brand-protection by kostja94/marketing-skills
npx skills add https://github.com/kostja94/marketing-skills --skill brand-protection指导发现、报告和预防品牌冒用行为——包括假冒网站、钓鱼网站、商标侵权和域名抢注。关于防御性域名注册,请参阅 domain-selection;关于官方网站验证信号,请参阅 trust-badges;关于身份声明,请参阅 about-page。
调用时机:在首次使用时,如果适用,请用 1-2 句话开头,说明此技能涵盖的内容及其重要性,然后提供主要输出。在后续使用或用户要求跳过时,直接进入主要输出。
首先检查项目上下文: 如果存在 .claude/project-context.md 或 .cursor/project-context.md 文件,请读取其中的品牌名称、官方域名和关键资产信息。
识别:
| 项目 | 行动 |
|---|---|
| 完整 URL |
广告位招租
在这里展示您的产品或服务
触达数万 AI 开发者,精准高效
| 记录假冒网站的所有关键页面 |
| 截图 | 主页、产品页面、Logo、布局;包含日期/时间 |
| 对比 | 并排对比:官方 vs 假冒(布局、Logo、文案相似度) |
| WHOIS | 使用 ICANN Lookup 查询注册商、创建日期、注册人 |
| 托管信息 | IP 查询以识别托管服务提供商 |
| 渠道 | 入口 | 适用场景 |
|---|---|---|
| 域名注册商 | 注册商网站上的"滥用"/"举报滥用" | 品牌冒用、商标侵权、欺诈 |
| 托管服务提供商 | 同上;提交滥用表单 | 托管侵权内容 |
| Google Safe Browsing | 举报钓鱼网站 | 钓鱼/冒用风险 |
| Google 商标 | 商标投诉 或 trademark@google.com | 搜索结果中的商标侵权;需要注册商标 |
| Bing 内容移除 | 内容审核平台 | 版权/商标侵权;从 Bing 移除内容 |
| 支付处理商 | PayPal 争议解决中心、Stripe 支持 | 如果假冒网站接受付款;举报欺诈 |
| 社交平台 | X、Facebook、Instagram 滥用举报表单 | 如果假冒网站在这些平台推广或链接 |
| Google Ads / Microsoft Ads | 平台商标投诉表单 | 如果冒用者投放品牌广告 |
| DMCA | 向托管服务提供商提交 | 版权侵权;复制了图片、文案、设计 |
| ICANN | DNS 滥用投诉 | 如果注册商在合理时间内未响应 |
举报内容:包含完整 URL、对欺诈活动的清晰描述以及所有证据(截图、日志)。
注册商 vs 托管商:使用 ICANN Lookup 查找注册商。对于托管商,使用 IP 查询(HostingCheckerOnline、HostingDetector、ipinfo.io)查找源服务器——注册商可能是 Cloudflare,而源主机在其他地方;向两者都举报。
Cloudflare 作为注册商:使用 abuse.cloudflare.com 或 滥用表单;选择"Phishing & Malware"进行冒用举报。电子邮件投诉通常不被处理;请使用在线表单。提供侵权页面的具体 URL。
托管检测:位于 Cloudflare CDN 后的网站会隐藏源 IP。使用反向 IP 查询或托管检测工具来识别底层主机;同时向该提供商提交滥用举报。
并行举报:同时向注册商、托管商和 Google Safe Browsing 提交举报;不要等待一个渠道后再提交其他渠道。Google 商标审核需要 1-8 周。
| 选项 | 适用时机 | 备注 |
|---|---|---|
| 停止并终止函 | 商标侵权 | 律师起草;通常是第一步 |
| DMCA 下架通知 | 受版权保护的材料被复制 | 图片、文案、设计;托管服务提供商通常配合 |
| 消费者保护 | 诈骗/欺诈 | FTC ReportFraud.ftc.gov(美国) |
| 执法部门 | 经济损失、身份盗窃 | IC3(FBI)处理网络犯罪 |
在显著位置放置"官方网站:[域名]":
使用 trust-badges 获取验证信号。关于身份声明,请参阅 about-page。
当用户报告"付款后无法使用"但无记录时——很可能是在假冒网站付款:
| 策略 | 目的 |
|---|---|
| 品牌搜索广告 | 在品牌关键词上投放 Google Ads 和 Microsoft Ads;确保官方网站在品牌查询中首先出现 |
| SEO | 针对品牌查询强化官方网站;使用组织架构、清晰的 H1、元标签。参见 schema-markup、title-tag |
| 社交媒体 | 置顶帖:"仅使用 [官方域名]。谨防冒用。" |
| 阶段 | 重点 |
|---|---|
| 立即行动(第 1-3 天) | 支持模板;网站声明;证据收集 |
| 短期(第 1-2 周) | 滥用举报;Google Safe Browsing;如适用,提交 DMCA |
| 流量恢复(第 2 周起) | 品牌广告;SEO;社交媒体公告 |
| 持续进行 | 监控;如可行,进行防御性注册 |
短期(1-2 周):证据收集;向注册商和托管商提交滥用举报;Google Safe Browsing 举报;如适用,提交 DMCA;在网站上添加"官方网站"声明。
中期:将冒用防范指南添加到 domain-selection;将官方验证添加到 trust-badges、about-page。
长期:定期搜索(品牌 + 变体);品牌监控(BrandShield、Doppel);防御性注册变体域名。
每周安装量
158
代码库
GitHub 星标数
237
首次出现
2026年3月6日
安全审计
安装于
cursor145
github-copilot144
gemini-cli144
kimi-cli144
codex144
opencode144
Guides discovery, reporting, and prevention of brand impersonation—fake websites, phishing sites, trademark infringement, and domain squatting. See domain-selection for defensive domain registration; trust-badges for official site verification signals; about-page for identity declaration.
When invoking : On first use , if helpful, open with 1–2 sentences on what this skill covers and why it matters, then provide the main output. On subsequent use or when the user asks to skip, go directly to the main output.
Check for project context first: If .claude/project-context.md or .cursor/project-context.md exists, read it for brand name, official domain, and key assets.
Identify:
| Item | Action |
|---|---|
| Full URLs | Document all key pages of the fake site |
| Screenshots | Homepage, product pages, logo, layout; include date/time |
| Comparison | Side-by-side: official vs fake (layout, logo, copy similarity) |
| WHOIS | Use ICANN Lookup for registrar, creation date, registrant |
| Hosting | IP lookup to identify hosting provider |
| Channel | Entry | Use Case |
|---|---|---|
| Domain registrar | Abuse / Report Misuse on registrar site | Brand impersonation, trademark, fraud |
| Hosting provider | Same; submit abuse form | Hosting infringing content |
| Google Safe Browsing | Report Phishing | Phishing / impersonation risk |
| Google Trademark | Trademark Complaint or trademark@google.com | Trademark infringement in search; requires registered trademark |
| Bing Content Removal | Content Moderation Platform | Copyright/trademark; content removal from Bing |
Report content : Include full URL, clear description of fraudulent activity, and all evidence (screenshots, logs).
Registrar vs hosting : Use ICANN Lookup for registrar. For hosting, use IP lookup (HostingCheckerOnline, HostingDetector, ipinfo.io) to find origin server—registrar may be Cloudflare while origin host is elsewhere; report to both.
Cloudflare as registrar : Use abuse.cloudflare.com or abuse form; select "Phishing & Malware" for impersonation. Email complaints are generally not processed; use the online form. Provide specific URLs of infringing pages.
Hosting detection : Sites behind Cloudflare CDN hide origin IP. Use reverse IP lookup or hosting detection tools to identify underlying host; submit abuse to that provider as well.
Parallel reporting : Submit to registrar, host, and Google Safe Browsing simultaneously; do not wait for one before others. Google trademark review takes 1–8 weeks.
| Option | When | Notes |
|---|---|---|
| Cease and desist | Trademark infringement | Lawyer-drafted; often first step |
| DMCA takedown | Copyrighted material copied | Images, copy, design; hosting providers typically comply |
| Consumer protection | Scam / fraud | FTC ReportFraud.ftc.gov (US) |
| Law enforcement | Financial loss, identity theft | IC3 (FBI) for cybercrime |
Place "Official website: [domain]" prominently:
Use trust-badges for verification signals. See about-page for identity declaration.
When users report "can't use after payment" but no record exists—likely paid on fake site:
| Tactic | Purpose |
|---|---|
| Brand search ads | Run Google Ads and Microsoft Ads on brand terms; ensure official site appears first for brand queries |
| SEO | Strengthen official site for branded queries; Organization schema, clear H1, meta tags. See schema-markup , title-tag |
| Social | Pinned post: "Only use [official-domain]. Beware of impersonation." |
| Phase | Focus |
|---|---|
| Immediate (Days 1–3) | Support template; site declaration; evidence collection |
| Short-term (Week 1–2) | Abuse reports; Google Safe Browsing; DMCA if applicable |
| Traffic (Week 2+) | Brand ads; SEO; social announcement |
| Ongoing | Monitoring; defensive registration if feasible |
Short-term (1–2 weeks) : Evidence collection; abuse reports to registrar and host; Google Safe Browsing report; DMCA if applicable; add "Official website" on site.
Medium-term : Add impersonation guidance to domain-selection; official verification to trust-badges, about-page.
Long-term : Periodic search (brand + variants); brand monitoring (BrandShield, Doppel); defensive registration of variants.
Weekly Installs
158
Repository
GitHub Stars
237
First Seen
Mar 6, 2026
Security Audits
Gen Agent Trust HubPassSocketPassSnykPass
Installed on
cursor145
github-copilot144
gemini-cli144
kimi-cli144
codex144
opencode144
社交媒体内容策略指南:创建、优化与互动全流程 | 营销技能
37,800 周安装
| Payment processors |
| PayPal Resolution Center, Stripe support |
| If fake site accepts payments; report fraud |
| Social platforms | X, Facebook, Instagram abuse forms | If fake site is promoted or linked there |
| Google Ads / Microsoft Ads | Platform trademark complaint forms | If impersonator runs brand ads |
| DMCA | To hosting provider | Copyright infringement; images, copy, design copied |
| ICANN | DNS Abuse complaint | If registrar does not respond within reasonable time |