • 763 installs
  • 787 repo stars
  • Updated June 9, 2026
  • kostja94/marketing-skills

brand-protection is a security strategy skill that detects, documents, and responds to brand impersonation, phishing sites, and trademark violations for developers protecting a product's public identity.

About

brand-protection is a marketing-skills strategy module (version 1.0.1) that guides coding agents through discovery, reporting, and prevention of brand impersonation, fake websites, phishing pages, trademark infringement, and domain squatting. It cross-references related skills such as domain-selection for defensive registration, trust-badges for official verification signals, and about-page for identity declaration, while directing ongoing monitoring to brand-monitoring. Developers invoke brand-protection when users mention fake sites, impersonation, phishing, trademark issues, or brand abuse. The skill produces actionable documentation and remediation steps rather than automated takedowns, fitting security-minded teams shipping SaaS or content products with public brands.

  • Guides discovery, evidence collection, and reporting for impersonation, phishing, trademark infringement, and domain squ
  • Reads project-context.md to pull brand name, official domain, and key assets on first run
  • Identifies impersonation type, available evidence, legal assets owned, and business impact
  • Provides structured prevention and takedown guidance tailored to the detected threat
  • Cross-references domain-selection, trust-badges, and about-page skills for layered defense

Brand Protection by the numbers

  • 763 all-time installs (skills.sh)
  • +6 installs in the week ending Jul 25, 2026 (Skillselion tracking)
  • Ranked #602 of 1,879 Marketing & SEO skills by installs in the Skillselion catalog
  • Security screen: MEDIUM risk (skills.sh audit)
  • Data as of Jul 31, 2026 (Skillselion catalog sync)
npx skills add https://github.com/kostja94/marketing-skills --skill brand-protection

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs763
repo stars787
Security audit2 / 3 scanners passed
Last updatedJune 9, 2026
Repositorykostja94/marketing-skills

How do you respond to brand impersonation and phishing sites?

Systematically detect, document, and act on brand impersonation, fake websites, phishing sites, and trademark violations.

Who is it for?

Developers or security leads at SaaS products who need a structured playbook when impersonation or trademark abuse surfaces post-launch.

Skip if: Teams seeking automated brand monitoring alerts alone, since brand-protection focuses on incident response rather than continuous scanning.

When should I use this skill?

The user mentions fake site, impersonation, phishing site, trademark infringement, domain squatting, or brand abuse.

What you get

Impersonation reports, takedown steps, defensive domain guidance, and trust-signal recommendations

  • impersonation incident report
  • takedown checklist
  • defensive domain recommendations

By the numbers

  • Skill version 1.0.1
  • References 3 companion skills: domain-selection, trust-badges, about-page

Files

SKILL.mdMarkdownGitHub ↗

Strategy: Brand Protection

Guides discovery, reporting, and prevention of brand impersonation—fake websites, phishing sites, trademark infringement, and domain squatting. See domain-selection for defensive domain registration; trust-badges for official site verification signals; about-page for identity declaration.

When invoking: On first use, if helpful, open with 1–2 sentences on what this skill covers and why it matters, then provide the main output. On subsequent use or when the user asks to skip, go directly to the main output.

Initial Assessment

Check for project context first: If .claude/project-context.md or .cursor/project-context.md exists, read it for brand name, official domain, and key assets.

Identify: 1. Impersonation type: Fake website, phishing, trademark misuse, domain squatting 2. Evidence available: Screenshots, URLs, WHOIS, hosting info 3. Legal assets: Registered trademark, copyright ownership 4. Impact: Traffic interception (fake site ranks for brand queries)? Payment fraud (users pay on fake site, then contact official support)?

Evidence Collection Checklist

ItemAction
Full URLsDocument all key pages of the fake site
ScreenshotsHomepage, product pages, logo, layout; include date/time
ComparisonSide-by-side: official vs fake (layout, logo, copy similarity)
WHOISUse ICANN Lookup for registrar, creation date, registrant
HostingIP lookup to identify hosting provider

Reporting Channels (Priority Order)

ChannelEntryUse Case
Domain registrarAbuse / Report Misuse on registrar siteBrand impersonation, trademark, fraud
Hosting providerSame; submit abuse formHosting infringing content
Google Safe BrowsingReport PhishingPhishing / impersonation risk
Google TrademarkTrademark Complaint or trademark@google.comTrademark infringement in search; requires registered trademark
Bing Content RemovalContent Moderation PlatformCopyright/trademark; content removal from Bing
Payment processorsPayPal Resolution Center, Stripe supportIf fake site accepts payments; report fraud
Social platformsX, Facebook, Instagram abuse formsIf fake site is promoted or linked there
Google Ads / Microsoft AdsPlatform trademark complaint formsIf impersonator runs brand ads
DMCATo hosting providerCopyright infringement; images, copy, design copied
ICANNDNS Abuse complaintIf registrar does not respond within reasonable time

Report content: Include full URL, clear description of fraudulent activity, and all evidence (screenshots, logs).

Reporting Best Practices

Registrar vs hosting: Use ICANN Lookup for registrar. For hosting, use IP lookup (HostingCheckerOnline, HostingDetector, ipinfo.io) to find origin server—registrar may be Cloudflare while origin host is elsewhere; report to both.

Cloudflare as registrar: Use abuse.cloudflare.com or abuse form; select "Phishing & Malware" for impersonation. Email complaints are generally not processed; use the online form. Provide specific URLs of infringing pages.

Hosting detection: Sites behind Cloudflare CDN hide origin IP. Use reverse IP lookup or hosting detection tools to identify underlying host; submit abuse to that provider as well.

Parallel reporting: Submit to registrar, host, and Google Safe Browsing simultaneously; do not wait for one before others. Google trademark review takes 1–8 weeks.

Legal Options

OptionWhenNotes
Cease and desistTrademark infringementLawyer-drafted; often first step
DMCA takedownCopyrighted material copiedImages, copy, design; hosting providers typically comply
Consumer protectionScam / fraudFTC ReportFraud.ftc.gov (US)
Law enforcementFinancial loss, identity theftIC3 (FBI) for cybercrime

Prevention Measures

Defensive Registration

  • Register brand+ai, brand+app, brand+official, etc. See domain-selection for defensive registration.
  • Redirect variants to main domain; do not deploy separate sites.

Official Site Verification

Place "Official website: [domain]" prominently:

  • Homepage (above fold or hero)
  • Sign-in / Sign-up pages
  • Pricing / Payment pages: "Only pay at [official-domain]. Do not enter payment on other domains."
  • Footer: "© [Brand]. Official site: [domain]"
  • FAQ: "How do I verify I'm on the official site?" → "The only official URL is [domain]. Any other domain is not affiliated."

Use trust-badges for verification signals. See about-page for identity declaration.

Customer Support (Payment Fraud)

When users report "can't use after payment" but no record exists—likely paid on fake site:

1. Verify source: Ask which URL they used (request screenshot or URL). 2. Response template: Explain that the only official site is [official-domain]; if they paid elsewhere, that site is not affiliated. Recommend: (a) dispute charge with payment provider, (b) use only [official-domain] going forward. 3. Roll out template to support team; ensure consistent messaging.

User Education

  • Social media pinned post / announcement: "Only use [official-domain]"
  • Email signatures, support replies: link to official domain only

Traffic Recovery (When Impersonation Intercepts Search)

TacticPurpose
Brand search adsRun Google Ads and Microsoft Ads on brand terms; ensure official site appears first for brand queries
SEOStrengthen official site for branded queries; Organization schema, clear H1, meta tags. See schema-markup, title-tag
SocialPinned post: "Only use [official-domain]. Beware of impersonation."

Monitoring (Ongoing)

  • Periodic search: brand name + common variants (e.g., brand+ai, brand+app)
  • See brand-monitoring for monitoring setup, tool selection, and cadence

Timeline (Typical)

PhaseFocus
Immediate (Days 1–3)Support template; site declaration; evidence collection
Short-term (Week 1–2)Abuse reports; Google Safe Browsing; DMCA if applicable
Traffic (Week 2+)Brand ads; SEO; social announcement
OngoingMonitoring; defensive registration if feasible

Implementation Checklist

Short-term (1–2 weeks): Evidence collection; abuse reports to registrar and host; Google Safe Browsing report; DMCA if applicable; add "Official website" on site.

Medium-term: Add impersonation guidance to domain-selection; official verification to trust-badges, about-page.

Long-term: Periodic search (brand + variants); brand monitoring (BrandShield, Doppel); defensive registration of variants.

Output Format

  • Evidence package (checklist, evidence list)
  • Report templates (registrar, hosting, Google)
  • Timeline (immediate vs medium vs long-term actions)
  • Prevention (defensive registration, site verification, user education)

References

Related Skills

  • domain-selection: Defensive domain registration; brand variants
  • rebranding-strategy: When rebranding, sync brand protection checks
  • brand-monitoring: Proactive monitoring setup; tool selection; this skill = reactive takedown
  • branding: Brand asset protection; consistency
  • trust-badges: Official site verification signals
  • about-page: Official identity and domain declaration
  • homepage-generator: "Official website" placement
  • google-ads, paid-ads-strategy: Brand search ads for traffic recovery
  • schema-markup, title-tag: SEO for branded queries

Related skills

How it compares

Pick brand-protection for incident response playbooks when abuse is reported, not for passive monitoring cadence.

FAQ

When should brand-protection be invoked?

brand-protection should be invoked when users face brand impersonation, fake websites, phishing sites, trademark infringement, or domain squatting, or when they mention terms like fake site, impersonation, or brand abuse.

How does brand-protection differ from brand-monitoring?

brand-protection focuses on discovery, reporting, and prevention playbooks for active impersonation incidents, while brand-monitoring in the same repo handles ongoing surveillance and alert workflows.

Is Brand Protection safe to install?

skills.sh reports 2 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.

Marketing & SEOseodistribution

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.