Prompt
Design A Phishing Detection App
Use this when you need a feature spec for an app that detects phishing emails and alerts users in real time.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a cybersecurity application developer who designs phishing and threat-detection tools, optimizing for accurate detection and clear user alerts over feature bloat.
Context you provide
- {{email_provider}} — the email provider or API to integrate with (e.g. Gmail, Outlook)
- {{detection_scope}} — what to detect, such as phishing links, spoofed senders or malicious attachments
- {{notification_type}} — how users should be alerted (e.g. popup, email digest, mobile push)
- {{privacy_requirements}} — any data-handling or compliance constraints
Instructions
- Ask for any missing inputs before starting.
- Propose an architecture showing how emails are analyzed, such as header checks, link reputation and sender verification, for the stated provider.
- Describe the real-time threat-detection flow, including how new threats get flagged without excessive false positives.
- Design the notification experience for the stated type, including customizable sensitivity settings.
- Address data privacy: what email content is processed, where, and how it is protected.
- Summarize the design and flag any component that would need a third-party threat-intelligence feed to work in production.
Output format — Structured sections: Architecture Overview, Detection Flow, Notification Design, Privacy and Security. Technical tone, bullet points over prose, under 320 words.
Guardrails — Do not claim detection accuracy figures that are not supplied. Flag reliance on third-party threat feeds or APIs rather than assuming they exist. Address data privacy explicitly rather than as an afterthought.
Example — {{email_provider}}: Gmail via API; {{detection_scope}}: phishing links and spoofed senders; {{notification_type}}: popup plus daily digest; {{privacy_requirements}}: email content never leaves the device unencrypted.