Glossary
Phishing
Tricking somebody into handing over a credential.
The message looks like it comes from somewhere trusted and the page it leads to looks like the real one. It remains the most effective attack against ordinary accounts because it targets the person rather than the software.
Passkeys defeat it structurally: the browser will not use a passkey on the wrong domain, however convincing the page looks.
Where Naven stands
Naven screens for scams and malicious links, and supports passkeys, which are the only credential here that a convincing fake page cannot obtain.