Triage reported phishing in Slack
When someone reports a suspicious message in Slack, assesses it for phishing indicators, replies in thread and logs it.
Apps it connects
Authenticate each one once and the workflow is ready to run.
What it does
The integration steps this workflow runs, in the order it first runs them.
- 1
SlackNew message trigger - 2
AnthropicGenerate model response - 3
SlackSend message - 4
Google SheetsAppend row
How it works
Everything the template sets up, and what to fill in before the first run.
People notice suspicious email long before any tool does, but reporting it is usually where the trail goes cold. This workflow runs the moment someone posts a report into your security channel: it reads what they pasted, assesses it against the usual phishing indicators - sender mismatch, lookalike domains, urgency and threat language, credential or payment requests, mismatched links, unexpected attachments - and replies in their thread with a risk level, what it saw, and what to do next.
It is deliberately written as a first pass, not a verdict. It is told never to call anything definitely safe, and to answer MEDIUM rather than LOW when there is not enough to go on, because the cost of waving through a real phish is far higher than the cost of a second look. Every reply says so.
Every report is logged to a spreadsheet with the reporter, the original text and the verdict, whatever the assessment said. The log is the point: it is what makes a wrong call findable afterwards and what turns scattered reports into something you can review.
To set it up, choose the Slack channel people report into on the trigger step, and paste the spreadsheet to log to.
Start from a workflow that already works.
Add "Triage reported phishing in Slack" to your workspace, connect its apps, and make it yours. No credit card required.
Free plan available · No credit card required
