# SKAMM3D - Daily Defensive Scam Intelligence

> Canonical HTML: https://h1dr4.dev/skamm3d
> Machine index: https://h1dr4.dev/llms.txt

SKAMM3D publishes source-backed incident files and purpose-built learning labs that decompose human, agentic, and infrastructure deception into attack chains, trust mechanics, observables, evidence, and defensive controls.

## Read the feed

- Human interface: https://h1dr4.dev/skamm3d
- Public JSON feed: https://h1dr4.dev/api/v1/skamm3d/briefs
- Deep-linked JSON dossier: `https://h1dr4.dev/api/v1/skamm3d/briefs/{slug}`

The interface refreshes automatically and every dossier has a stable route at `/skamm3d/{slug}`. The homepage hosts a sanitized Would You Click phishing drill. Each dossier declares one adaptive experience: an incident decision and operation flow, a local agent-boundary trace lab, an OPSEC signal topology, or a historical evidence reconstruction.

The feed separates current signals from durable monitoring and history: `emerging` and `active` are hot, `persistent` is monitored, and `disrupted` or `archived` records remain available as historical control and evidence lessons. Dedicated OPSEC field notes distinguish weak signals from corroborated trails.

## Publication standard

- Claims must be supported by public, directly linked sources.
- Confidence describes the evidence available, not certainty about an actor's identity.
- Suspected malicious domains, addresses, and URLs are defanged and never made clickable.
- SKAMM3D does not publish victim PII, credentials, live malicious links, phishing copy, or replayable scam instructions.
- If no materially new and corroborated pattern is found, the daily publisher creates no filler entry.

The publisher credential is private, server-side, and separate from H1DR4 operator credentials.
